INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Microsoft Releases Out-of-Band Patch for September 2026 Security Update
| 2026-09-14 20:43 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
Microsoft has released an out-of-band update to address a security vulnerability in Windows 11, version 26H1. The CVE-2026-62721 vulnerability was first patched in August but received additional attention due to its potential impact on users. Although there are no signs that the vulnerability is actively being exploited, Microsoft has taken proactive measures to ensure user safety. This update includes security patches for Windows 11, version 25H2 and 24H2, as well as other affected products such as Exchange. The vulnerabilities include a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC), a flaw in the Windows Update Stack, remote code execution vulnerability, and a use-after-free bug that allows an unauthenticated attacker to execute arbitrary code via Remote Desktop Services. Microsoft has prioritized these updates due to their potential impact on users, particularly with CVE-2026-69525 having a CVSS score of 9.8.
Technical Mitigations AI-generated
• Apply the latest security update for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix for CVE-2026-62721.
• Use caution when opening malicious links in the Windows Update Stack, as an attacker can follow it and escalate privileges (CVE-2026-81963).
• Ensure all software is up-to-date with the latest patches from Microsoft's Patch Tuesday releases.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
sn•••••.org
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-83941CVE-2026-83941
CVE-2026-70586CVE-2026-70586
CVE-2026-72962CVE-2026-72962
CVE-2026-69530CVE-2026-69530
CVE-2026-69832CVE-2026-69832
CVE-2026-73018CVE-2026-73018
CVE-2026-69436CVE-2026-69436
CVE-2026-81953CVE-2026-81953
CVE-2026-81948CVE-2026-81948
CVE-2026-69757CVE-2026-69757
CVE-2026-70562CVE-2026-70562
CVE-2026-69921CVE-2026-69921
CVE-2026-69525CVE-2026-69525
CVE-2026-80098CVE-2026-80098
CVE-2026-69820CVE-2026-69820
CVE-2026-69911CVE-2026-69911
CVE-2026-69380CVE-2026-69380
CVE-2026-69799CVE-2026-69799
CVE-2026-69385CVE-2026-69385
CVE-2026-73023CVE-2026-73023
CVE-2026-69499CVE-2026-69499
CVE-2026-81952CVE-2026-81952
CVE-2026-83498CVE-2026-83498
CVE-2026-78519CVE-2026-78519
CVE-2026-77505CVE-2026-77505
CVE-2026-80083CVE-2026-80083
CVE-2026-69450CVE-2026-69450
CVE-2026-55007CVE-2026-55007
CVE-2026-78449CVE-2026-78449
CVE-2026-69890CVE-2026-69890
CVE-2026-69585CVE-2026-69585
CVE-2026-67631CVE-2026-67631
CVE-2026-67643CVE-2026-67643
CVE-2026-81955CVE-2026-81955
CVE-2026-69857CVE-2026-69857
CVE-2026-69649CVE-2026-69649
CVE-2026-69310CVE-2026-69310
CVE-2026-65818CVE-2026-65818
CVE-2026-72959CVE-2026-72959
CVE-2026-70351CVE-2026-70351
CVE-2026-71343CVE-2026-71343
CVE-2026-81354CVE-2026-81354
CVE-2026-72954CVE-2026-72954
CVE-2026-67378CVE-2026-67378
CVE-2026-69767CVE-2026-69767
CVE-2026-77495CVE-2026-77495
CVE-2026-72979CVE-2026-72979
CVE-2026-69714CVE-2026-69714
CVE-2026-81951CVE-2026-81951
CVE-2026-78445CVE-2026-78445
CVE-2026-69305CVE-2026-69305
CVE-2026-69460CVE-2026-69460
CVE-2026-69391CVE-2026-69391
CVE-2026-72961CVE-2026-72961
CVE-2026-70203CVE-2026-70203
CVE-2026-69864CVE-2026-69864
CVE-2026-81950CVE-2026-81950
CVE-2026-69854CVE-2026-69854
CVE-2026-73006CVE-2026-73006
CVE-2026-69285CVE-2026-69285
CVE-2026-81963CVE-2026-81963
CVE-2026-69712CVE-2026-69712
CVE-2026-69827CVE-2026-69827
CVE-2026-85880CVE-2026-85880
CVE-2026-78525CVE-2026-78525
CVE-2026-77500CVE-2026-77500
CVE-2026-69874CVE-2026-69874
CVE-2026-69858CVE-2026-69858
CVE-2026-69730CVE-2026-69730
CVE-2026-69478CVE-2026-69478
CVE-2026-69406CVE-2026-69406
CVE-2026-72987CVE-2026-72987
CVE-2026-69459CVE-2026-69459
CVE-2026-83939CVE-2026-83939
CVE-2026-68880CVE-2026-68880
CVE-2026-69906CVE-2026-69906
CVE-2026-70583CVE-2026-70583
CVE-2026-70296CVE-2026-70296
CVE-2026-69366CVE-2026-69366
CVE-2026-69846CVE-2026-69846
CVE-2026-69277CVE-2026-69277
CVE-2026-72940CVE-2026-72940
CVE-2026-68876CVE-2026-68876
CVE-2026-77504CVE-2026-77504
CVE-2026-83711CVE-2026-83711
CVE-2026-69364CVE-2026-69364
CVE-2026-78454CVE-2026-78454
CVE-2026-69845CVE-2026-69845
CVE-2026-69467CVE-2026-69467
CVE-2026-69600CVE-2026-69600
CVE-2026-68846CVE-2026-68846
CVE-2026-81949CVE-2026-81949
CVE-2026-69595CVE-2026-69595
CVE-2026-69710CVE-2026-69710
CVE-2026-68884CVE-2026-68884
