Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats.
This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August.
Microsoft Patch Tuesday for September 2026
This month’s release addresses 974 vulnerabilities, including 113 critical and 860 important-severity vulnerabilities.
In this month’s updates, Microsoft has addressed two vulnerabilities that have been exploited in the wild.
Microsoft has not addressed any vulnerabilities in Microsoft Edge (Chromium-based) in this month’s update.
Microsoft Patch Tuesday, September edition, includes updates for vulnerabilities in Windows HTTP.sys, Windows Hyper-V, GitHub Copilot, and Visual Studio Code, Copilot Studio, Data Sharing Service Client, Entra ID, Microsoft Exchange Server, and more.
This month’s release includes fixes for several high-severity issues that could potentially enable remote code execution, privilege escalation, or denial-of-service attacks. As always, timely patch deployment is crucial to reduce exposure and ensure systems remain resilient against exploitation attempts.
The September 2026 Microsoft vulnerabilities are classified as follows:
| Vulnerability Category | Quantity | Severities |
| Spoofing Vulnerability | 16 | Critical: 1 Important: 15 |
| Denial of Service Vulnerability | 56 | Important: 56 |
| Elevation of Privilege Vulnerability | 438 | Critical: 27 Important: 411 |
| Information Disclosure Vulnerability | 173 | Critical: 2 Important: 171 |
| Remote Code Execution Vulnerability | 253 | Critical: 82 Important: 171 |
| Security Feature Bypass Vulnerability | 19 | Critical: 1 Important: 18 |
Adobe Patch for September 2026
Adobe has released nine advisories addressing 170 vulnerabilities across Adobe Experience Manager, Adobe ColdFusion, Adobe Photoshop, Adobe Illustrator, Adobe Animate, Adobe Commerce, Adobe Acrobat Reader, and Adobe Campaign Classic. 50 of these vulnerabilities are rated critical. Successful exploitation of these vulnerabilities may lead to privilege escalation, arbitrary code execution, security feature bypass, and arbitrary file system read.
Zero-day Vulnerabilities Patched in September Patch Tuesday Edition
CVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerability
A link following flaw in the Windows Update Stack may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
CISA added the CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026.
CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
The heap-based buffer overflow flaw in Windows ALPC may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
CISA added the CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026.
Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition
CVE-2026-58599: HEVC Video Extensions Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code locally.
CVE-2026-62906: Microsoft Discovery Studio Information Disclosure Vulnerability
Improper neutralization of special elements in data query logic within Microsoft Discovery Studio may allow an unauthenticated attacker to disclose information over a network.
CVE-2026-62916: Microsoft Entra ID Elevation of Privilege Vulnerability
An authentication bypass using an alternate path or channel in Microsoft Entra ID may allow an unauthenticated attacker to elevate privileges over a network.
CVE-2026-65669: Microsoft SQL Server Elevation of Privilege Vulnerability
The code injection flaw in SQL Server may allow an unauthenticated attacker to elevate privileges over a network.
CVE-2026-65772: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
The deserialization of untrusted data in Microsoft Dynamics 365 may allow an authenticated attacker to execute code over a network.
CVE-2026-69632, CVE-2026-69678, CVE-2026-69767, & CVE-2026-69797: Microsoft Office PowerPoint Remote Code Execution Vulnerability
The use-after-free flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, & CVE-2026-72987: Windows DNS Server Remote Code Execution Vulnerability
The use-after-free flaw in Windows DNS may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69860, CVE-2026-73013, CVE-2026-73023, & CVE-2026-77495: Windows Imaging Component Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69590, CVE-2026-69852, CVE-2026-72950, & CVE-2026-72959: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Successful exploitation of the vulnerability may allow an attacker to gain unauthenticated access to the victim’s machine.
CVE-2026-81948, CVE-2026-81951, & CVE-2026-81959: Microsoft Excel Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
CVE-2026-69530, CVE-2026-78449, & CVE-2026-78450: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
The use-after-free flaw in the Reliable Multicast Transport Driver (RMCAST) may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69740, CVE-2026-69784, & CVE-2026-69864: Windows Hello Elevation of Privilege Vulnerability
The use-after-free in Windows Hello may allow an authenticated attacker to elevate privileges locally.
