<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac" -->

---
title: September 2026 Microsoft Patch Tuesday | daily.dev
description: Microsoft&#x27;s September 2026 Patch Tuesday addressed 964 CVEs, the largest release in its history, with 104 rated critical and 860 important. Two zero-day...
canonical: https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: September 2026 Microsoft Patch Tuesday | daily.dev
og:description: Microsoft&#x27;s September 2026 Patch Tuesday addressed 964 CVEs, the largest release in its history, with 104 rated critical and 860 important. Two zero-day...
og:url: https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac
og:image: https://api.daily.dev/og/posts/oZj18FHAc.png
og:image:alt: September 2026 Microsoft Patch Tuesday
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# September 2026 Microsoft Patch Tuesday

**[Tenable Blog](https://daily.dev/sources/tenable-blog)** · 8 min read · 1 upvotes · 0 comments

## Summary

Microsoft's September 2026 Patch Tuesday addressed 964 CVEs, the largest release in its history, with 104 rated critical and 860 important. Two zero-day vulnerabilities exploited in the wild were patched: CVE-2026-81963 (Windows Update Stack elevation of privilege) and CVE-2026-85880 (Windows ALPC elevation of privilege), both with CVSSv3 7.8. Other notable flaws include CVE-2026-69380 (Exchange Server EoP), CVE-2026-69525 (Remote Desktop Services RCE, CVSS 9.8), CVE-2026-69730 (Windows DNS Server RCE, CVSS 9.8, critical), and CVE-2026-69676 (Windows Kerberos RCE, CVSS 8.8). Elevation of privilege bugs made up 44.7% of patches, remote code execution 26.8%. Tenable recommends prompt patching and regular vulnerability scanning.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880>

## Questions this post answers

### How many CVEs did Microsoft patch in the September Patch Tuesday release with the CVE-2026-81963 and CVE-2026-85880 zero-days?

Microsoft patched 964 CVEs in that release, the largest Patch Tuesday release in its history, with 104 rated critical and 860 rated important. Two zero-day vulnerabilities were exploited in the wild: CVE-2026-81963, a Windows Update Stack elevation of privilege flaw, and CVE-2026-85880, a Windows ALPC elevation of privilege flaw, both scoring 7.8 on CVSSv3.

_Security teams tracking record-breaking patch cycles can follow Windows CVE disclosures on daily.dev._

### What is CVE-2026-85880 and why is it notable for Windows ALPC?

CVE-2026-85880 is an elevation of privilege vulnerability in Windows Advanced Local Procedure Call (ALPC), scoring 7.8 on CVSSv3, exploited in the wild as a zero-day allowing attackers to gain SYSTEM-level privileges. It is the first ALPC vulnerability included in Patch Tuesday in over three years, since April 2023, and only the second ALPC zero-day exploited since CVE-2023-21674 in January 2023.

_Developers securing Windows infrastructure can track recurring ALPC and kernel flaws on daily.dev._

### What is the exploitability of CVE-2026-69730 affecting Windows DNS Server?

CVE-2026-69730 is a critical remote code execution vulnerability in Windows DNS Server with a CVSSv3 score of 9.8, assessed by Microsoft as 'Exploitation More Likely.' An unauthenticated remote attacker could send a crafted packet exploiting a use-after-free flaw to achieve remote code execution. Eight additional Windows DNS Server RCEs were patched the same month with lower exploitability ratings.

_Admins prioritizing critical DNS server patches can monitor exploitability ratings via daily.dev._

## Similar posts on daily.dev

- [June 2026 Microsoft Patch Tuesday](https://daily.dev/posts/june-2026-microsoft-patch-tuesday-soc9er861) · Tenable Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#microsoft](https://daily.dev/tags/microsoft), [#windows](https://daily.dev/tags/windows), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"September 2026 Microsoft Patch Tuesday","url":"https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac"},"datePublished":"2026-09-08T18:16:06.610Z","dateModified":"2026-09-09T00:31:19.686Z","description":"Microsoft's September 2026 Patch Tuesday addressed 964 CVEs, the largest release in its history, with 104 rated critical and 860 important. Two zero-day...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ea778a00a8c5a8ae8fff286298f7d60e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ea778a00a8c5a8ae8fff286298f7d60e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Tenable Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Tenable Blog","logo":"https://media.daily.dev/image/upload/s--B6GAvw3H--/f_auto,q_auto/v1780213271/logos/tenable-blog?_a=BAMAMiWQ0","url":"https://daily.dev/sources/tenable-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,microsoft,windows,zero-day","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Tenable Blog","item":"https://daily.dev/sources/tenable-blog"},{"@type":"ListItem","position":3,"name":"September 2026 Microsoft Patch Tuesday"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/september-2026-microsoft-patch-tuesday-ozj18fhac#faq","mainEntity":[{"@type":"Question","name":"How many CVEs did Microsoft patch in the September Patch Tuesday release with the CVE-2026-81963 and CVE-2026-85880 zero-days?","acceptedAnswer":{"@type":"Answer","text":"Microsoft patched 964 CVEs in that release, the largest Patch Tuesday release in its history, with 104 rated critical and 860 rated important. Two zero-day vulnerabilities were exploited in the wild: CVE-2026-81963, a Windows Update Stack elevation of privilege flaw, and CVE-2026-85880, a Windows ALPC elevation of privilege flaw, both scoring 7.8 on CVSSv3. Security teams tracking record-breaking patch cycles can follow Windows CVE disclosures on daily.dev."}},{"@type":"Question","name":"What is CVE-2026-85880 and why is it notable for Windows ALPC?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-85880 is an elevation of privilege vulnerability in Windows Advanced Local Procedure Call (ALPC), scoring 7.8 on CVSSv3, exploited in the wild as a zero-day allowing attackers to gain SYSTEM-level privileges. It is the first ALPC vulnerability included in Patch Tuesday in over three years, since April 2023, and only the second ALPC zero-day exploited since CVE-2023-21674 in January 2023. Developers securing Windows infrastructure can track recurring ALPC and kernel flaws on daily.dev."}},{"@type":"Question","name":"What is the exploitability of CVE-2026-69730 affecting Windows DNS Server?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-69730 is a critical remote code execution vulnerability in Windows DNS Server with a CVSSv3 score of 9.8, assessed by Microsoft as 'Exploitation More Likely.' An unauthenticated remote attacker could send a crafted packet exploiting a use-after-free flaw to achieve remote code execution. Eight additional Windows DNS Server RCEs were patched the same month with lower exploitability ratings. Admins prioritizing critical DNS server patches can monitor exploitability ratings via daily.dev."}}]}
```