CVE-2026-62721CVE-2026-62721
CVE-2026-69779CVE-2026-69779
CVE-2026-69603CVE-2026-69603
CVE-2026-69337CVE-2026-69337
CVE-2026-69676CVE-2026-69676
CVE-2026-72981CVE-2026-72981
CVE-2026-70342CVE-2026-70342
CVE-2026-78439CVE-2026-78439
CVE-2026-72980CVE-2026-72980
CVE-2026-73010CVE-2026-73010
CVE-2026-69725CVE-2026-69725
CVE-2026-72958CVE-2026-72958
CVE-2026-72983CVE-2026-72983
CVE-2026-69829CVE-2026-69829
CVE-2026-69301CVE-2026-69301
CVE-2026-69777CVE-2026-69777
CVE-2026-69632CVE-2026-69632
CVE-2026-70289CVE-2026-70289
CVE-2026-69274CVE-2026-69274
CVE-2026-77493CVE-2026-77493
CVE-2026-72986CVE-2026-72986
CVE-2026-67636CVE-2026-67636
CVE-2026-69678CVE-2026-69678
CVE-2026-66302CVE-2026-66302
CVE-2026-69740CVE-2026-69740
CVE-2026-70585CVE-2026-70585
CVE-2026-69852CVE-2026-69852
CVE-2026-73013CVE-2026-73013
CVE-2026-78450CVE-2026-78450
CVE-2026-70352CVE-2026-70352
CVE-2026-78509CVE-2026-78509
CVE-2026-69501CVE-2026-69501
CVE-2026-62906CVE-2026-62906
CVE-2026-80093CVE-2026-80093
CVE-2026-69498CVE-2026-69498
CVE-2026-69813CVE-2026-69813
CVE-2026-69590CVE-2026-69590
CVE-2026-69797CVE-2026-69797
CVE-2026-69784CVE-2026-69784
CVE-2026-73009CVE-2026-73009
CVE-2026-62916CVE-2026-62916
CVE-2026-69769CVE-2026-69769
CVE-2026-70178CVE-2026-70178
CVE-2026-69518CVE-2026-69518
CVE-2026-81352CVE-2026-81352
CVE-2026-72982CVE-2026-72982
CVE-2026-65669CVE-2026-65669
CVE-2026-69860CVE-2026-69860
CVE-2026-69541CVE-2026-69541
CVE-2026-72960CVE-2026-72960
CVE-2026-72957CVE-2026-72957
CVE-2026-69579CVE-2026-69579
CVE-2026-81355CVE-2026-81355
CVE-2026-65772CVE-2026-65772
CVE-2026-72950CVE-2026-72950
CVE-2026-78505CVE-2026-78505
CVE-2026-73017CVE-2026-73017
CVE-2026-69601CVE-2026-69601
CVE-2026-71340CVE-2026-71340
CVE-2026-69723CVE-2026-69723
CVE-2026-83501CVE-2026-83501
CVE-2026-69623CVE-2026-69623
CVE-2026-78444CVE-2026-78444
CVE-2026-69466CVE-2026-69466
CVE-2026-58599CVE-2026-58599
CVE-2026-78510CVE-2026-78510
CVE-2026-69473CVE-2026-69473
CVE-2026-77898CVE-2026-77898
CVE-2026-69451CVE-2026-69451
CVE-2026-81959CVE-2026-81959
CVE-2026-78520CVE-2026-78520
CVE-2026-72936CVE-2026-72936
CVE-2026-69605CVE-2026-69605
Target & Sectors
MS
Incident Timeline
January 2023
Microsoft patched an ALPC zero-day vulnerability, allowing a local attacker to gain SYSTEM-level privileges.
September 2026
Microsoft released its September 2026 Patch Tuesday, fixing a record 973 vulnerabilities including 113 critical ones and two zero-days.
Click on any entity below to view its context and source!
general_metric
2 Days
Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
Pierluigi Paganini
September 09, 2026
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email.
general_metric
20 Wormable Bugs
Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
Pierluigi Paganini
September 09, 2026
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email.
organisation
Microsoft’s
Microsoft’s September 2026 Patch Tuesday set a new record.
organisation
Microsoft Patch
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities.
organisation
Snort
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities.
organisation
Microsoft
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
general_metric
113 critical vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
general_metric
973 vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
September 09, 2026
Threat actors exploited Microsoft's Patch Tuesday 2026 to target systems with a record 974 CVEs, including two zero-days and twenty wormable bugs.
Click on any entity below to view its context and source!
general_metric
2 Days
Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
Pierluigi Paganini
September 09, 2026
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email.
general_metric
20 Wormable Bugs
Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
Pierluigi Paganini
September 09, 2026
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email.
2026/09/14
Microsoft released an out-of-band security update on September 14, 2026.
Click on any entity below to view its context and source!
organisation
Microsoft
Microsoft today released an out of band update that includes....
Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August.
2026/09/14
Threat actors used the unauthenticated attack path of a remote code execution vulnerability with a CVSS base score of 9.8 to exploit CVE-2026-78445, affecting Windows Imaging Component and Microsoft Excel.