CVE-2026-72986 & CVE-2026-73018: Graphic Fonts Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Graphic Fonts may allow an unauthenticated attacker to execute code over a network.
CVE-2026-73006 & CVE-2026-78439: Microsoft Office Graphics Component Remote Code Execution Vulnerability
The stack-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69285 & CVE-2026-78505: Microsoft Office Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Microsoft Office may allow an unauthenticated attacker to execute code over a network.
CVE-2026-78509 & CVE-2026-78510: Microsoft Office Outlook Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
CVE-2026-67631 & CVE-2026-67643: Microsoft SQL Server Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in SQL Server may allow an authenticated attacker to execute code over a network.
CVE-2026-69710 & CVE-2026-69799: Windows Hello Elevation of Privilege Vulnerability
A race condition in Windows Hello may allow an authenticated attacker to elevate privileges locally.
CVE-2026-69820 & CVE-2026-81354: Windows Hello Elevation of Privilege Vulnerability
The heap-based buffer overflow flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally.
CVE-2026-70203 & CVE-2026-72960: Windows Media Player Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Media Player may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69501 & CVE-2026-83939: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
CVE-2026-69595 & CVE-2026-78445: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
The use-after-free flaw in Windows Services for NFS ONCRPC XDR Driver may allow an unauthenticated attacker to execute code over a network.
CVE-2026-65818: Power Automate Elevation of Privilege Vulnerability
The server-side request forgery (SSRF) flaw in Power Automate may allow an authenticated attacker to elevate privileges over a network.
CVE-2026-66302: Skype for Business Remote Code Execution Vulnerability
Successful exploitation of the vulnerability may allow an unauthenticated attacker to execute code over a network.
CVE-2026-67378: Microsoft SQL Server Remote Code Execution Vulnerability
Successful exploitation of the vulnerability may allow an authenticated attacker to execute code over a network.
CVE-2026-67636: Microsoft SQL Server Remote Code Execution Vulnerability
An out-of-bounds read flaw in SQL Server may allow an authenticated attacker to execute code over a network.
CVE-2026-69499: Windows Imaging Component Remote Code Execution Vulnerability
An integer overflow flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69518: Windows Remote Desktop Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Remote Desktop may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69579: Windows Message Queuing Remote Code Execution Vulnerability
The use-after-free flaw in Windows Message Queuing may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69601: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Microsoft Windows Media Foundation may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69603: Windows Hyper-V Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Hyper-V may allow an authenticated attacker to execute code locally.
CVE-2026-69676: Windows Kerberos Remote Code Execution Vulnerability
An authentication-bypass flaw via capture-replay in Windows Kerberos may allow an authenticated attacker to execute code over a network.
CVE-2026-69712: Windows Key Distribution Center Remote Code Execution Vulnerability
The use-after-free flaw in the Windows Key Distribution Center may allow an authenticated attacker to execute code over a network.
CVE-2026-69725: Windows Hello Elevation of Privilege Vulnerability
A double-free flaw in Windows Hello may allow an authenticated attacker to elevate privileges locally.
CVE-2026-69769: Windows HTTP Print Provider Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows HTTP Print Provider may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69829: Windows Shell Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Shell may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69845: Windows DHCP Server Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows DHCP Server may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69846: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
An integer overflow flaw in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
CVE-2026-69854: Spring Cloud Azure Elevation of Privilege Vulnerability
An improper authentication flaw in Spring Cloud Azure may allow an unauthenticated attacker to elevate privileges over a network.
CVE-2026-69857: Azure Cosmos DB Spoofing Vulnerability
An authorization bypass via a user-controlled key in Azure Cosmos DB may allow an authenticated attacker to perform network spoofing.
CVE-2026-69874: Windows ALPC Elevation of Privilege Vulnerability
Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges locally.
CVE-2026-69890: Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability
The use-after-free flaw in the Windows Virtual Trusted Platform Module may allow an authenticated attacker to elevate local privileges.
CVE-2026-69906: Windows Secure Kernel Mode Elevation of Privilege Vulnerability
The heap-based buffer overflow flaw in Windows Secure Kernel Mode may allow an authenticated attacker to elevate privileges locally.
