Home › Microsoft Patch Tuesday › September 2026

Microsoft Patch Tuesday, September 2026

·

Microsoft's September 2026 security release, published September 8, 2026: 60 updates fixing 1,169 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 2 CVEs from this release are on the Senserva hot list today (as of 2026-09-27), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
60
Updates (KBs)
1,169
CVEs fixed
2
Exploited zero-day
2
On the CISA KEV list
118
Critical, rated by Microsoft

Severity, as Microsoft rates it

Critical 118Important 910Moderate 104Low 14No rating 23

That covers 1,146 of the 1,169; the remaining 23 carry no Severity rating at all.

Zero-days in this release

CVE-2026-81963Windows Update StackCVSS 7.8Exploited
CVE-2026-85880Windows Advanced Local Procedure Call (ALPC)CVSS 7.8Exploited

Actively exploited CVEs (CISA KEV)

CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow VulnerabilityExploited Hot now
CVE-2026-81963Microsoft Windows Link Following VulnerabilityExploited Hot now

Other high-risk CVEs (CVSS 8.8+)

CVE-2026-68839Windows USB Mass Storage Class Driver Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69276Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69408Microsoft Windows Media Foundation Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69431Telnet Client Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69463Windows NTFS Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69491Microsoft DirectMusic Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69493Windows Event Logging Service Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69496Windows Compressed Folder Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69525Remote Desktop Services Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69579Windows Message Queuing Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69586Microsoft Windows PDF Remote Code Execution VulnerabilityCVSS 9.8
CVE-2026-69590Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 9.8

Products fixed this month

Microsoft Office 2016 (32-bit edition) (6)Microsoft Office 2016 (64-bit edition) (6)Microsoft SQL Server 2017 for x64-based Systems (GDR) (3)Windows 10 Version 1607 for 32-bit Systems (2)Windows 10 Version 1607 for x64-based Systems (2)Windows Server 2016 (2)Windows 11 version 26H1 for x64-based Systems (2)Windows 11 Version 26H1 for ARM64-based Systems (2)Microsoft SQL Server 2022 for x64-based Systems (CU 25) (2)Microsoft SQL Server 2025 for x64-based Systems (CU6) (2)