Click on any entity below to view its context and source!
organisation
Microsoft
Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs.
infrastructure
Windows
MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://
support.microsoft.com/en-us/se
rvicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update
https://
msrc.microsoft.com/update-guid
e/advisory/CVE-2026-62721
CVE-2026-85880
(CVSS score of 7.8) is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC).
CVE-2026-81963
(CVSS score of 7.8) flaw resides in the Windows Update Stack.
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
CVE-2026-69601
affects Microsoft Windows Media Foundation.
CVE-2026-70203
affects Windows Media Player.
CVE-2026-72960
affects Windows Media Player.
Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:
CVE-2026-81963
affects Windows Update Stack.
CVE-2026-85880
affects Windows Advanced Local Procedure Call (ALPC).
Microsoft considers exploitation of the following vulnerabilities more likely:
CVE-2026-69676
affects Windows Kerberos.
CVE-2026-69852
affects Windows Routing and Remote Access Service (RRAS).
CVE-2026-72957
affects Windows Deployment Services.
CVE-2026-83501
affects Windows Virtualization-Based Security (VBS).
CVE-2026-70585
affects Windows Services for NFS ONCRPC XDR Driver.
CVE-2026-69730
affects Windows DNS Server.
Microsoft considers exploitation of the following vulnerabilities less likely:
CVE-2026-69845
and
CVE-2026-72979
affect Windows DHCP Server.
CVE-2026-69499
,
CVE-2026-70296
,
CVE-2026-73023
,
CVE-2026-77495
, and
CVE-2026-73013
affect Windows Imaging Component.
CVE-2026-69501
,
CVE-2026-83939
,
CVE-2026-69906
, and
CVE-2026-69846
affect Windows Secure Kernel Mode.
CVE-2026-69590
and
CVE-2026-72959
affect Windows Routing and Remote Access Service (RRAS).
CVE-2026-73009
affects Windows Secure Socket Tunneling Protocol (SSTP).
CVE-2026-77493
affects Windows Graphics Component.
CVE-2026-83498
affects Windows Virtualization-Based Security (VBS) Enclave.
CVE-2026-69530
,
CVE-2026-78449
, and
CVE-2026-78450
affect Windows Reliable Multicast Transport Driver (RMCAST).
CVE-2026-81354
affects Windows Hello.
CVE-2026-69595
and
CVE-2026-78445
affect Windows Services for NFS ONCRPC XDR Driver.
CVE-2026-69813
and
CVE-2026-77505
affect Windows DNS Server.
CVE-2026-69518
affects Windows Remote Desktop.
CVE-2026-69712
affects Windows Key Distribution Center.
Microsoft considers exploitation of the following vulnerabilities unlikely:
CVE-2026-69603
,
CVE-2026-72961
, and
CVE-2026-80083
affect Windows Hyper-V.
CVE-2026-69603
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
CVE-2026-69710
,
CVE-2026-69725
,
CVE-2026-69740
,
CVE-2026-69784
,
CVE-2026-69799
,
CVE-2026-69820
,
CVE-2026-69864
, and
CVE-2026-72980
affect Windows Hello.
CVE-2026-69769
affects Windows HTTP Print Provider.
CVE-2026-69829
affects Windows Shell.
CVE-2026-69860
affects Windows Imaging Component.
CVE-2026-69874
affects Windows ALPC.
CVE-2026-69890
affects Windows Virtual Trusted Platform Module.
CVE-2026-70586
affects Windows Paint.
CVE-2026-72950
affects Windows Routing and Remote Access Service (RRAS).
CVE-2026-72954
affects Windows Deployment Services.
CVE-2026-72958
affects Windows Credential Guard.
CVE-2026-72962
affects Windows USB Video Driver.
CVE-2026-72982
affects Windows Netlogon.
CVE-2026-72987
affects Windows DNS.
CVE-2026-81955
affects Windows Graphics Component.
CVE-2026-69858
and
CVE-2026-69827
affect Windows DNS Server.
CVE-2026-69579
affects Windows Message Queuing.
Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"
CVE-2026-68846
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-68876
: Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
CVE-2026-68880
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-68884
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69274
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-69277
: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
CVE-2026-69301
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-69305
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69310
: Windows DNS Elevation of Privilege Vulnerability
CVE-2026-69337
: Windows Registry Elevation of Privilege Vulnerability
CVE-2026-69364
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-69385
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69391
: Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
CVE-2026-69406
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69436
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69450
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69451
: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-69459
: Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
CVE-2026-69466
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69473
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69478
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69498
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-69525
: Remote Desktop Services Remote Code Execution Vulnerability
CVE-2026-69541
: Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
CVE-2026-69585
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69600
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69605
: Microsoft Install Service Elevation of Privilege Vulnerability
CVE-2026-69623
: Windows HTTP Print Provider Remote Code Execution Vulnerability
CVE-2026-69714
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69723
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69757
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69777
: Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2026-69779
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-69832
: Win32k Information Disclosure Vulnerability
CVE-2026-69911
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69921
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-70289
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
organisation
CVE
MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://
support.microsoft.com/en-us/se
rvicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update
https://
msrc.microsoft.com/update-guid
e/advisory/CVE-2026-62721
organisation
Windows Advanced Local Procedure Call
CVE-2026-85880
(CVSS score of 7.8) is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC).
