September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
Microsoft released a record-breaking 973 vulnerabilities this Patch Tuesday, the largest to date. Among these, two were exploited in the wild, including a critical Remote Code Execution (RCE) vulnerability in Skype for Business and a stack elevation of privilege vulnerability in Windows Update. Several other vulnerabilities, including those in MSMQ, RRAS, and various Azure services, were also addressed. Organizations should prioritize patching these critical flaws, especially those actively being exploited, to mitigate potential risks.
This month, Microsoft released a massive 973 security updates as part of Patch Tuesday, significantly surpassing the previous high of 664. Two vulnerabilities were confirmed to be exploited in the wild, highlighting the urgency of addressing these issues. Notably, CVE-2026-81963, a Windows Update Stack Elevation of Privilege Vulnerability, carries a CVSS score of 7.8 and allows a local, authenticated attacker with low privileges to escalate to SYSTEM privileges. This vulnerability is being actively exploited.
Another critical RCE vulnerability, CVE-2026-66302, affects Skype for Business Server, with a CVSS score of 9.8. This allows an unauthenticated attacker to send a specially crafted network request, potentially leading to code execution on the server without authentication. Microsoft reports that this vulnerability was not publicly disclosed before Patch Tuesday and is not currently in CISA’s Known Exploited Vulnerabilities catalogue.
Beyond these, several other vulnerabilities were addressed, including:
- **Windows Message Queuing Remote Code Execution Vulnerability (CVE-2026-69579):** A use-after-free flaw in Windows Message Queuing, exploitable remotely by an unauthenticated attacker, potentially leading to code execution with high impact.
- **Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (CVE-2026-69590):** An unauthenticated remote attacker could exploit this flaw by sending a specially crafted packet, potentially allowing code execution on the target system.
- **Skype for Business Remote Code Execution Vulnerability (CVE-2026-66302):** As mentioned above, this is a Critical RCE vulnerability in Skype for Business Server with a CVSS score of 9.8, affecting specific versions and allowing unauthenticated attackers to execute code.
- **Various Azure Services:** Several vulnerabilities were identified within Azure services, including Azure AI Language, Azure Arc SQL Server Extension, Azure Cosmos DB Spoofing, and Microsoft Authentication Library (MSAL) for Node.js.
- **Microsoft Products:** Numerous vulnerabilities were found in Microsoft products like Microsoft Excel, Microsoft Dynamics 365 On-Premises, Microsoft COM for Windows, and Microsoft Authenticator.
Microsoft lists the following vulnerabilities and their status:
- **CVE-2026-69805:** No, No - Important 7.5
- **CVE-2026-69806:** No, No - Important 7.0
- **CVE-2026-58649:** No, No - Important 6.5
- **CVE-2026-69439:** No, No - Important 8.8
- **CVE-2026-71328:** No, No - Important 8.8
- **CVE-2026-71328:** No, No - Important 8.8
- **CVE-2026-62810:** No, No - Important 7.8
- **CVE-2026-69821:** No, No - Important 7.8
- **CVE-2026-69395:** No, No - Important 6.5
- **CVE-2026-69624:** No, No - Important 6.5
- **CVE-2026-69359:** No, No - Important 7.8
- **CVE-2026-69470:** No, No - Important 7.0
- **CVE-2026-80098:** No, No - Important 9.3
- **CVE-2026-73014:** No, No - Important 7.8
- **CVE-2026-69857:** No, No - Important 8.5
- **CVE-2026-77909:** No, No - Important 8.8
- **CVE-2026-81349:** No, No - Important 7.2
- **CVE-2026-69516:** No, No - Important 7.0
- **CVE-2026-68824:** No, No - Important 7.0
- **CVE-2026-68847:** No, No - Important 7.0
- **CVE-2026-69470:** No, No - Important 7.0
- **CVE-2026-80097:** No, No - Important 8.6
- **CVE-2026-62906:** No, No - Important 7.4
- **CVE-2026-81387:** No, No - Important 5.5
- **CVE-2026-81390:** No, No - Important 5.5
- **CVE-2026-81391:** No, No - Important 5.5
- **CVE-2026-81392:** No, No - Important 5.5
- **CVE-2026-81393:** No, No - Important 5.5
- **CVE-2026-81394:** No, No - Important 5.5
- **CVE-2026-81395:** No, No - Important 5.5
- **CVE-2026-81399:** No, No - Important 5.5
Organizations should prioritize applying these critical security updates promptly, especially those actively being exploited. Monitoring exposed deployments, logging, and access controls for signs of suspicious activity is also recommended. A detailed list of this month's vulnerabilities and their status can be found at: https://patchlens.io