Every update in this release

All 61 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5122876 ExploitedCritical9.8616Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5122882 ExploitedCritical9.8641Windows Server 2022, Windows Server 2022 (Server Core installation)Support · Catalog
KB5122878 ExploitedCritical9.8568Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5123099 ExploitedCritical9.8555Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5123065 ExploitedCritical9.8393Windows Server 2012, Windows Server 2012 (Server Core installation)Support · Catalog
KB5123066 ExploitedCritical9.8418Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)Support · Catalog
KB5122871 ExploitedCritical9.8679Windows Server 2025 (Server Core installation), Windows Server 2025Support · Catalog
KB5124008 ExploitedCritical9.8628Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based SystemsSupport · Catalog
KB5122880 ExploitedCritical9.8602Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based SystemsSupport · Catalog
KB5124012 ExploitedCritical9.8627Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based SystemsSupport · Catalog
KB5122773Critical9.852Microsoft SQL Server 2019 for x64-based Systems (GDR)Support · Catalog
KB5122771Critical9.852Microsoft SQL Server 2022 for x64-based Systems (GDR)Support · Catalog
KB5122770Critical9.856Microsoft SQL Server 2025 for x64-based Systems (GDR)Support · Catalog
KB5122772Critical9.852Microsoft SQL Server 2019 for x64-based Systems (CU 32)Support · Catalog
KB5122769Critical9.856Microsoft SQL Server 2025 for x64-based Systems (CU8)Support · Catalog
KB5122768Critical9.852Microsoft SQL Server 2022 for x64-based Systems (CU 26)Support · Catalog
KB5101347Critical9.85Microsoft SQL Server 2022 for x64-based Systems (CU 25), Microsoft SQL Server 2025 for x64-based Systems (CU6), Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5101346Critical9.88Microsoft SQL Server 2025 for x64-based Systems (CU6), Microsoft SQL Server 2022 for x64-based Systems (CU 25), Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5123301Critical9.810Skype for Business Server 2015 CU13Support · Catalog
KB5123287Critical9.810Skype for Business Server Subscription Edition CU1Support · Catalog
KB5123300Critical9.810Skype for Business Server 2019 CU8Support · Catalog
KB5122775Critical9.845Microsoft SQL Server 2017 for x64-based Systems (GDR)Support · Catalog
KB5122774Critical9.845Microsoft SQL Server 2017 for x64-based Systems (CU 31)Support · Catalog
KB5002923Critical9.831Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition), Microsoft Word 2016 (32-bit edition)Support · Catalog
KB5121610Critical9.39Microsoft Exchange Server 2019 Cumulative Update 14Support · Catalog
KB5121609Critical9.39Microsoft Exchange Server 2019 Cumulative Update 15Support · Catalog
KB5121608Critical9.39Microsoft Exchange Server Subscription Edition RTMSupport · Catalog
KB5121611Critical9.38Microsoft Exchange Server 2016 Cumulative Update 23Support · Catalog
KB5126105High8.86.NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows, .NET 9.0 installed on LinuxSupport · Catalog
KB5126106High8.86.NET 10.0 installed on Windows, .NET 10.0 installed on Linux, .NET 10.0 installed on Mac OSSupport · Catalog
KB5002644High8.82Microsoft Publisher 2016 (32-bit edition), Microsoft Publisher 2016 (64-bit edition)Support · Catalog
KB5002908High8.816Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5123731High8.81Microsoft Dynamics 365 Customer Engagement V9.1Support · Catalog
KB5002920High8.86Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition)Support · Catalog
KB5002916High8.818Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition), Microsoft Word 2016 (32-bit edition)Support · Catalog
KB5002919High8.83Microsoft Outlook 2016 (32-bit edition), Microsoft Outlook 2016 (64-bit edition)Support · Catalog
KB5002898High8.82Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5126104High8.85.NET 8.0 installed on Windows, .NET 8.0 installed on Mac OS, .NET 8.0 installed on LinuxSupport · Catalog
KB5126049High8.82Microsoft .NET Framework 4.8 on Windows Server 2012Support · Catalog
KB5126047High8.82Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based SystemsSupport · Catalog
KB5126051High8.82Microsoft .NET Framework 4.8 on Windows Server 2012 R2Support · Catalog
KB5126421High8.82Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based SystemsSupport · Catalog
KB5126048High8.82Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019Support · Catalog
KB5126050High8.82Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022Support · Catalog
KB5126046High8.82Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based SystemsSupport · Catalog
KB5126043High8.82Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based SystemsSupport · Catalog
KB5126044High8.82Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012Support · Catalog
KB5126045High8.82Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2Support · Catalog
KB5126053High8.82Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based SystemsSupport · Catalog
KB5126422High8.82Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022Support · Catalog
KB5126052High8.82Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based SystemsSupport · Catalog
KB5126424High8.82Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based SystemsSupport · Catalog
KB5126042High8.82Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012Support · Catalog
KB5002912High8.82Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)Support · Catalog
KB5002914High8.830Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)Support · Catalog
KB5002904High8.830Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5122874High8.81Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016Support · Catalog
KB5002913High8.82Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition), Microsoft Access 2016 (32-bit edition)Support · Catalog
KB4011160High8.81Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5129194High8.22Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based SystemsSupport · Catalog
KB5002910High7.84Office Online ServerSupport · Catalog
Take this release to your AI

Composed from the September 2026 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Now see your own patch state.

Senserva reads your Microsoft 365, Intune, Defender, and Entra ID environment and turns this release into your list: every update still missing, on every device, ranked by what attackers are actually exploiting. The 650+ configuration checks come with it.

1Find it2Fix it3Prove it
Start my free patch auditAll you do is register.
Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.