CVE-2026-85880
affects Windows Advanced Local Procedure Call (ALPC).
infrastructure
7.8
CVE-2026-81963
(CVSS score of 7.8) flaw resides in the Windows Update Stack.
organisation
the Windows Update Stack
CVE-2026-81963
(CVSS score of 7.8) flaw resides in the Windows Update Stack.
organisation
SMB Client
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
organisation
Netlogon
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
organisation
NFS
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
CVE-2026-70585
affects Windows Services for NFS ONCRPC XDR Driver.
organisation
RRAS
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
CVE-2026-69852
affects Windows Routing and Remote Access Service (RRAS).
organisation
IP Helper
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
CVE-2026-72981
affects IP Helper.
organisation
Message Queuing
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
organisation
Microsoft Windows Media Foundation
CVE-2026-69601
affects Microsoft Windows Media Foundation.
organisation
CVE-2026-70203
CVE-2026-70203
affects Windows Media Player.
organisation
Windows Media Player
CVE-2026-70203
affects Windows Media Player.
organisation
Windows Update Stack
Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:
CVE-2026-81963
affects Windows Update Stack.
organisation
Remote Access Service
CVE-2026-69852
affects Windows Routing and Remote Access Service (RRAS).
organisation
Windows Deployment Services
CVE-2026-72957
affects Windows Deployment Services.
organisation
Windows Virtualization-Based Security
CVE-2026-83501
affects Windows Virtualization-Based Security (VBS).
organisation
Windows Services
CVE-2026-70585
affects Windows Services for NFS ONCRPC XDR Driver.
organisation
CVE-2026
CVE-2026-69499
,
CVE-2026-70296
,
CVE-2026-73023
,
CVE-2026-77495
, and
CVE-2026-73013
affect Windows Imaging Component.
organisation
Windows Imaging Component
CVE-2026-69499
,
CVE-2026-70296
,
CVE-2026-73023
,
CVE-2026-77495
, and
CVE-2026-73013
affect Windows Imaging Component.
organisation
Windows Secure Socket Tunneling Protocol
CVE-2026-73009
affects Windows Secure Socket Tunneling Protocol (SSTP).
organisation
Windows Graphics Component
CVE-2026-77493
affects Windows Graphics Component.
organisation
Windows Reliable Multicast Transport Driver
CVE-2026-69530
,
CVE-2026-78449
, and
CVE-2026-78450
affect Windows Reliable Multicast Transport Driver (RMCAST).
organisation
RMCAST
CVE-2026-69530
,
CVE-2026-78449
, and
CVE-2026-78450
affect Windows Reliable Multicast Transport Driver (RMCAST).
organisation
Windows Hello
CVE-2026-81354
affects Windows Hello.
organisation
Windows Remote Desktop
CVE-2026-69518
affects Windows Remote Desktop.
organisation
Windows Key Distribution Center
CVE-2026-69712
affects Windows Key Distribution Center.
infrastructure
8.8
Microsoft considers exploitation of the following vulnerabilities unlikely:
CVE-2026-69603
,
CVE-2026-72961
, and
CVE-2026-80083
affect Windows Hyper-V.
CVE-2026-69603
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
organisation
CVE-2026-69769
CVE-2026-69769
affects Windows HTTP Print Provider.
organisation
Windows HTTP Print Provider
CVE-2026-69769
affects Windows HTTP Print Provider.
organisation
CVE-2026-69829
CVE-2026-69829
affects Windows Shell.
organisation
Windows Virtual
CVE-2026-69890
affects Windows Virtual Trusted Platform Module.
organisation
CVE-2026-72954
CVE-2026-72954
affects Windows Deployment Services.
organisation
Windows Credential Guard
CVE-2026-72958
affects Windows Credential Guard.
organisation
Windows USB Video Driver
CVE-2026-72962
affects Windows USB Video Driver.
organisation
Windows Message Queuing
CVE-2026-69579
affects Windows Message Queuing.
organisation
Windows Win32k
Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"
CVE-2026-68846
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-68876
: Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
CVE-2026-68880
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-68884
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69274
: Windows Win32k
organisation
Microsoft Local Security Authority
Elevation of Privilege Vulnerability
CVE-2026-69277
: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
CVE-2026-69301
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-69305
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69310
: Windows DNS Elevation of Privilege Vulnerability
CVE-2026-69337
: Windows Registry Elevation of Privilege Vulnerability
CVE-2026-69364
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-69385
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69391
: Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
CVE-2026-69406
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69436
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69450
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69451
: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-69459
: Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
CVE-2026-69466
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69473
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69478
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69498
: Windows Win32k
organisation
LSA
Elevation of Privilege Vulnerability
CVE-2026-69277
: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
CVE-2026-69301
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-69305
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69310
: Windows DNS Elevation of Privilege Vulnerability
CVE-2026-69337
: Windows Registry Elevation of Privilege Vulnerability
CVE-2026-69364
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-69385
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69391
: Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
CVE-2026-69406
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69436
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69450
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69451
: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-69459
: Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
CVE-2026-69466
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69473
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69478
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69498
: Windows Win32k
infrastructure
69301 Server Elevation
Elevation of Privilege Vulnerability
CVE-2026-69277
: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
CVE-2026-69301
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-69305
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69310
: Windows DNS Elevation of Privilege Vulnerability
CVE-2026-69337
: Windows Registry Elevation of Privilege Vulnerability
CVE-2026-69364
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-69385
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69391
: Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
CVE-2026-69406
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69436
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69450
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69451
: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-69459
: Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
CVE-2026-69466
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69473
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69478
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69498
: Windows Win32k
organisation
Remote Desktop Services
Elevation of Privilege Vulnerability
CVE-2026-69525
: Remote Desktop Services Remote Code Execution Vulnerability
CVE-2026-69541
: Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
CVE-2026-69585
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69600
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69605
: Microsoft Install Service Elevation of Privilege Vulnerability
CVE-2026-69623
: Windows HTTP Print Provider Remote Code Execution Vulnerability
CVE-2026-69714
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69723
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69757
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69777
: Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2026-69779
: Windows Win32k
Remote Desktop Services adds another urgent item:
CVE-2026-69525
(CVSS score of 9.8) is a use-after-free bug that lets an unauthenticated in-network attacker execute arbitrary code.
organisation
Windows Ancillary Function
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
organisation
Windows SMB Client
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
organisation
Windows Modern Device Management
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
organisation
MDM
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
organisation
Windows Schannel
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
organisation
Windows Remote Access Connection
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
infrastructure
8.1
A second Exchange bug, CVE-2026-69380 (CVSS 8.1), is also a priority: it lets a low-privileged authenticated attacker impersonate any user in the organization and hijack every mailbox.
organisation
Buffer Overflow
CVE-2026-85880
is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.8.
organisation
Heap
CVE-2026-85880
is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.8.
organisation
Uninitialized Resource
CVE-2026-85880
is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.8.
organisation
CVE-2026-69845
CVE-2026-69845
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and Improper Input Validation and has a CVSS base score of 9.8.
organisation
CVE-2026-67631
CVE-2026-67631
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
organisation
CVE-2026-73023
CVE-2026-73023
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
organisation
CVE-2026-77495
CVE-2026-77495
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
organisation
Stack
CVE-2026-73006
is a remote code execution vulnerability associated with Stack-based Buffer Overflow and has a CVSS base score of 8.8.
organisation
CVE-2026-72986
CVE-2026-72986
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and Integer Overflow or Wraparound and has a CVSS base score of 8.8.
organisation
CVE-2026-69285
CVE-2026-69285
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
organisation
CVE-2026-69820
CVE-2026-69820
is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.2.
organisation
CVE-2026-67643
CVE-2026-67643
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
organisation
CVSS
CVE-2026-81963
is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.
Microsoft specifies an “in-network” requirement, but the CVSS network vector score suggests any network path could be relevant.
organisation
Improper Access Control
CVE-2026-81963
is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.
organisation
SharePoint
Microsoft also patched 17 SharePoint flaws, including four that allow remote code execution, and more than 60 SQL Server vulnerabilities.
infrastructure
60 SQL Server
Microsoft also patched 17 SharePoint flaws, including four that allow remote code execution, and more than 60 SQL Server vulnerabilities.
organisation
Authentication Bypass
CVE-2026-69676
is a remote code execution vulnerability associated with Authentication Bypass by Capture-replay and has a CVSS base score of 8.8.
organisation
CVE-2026-69730
CVE-2026-69730
is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 9.8.
organisation
Deserialization of Untrusted Data
CVE-2026-65772
is a remote code execution vulnerability associated with Deserialization of Untrusted Data and has a CVSS base score of 8.8.
organisation
External Control of File Name
CVE-2026-66302
is a remote code execution vulnerability associated with External Control of File Name or Path and has a CVSS base score of 9.8.
organisation
Untrusted Pointer Dereference
CVE-2026-67378
is a remote code execution vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.5.
organisation
Wraparound
CVE-2026-69499
is a remote code execution vulnerability associated with Integer Overflow or Wraparound and has a CVSS base score of 8.8.
organisation
CVE-2026-70296
CVE-2026-70296
is a remote code execution vulnerability associated with Out-of-bounds Write and has a CVSS base score of 9.8.
organisation
Double Free
CVE-2026-77493
is a remote code execution vulnerability associated with Double Free and has a CVSS base score of 9.8.
organisation
CVE-2026-69813
CVE-2026-69813
is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1.
organisation
CVE-2026-77505
CVE-2026-77505
is a remote code execution vulnerability associated with Use After Free and has a CVSS base score of 8.1.
organisation
DNS
One DNS flaw, CVE-2026-69730, has a CVSS score of 9.8.
organisation
SQL Copilot
One SQL Server flaw affects SQL Copilot in SQL Server Management Studio.
infrastructure
Android
Microsoft also fixed an Android Microsoft Authenticator flaw that can let a malicious app gain valid access tokens after the user completes an authentication step.
organisation
Snort 2
Snort 2 rule coverage: SIDs 67011-67032 and 67036-67084.
organisation
Chromium
Depending on how researchers count external and Chromium bugs, Microsoft fixed between 966 and 997 CVEs in this update.
organisation
Entra ID
The company also fixed another 204 vulnerabilities earlier in September across Azure, Entra ID, Edge, and other services.
CVE-2026-83941
affects Entra ID.
organisation
Update Stack
It is the first Update Stack vulnerability that Microsoft has confirmed attackers actively exploiting.
organisation
Exchange
“An unauthenticated attacker could send a specially crafted Visio attachment to an affected Exchange server.
organisation
RDP
RDP is everywhere in enterprise environments, and that CVSS score combined with the unauthenticated attack path makes this one worth treating as urgent regardless of the technical qualifier.
organisation
SigRed
ZDI calls it a “SigRed’s spiritual successor,” referring to the critical DNS flaw exploited in 2020.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Patch Tuesday)
organisation
Web Media Extensions
CVE-2026-81352
affects Web Media Extensions.
organisation
Authorization Bypass Through User-Controlled Key
CVE-2026-69857
is a spoofing vulnerability associated with Authorization Bypass Through User-Controlled Key and has a CVSS base score of 8.5.
organisation
Improper Authentication
CVE-2026-69854
is a elevation of privilege vulnerability associated with Improper Authentication and has a CVSS base score of 9.0.
organisation
HEVC Video Extensions
CVE-2026-58599
affects HEVC Video Extensions.
organisation
Microsoft Dynamics 365 On-Premises
CVE-2026-65772
affects Microsoft Dynamics 365 On-Premises.
organisation
Skype for Business
CVE-2026-66302
affects Skype for Business.
organisation
Improper Neutralization of Special Elements
CVE-2026-65669
is a elevation of privilege vulnerability associated with Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') and has a CVSS base score of 9.6.
organisation
CVE-2026-73006
CVE-2026-73006
affects DirectWrite.
organisation
DirectWrite
CVE-2026-73006
affects DirectWrite.
organisation
Microsoft Failover Cluster
CVE-2026-73010
and
CVE-2026-78444
affect Microsoft Failover Cluster.
organisation
Graphics Kernel
CVE-2026-73017
affects Graphics Kernel.
organisation
Microsoft Excel
CVE-2026-81948
,
CVE-2026-81950
,
CVE-2026-81951
,
CVE-2026-81959
, and
CVE-2026-81953
affect Microsoft Excel.
infrastructure
Microsoft Office
CVE-2026-78525
,
CVE-2026-78520
,
CVE-2026-78519
, and
CVE-2026-78509
affect Microsoft Office Outlook.
CVE-2026-69632
,
CVE-2026-77898
,
CVE-2026-69285
, and
CVE-2026-78505
affect Microsoft Office.
CVE-2026-78439
affects Microsoft Office Graphics Component.
CVE-2026-77504
affects Microsoft Office Word.
CVE-2026-69797
,
CVE-2026-69767
, and
CVE-2026-69678
affect Microsoft Office PowerPoint.
organisation
Microsoft Office Outlook
CVE-2026-78525
,
CVE-2026-78520
,
CVE-2026-78519
, and
CVE-2026-78509
affect Microsoft Office Outlook.
organisation
CVE-2026-78439
CVE-2026-78439
affects Microsoft Office Graphics Component.
organisation
Microsoft Office Graphics Component
CVE-2026-78439
affects Microsoft Office Graphics Component.
organisation
Microsoft Office Word
CVE-2026-77504
affects Microsoft Office Word.
organisation
Microsoft Office PowerPoint
CVE-2026-69797
,
CVE-2026-69767
, and
CVE-2026-69678
affect Microsoft Office PowerPoint.
organisation
Microsoft Word
CVE-2026-81952
and
CVE-2026-78510
affect Microsoft Word.
organisation
Virtual Hard Disk
CVE-2026-81355
affects Virtual Hard Disk (VHD) Miniport Driver.
organisation
Raw Image Extension
CVE-2026-69649
affects Raw Image Extension.
organisation
CVE-2026-72983
CVE-2026-72983
affects Internet Connection Sharing (ICS).
organisation
ICS
CVE-2026-72983
affects Internet Connection Sharing (ICS).
organisation
Concurrent Execution
CVE-2026-69710
is a elevation of privilege vulnerability associated with Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and has a CVSS base score of 7.5.
organisation
CVE-2026-69874
CVE-2026-69874
is a elevation of privilege vulnerability associated with Untrusted Pointer Dereference and has a CVSS base score of 8.2.
organisation
Microsoft WebP Image Extension
CVE-2026-70351
affects Microsoft WebP Image Extension.
organisation
Microsoft Entra ID
Other critical vulnerabilities:
CVE-2026-62916
affects Microsoft Entra ID.
organisation
Authentication Bypass Using
CVE-2026-62916
is a elevation of privilege vulnerability associated with Authentication Bypass Using an Alternate Path or Channel and has a CVSS base score of 9.1.
organisation
Missing Authorization
CVE-2026-83941
is a elevation of privilege vulnerability associated with Missing Authorization and has a CVSS base score of 9.9.
organisation
Improper Verification of Cryptographic Signature
CVE-2026-80098
is a elevation of privilege vulnerability associated with Improper Verification of Cryptographic Signature and has a CVSS base score of 9.3.
organisation
Microsoft Azure Active Directory B2C.
CVE-2026-83711
affects Microsoft Azure Active Directory B2C.
CVE-2026-83711
is a elevation of privilege vulnerability associated with Authorization Bypass Through User-Controlled Key and has a CVSS base score of 10.0.
organisation
CVE-2026-70178
CVE-2026-70178
affects Microsoft Fabric.
organisation
Microsoft Fabric
CVE-2026-70178
affects Microsoft Fabric.
organisation
Missing Authentication for Critical Function
CVE-2026-70352
is a elevation of privilege vulnerability associated with Missing Authentication for Critical Function and has a CVSS base score of 10.0.
organisation
CVE-2026-62906
CVE-2026-62906
affects Microsoft Discovery Studio.
organisation
Microsoft Discovery Studio
CVE-2026-62906
affects Microsoft Discovery Studio.
organisation
Data Query Logic
CVE-2026-62906
is a information disclosure vulnerability associated with Improper Neutralization of Special Elements in Data Query Logic and has a CVSS base score of 7.4.
organisation
Cisco Secure Firewall
Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU.
organisation
SRU
Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://
support.microsoft.com/en-us/se
rvicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update
https://
msrc.microsoft.com/update-guid
e/advisory/CVE-2026-62721
CVE-2026-85880
(CVSS score of 7.8) is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC).
CVE-2026-81963
(CVSS score of 7.8) flaw resides in the Windows Update Stack.
The affected components include DHCP Server, Active Directory, Windows DNS Server, SMB Client, Netlogon, NFS, RRAS, IP Helper, Message Queuing, and others.
CVE-2026-69601
affects Microsoft Windows Media Foundation.
CVE-2026-70203
affects Windows Media Player.
CVE-2026-72960
affects Windows Media Player.
Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:
CVE-2026-81963
affects Windows Update Stack.
CVE-2026-85880
affects Windows Advanced Local Procedure Call (ALPC).
Microsoft considers exploitation of the following vulnerabilities more likely:
CVE-2026-69676
affects Windows Kerberos.
CVE-2026-69852
affects Windows Routing and Remote Access Service (RRAS).
CVE-2026-72957
affects Windows Deployment Services.
CVE-2026-83501
affects Windows Virtualization-Based Security (VBS).
CVE-2026-70585
affects Windows Services for NFS ONCRPC XDR Driver.
CVE-2026-69730
affects Windows DNS Server.
Microsoft considers exploitation of the following vulnerabilities less likely:
CVE-2026-69845
and
CVE-2026-72979
affect Windows DHCP Server.
CVE-2026-69499
,
CVE-2026-70296
,
CVE-2026-73023
,
CVE-2026-77495
, and
CVE-2026-73013
affect Windows Imaging Component.
CVE-2026-69501
,
CVE-2026-83939
,
CVE-2026-69906
, and
CVE-2026-69846
affect Windows Secure Kernel Mode.
CVE-2026-69590
and
CVE-2026-72959
affect Windows Routing and Remote Access Service (RRAS).
CVE-2026-73009
affects Windows Secure Socket Tunneling Protocol (SSTP).
CVE-2026-77493
affects Windows Graphics Component.
CVE-2026-83498
affects Windows Virtualization-Based Security (VBS) Enclave.
CVE-2026-69530
,
CVE-2026-78449
, and
CVE-2026-78450
affect Windows Reliable Multicast Transport Driver (RMCAST).
CVE-2026-81354
affects Windows Hello.
CVE-2026-69595
and
CVE-2026-78445
affect Windows Services for NFS ONCRPC XDR Driver.
CVE-2026-69813
and
CVE-2026-77505
affect Windows DNS Server.
CVE-2026-69518
affects Windows Remote Desktop.
CVE-2026-69712
affects Windows Key Distribution Center.
Microsoft considers exploitation of the following vulnerabilities unlikely:
CVE-2026-69603
,
CVE-2026-72961
, and
CVE-2026-80083
affect Windows Hyper-V.
CVE-2026-69603
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
CVE-2026-69710
,
CVE-2026-69725
,
CVE-2026-69740
,
CVE-2026-69784
,
CVE-2026-69799
,
CVE-2026-69820
,
CVE-2026-69864
, and
CVE-2026-72980
affect Windows Hello.
CVE-2026-69769
affects Windows HTTP Print Provider.
CVE-2026-69829
affects Windows Shell.
CVE-2026-69860
affects Windows Imaging Component.
CVE-2026-69874
affects Windows ALPC.
CVE-2026-69890
affects Windows Virtual Trusted Platform Module.
CVE-2026-70586
affects Windows Paint.
CVE-2026-72950
affects Windows Routing and Remote Access Service (RRAS).
CVE-2026-72954
affects Windows Deployment Services.
CVE-2026-72958
affects Windows Credential Guard.
CVE-2026-72962
affects Windows USB Video Driver.
CVE-2026-72982
affects Windows Netlogon.
CVE-2026-72987
affects Windows DNS.
CVE-2026-81955
affects Windows Graphics Component.
CVE-2026-69858
and
CVE-2026-69827
affect Windows DNS Server.
CVE-2026-69579
affects Windows Message Queuing.
Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"
CVE-2026-68846
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-68876
: Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
CVE-2026-68880
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-68884
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69274
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-69277
: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
CVE-2026-69301
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-69305
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69310
: Windows DNS Elevation of Privilege Vulnerability
CVE-2026-69337
: Windows Registry Elevation of Privilege Vulnerability
CVE-2026-69364
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-69385
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69391
: Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
CVE-2026-69406
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69436
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69450
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69451
: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-69459
: Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
CVE-2026-69466
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69473
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69478
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69498
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-69525
: Remote Desktop Services Remote Code Execution Vulnerability
CVE-2026-69541
: Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability
CVE-2026-69585
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69600
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69605
: Microsoft Install Service Elevation of Privilege Vulnerability
CVE-2026-69623
: Windows HTTP Print Provider Remote Code Execution Vulnerability
CVE-2026-69714
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69723
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69757
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69777
: Windows DHCP Client Elevation of Privilege Vulnerability
CVE-2026-69779
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-69832
: Win32k Information Disclosure Vulnerability
CVE-2026-69911
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69921
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-70289
: Windows Win32k
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
Metrics
infrastructure
8.1
Software Version
A second Exchange bug, CVE-2026-69380 (CVSS 8.1), is also a priority: it lets a low-privileged authenticated attacker impersonate any user in the organization and hijack every mailbox.
Metrics
infrastructure
7.8
Software Version
CVE-2026-81963
(CVSS score of 7.8) flaw resides in the Windows Update Stack.
Metrics
infrastructure
60
Sql Server
Microsoft also patched 17 SharePoint flaws, including four that allow remote code execution, and more than 60 SQL Server vulnerabilities.
Metrics
infrastructure
Android
Affected Product
Microsoft also fixed an Android Microsoft Authenticator flaw that can let a malicious app gain valid access tokens after the user completes an authentication step.
Metrics
infrastructure
Microsoft Office
Affected Product
CVE-2026-78525
,
CVE-2026-78520
,
CVE-2026-78519
, and
CVE-2026-78509
affect Microsoft Office Outlook.
CVE-2026-69632
,
CVE-2026-77898
,
CVE-2026-69285
, and
CVE-2026-78505
affect Microsoft Office.
CVE-2026-78439
affects Microsoft Office Graphics Component.
CVE-2026-77504
affects Microsoft Office Word.
CVE-2026-69797
,
CVE-2026-69767
, and
CVE-2026-69678
affect Microsoft Office PowerPoint.
Metrics
infrastructure
8.8
Software Version
Microsoft considers exploitation of the following vulnerabilities unlikely:
CVE-2026-69603
,
CVE-2026-72961
, and
CVE-2026-80083
affect Windows Hyper-V.
CVE-2026-69603
is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 8.8.
Metrics
infrastructure
69,301
Server Elevation
Elevation of Privilege Vulnerability
CVE-2026-69277
: Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
CVE-2026-69301
: Windows Win32k Elevation of Privilege Vulnerability
CVE-2026-69305
: Microsoft Windows Search Component Elevation of Privilege Vulnerability
CVE-2026-69310
: Windows DNS Elevation of Privilege Vulnerability
CVE-2026-69337
: Windows Registry Elevation of Privilege Vulnerability
CVE-2026-69364
: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-69385
: Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-69391
: Windows Broker Infrastructure Service Elevation of Privilege Vulnerability
CVE-2026-69406
: Windows Kernel Information Disclosure Vulnerability
CVE-2026-69436
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69450
: Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2026-69451
: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-69459
: Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
CVE-2026-69466
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69473
: Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-69478
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-69498
: Windows Win32k
Metrics
data_breach
72,940
Windows Cloud Files Mini Filter Driver Elevation
Elevation of Privilege Vulnerability
CVE-2026-70342
: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-70562
: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-70583
: Windows Core Messaging Elevation of Privilege Vulnerability
CVE-2026-71340
: Windows File History Service Elevation of Privilege Vulnerability
CVE-2026-72936
: Windows SMB Client Remote Code Execution Vulnerability
CVE-2026-77500
: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-78454
: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-69460
: Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability
CVE-2026-69467
: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-80093
: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-72940
: Windows Schannel Remote Code Execution Vulnerability
CVE-2026-71343
: Windows Remote Access Connection Manager Remote Code Execution Vulnerability
CVE-2026-69366
: Windows Kernel Elevation of Privilege Vulnerability
A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its
update page
.
Intelligence Sources
Security Affairs
2026-09-09
Talos Intelligence
2026-09-08
Mastodon BrianKrebs
2026-09-14
Microsoft today released an out of band update that includes...
Mastodon BrianKrebs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-03T15:36
Comprehensive Tactical Telemetry
Highly Correlated Entities
168x
vulnerability
Exploited CVE
CVE-2026-62721
cve
154x
organisation
Identified Entity
Microsoft
entity
11x
timeline
Temporal Reference
2026/09/14
date
4x
tactic
Cyber Operation Type
Impersonate
tactic
3x
infrastructure
Affected Product
Windows
software
3x
vulnerability
CVSS Score
8
score
3x
infrastructure
Software Version
8.1
version
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
3x
general metric
Vulnerabilities
204
vulnerabilities
3x
general metric
Windows Kernel Elevation
68,880
windows kernel elevation
3x
general metric
Elevation
69,525
elevation
2x
general metric
Windows Error Reporting Elevation
69,450
windows error reporting elevation
2x
general metric
Virtual Hard Disk
69,585
virtual hard disk
Contextual Telemetry
Context Block
18 METRICS
general metric
Windows
11
windows
target region
Target Country
Montserrat
country
general metric
Sharepoint Flaws
17
sharepoint flaws
infrastructure
Sql Server
60
sql server
general metric
Days
2
days
general metric
Wormable Bugs
20
wormable bugs
industry
Targeted Sector
Media
sector
general metric
Critical Vulnerabilities
113
critical vulnerabilities
general metric
Microsoft Dynamics
365
microsoft dynamics
infrastructure
Server Elevation
69,301
server elevation
general metric
Windows Service Elevation
69,406
windows service elevation
general metric
Windows Instrumentation Elevation
69,459
windows instrumentation elevation
general metric
Dependency Coordinator Elevation
69,466
dependency coordinator elevation
general metric
Microsoft Component Elevation
69,600
microsoft component elevation
general metric
Windows Audio Service Elevation
70,583
windows audio service elevation
data breach
Windows Cloud Files Mini Filter Driver Elevation
72,940
windows cloud files mini filter driver elevation
general metric
Rule Coverage
3
rule coverage
general metric
Sids
301,632
sids
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.