CVE-2026-70178: Microsoft Fabric Elevation of Privilege Vulnerability
A missing authorization flaw in Microsoft Fabric may allow an authenticated attacker to elevate privileges over a network.
CVE-2026-70296: Windows Imaging Component Remote Code Execution Vulnerability
An out-of-bounds write flaw in Windows Imaging Component may allow an unauthenticated attacker to execute code over a network.
CVE-2026-70351: Microsoft WebP Image Extension Remote Code Execution Vulnerability
An integer overflow flaw in Microsoft WebP Image Extension may allow an unauthenticated attacker to execute code over a network.
CVE-2026-70352: Azure AI Language Elevation of Privilege Vulnerability
A missing authentication for a critical function in Azure AI Language may allow an unauthenticated attacker to elevate privileges over a network.
CVE-2026-70585: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
The use-after-free flaw in Windows Services for NFS ONCRPC XDR Driver may allow an authenticated attacker to execute code locally.
CVE-2026-70586: Windows Paint Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Paint may allow an unauthenticated attacker to execute code over a network.
CVE-2026-72954: Windows Deployment Services Remote Code Execution Vulnerability
The use-after-free flaw in Windows Deployment Services may allow an authenticated attacker to execute code over a network.
CVE-2026-72957: Windows Deployment Services Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Deployment Services may allow an authenticated attacker to execute code locally.
CVE-2026-72958: Windows Credential Guard Elevation of Privilege Vulnerability
A double-free flaw in Windows Credential Guard may allow an authenticated attacker to elevate privileges locally.
CVE-2026-72961: Windows Hyper-V Elevation of Privilege Vulnerability
An out-of-bounds read flaw in Windows Hyper-V may allow an authenticated attacker to elevate privileges locally.
CVE-2026-72962: Windows USB Video Driver Elevation of Privilege Vulnerability
The heap-based buffer overflow flaw in the Windows USB Video Driver may allow an authenticated attacker to elevate local privileges.
CVE-2026-72979: Windows DHCP Server Remote Code Execution Vulnerability
The use-after-free flaw in Windows DHCP Server may allow an unauthenticated attacker to execute code over a network.
CVE-2026-72980: Windows Hello Security Feature Bypass Vulnerability
An uncontrolled search path element in Windows Hello may allow an authenticated attacker to bypass a security feature locally.
CVE-2026-72981: IP Helper Remote Code Execution Vulnerability
The use-after-free flaw in IP Helper may allow an unauthenticated attacker to execute code over a network.
CVE-2026-72982: Windows Netlogon Remote Code Execution Vulnerability
The stack-based buffer overflow flaw in Windows Netlogon may allow an unauthenticated attacker to execute code over a network.
CVE-2026-72983: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
The use-after-free flaw in Windows Internet Connection Sharing (ICS) may allow an unauthenticated attacker to execute code over a network.
CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
The use-after-free flaw in Windows Secure Socket Tunneling Protocol (SSTP) may allow an unauthenticated attacker to execute code over a network.
CVE-2026-73010: Microsoft Failover Cluster Remote Code Execution Vulnerability
The use-after-free flaw in Windows Failover Cluster may allow an unauthenticated attacker to execute code over a network.
CVE-2026-73017: Graphics Kernel Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Graphics Kernel may allow an authenticated attacker to execute code locally.
CVE-2026-77493: Microsoft Office Outlook Remote Code Execution Vulnerability
A double-free flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
CVE-2026-77504: Microsoft Office Word Remote Code Execution Vulnerability
A double-free flaw in Microsoft Office Word may allow an unauthenticated attacker to execute code over a network.
CVE-2026-77505: Windows DNS Server Remote Code Execution Vulnerability
The use-after-free flaw in the DNS Server may allow an unauthenticated attacker to execute code over a network.
CVE-2026-77898: Microsoft Office PowerPoint Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Microsoft Office PowerPoint may allow an unauthenticated attacker to execute code over a network.
CVE-2026-78444: Microsoft Failover Cluster Remote Code Execution Vulnerability
An untrusted pointer dereference flaw in Windows Failover Cluster may allow an unauthenticated attacker to execute code over a network.
CVE-2026-78519: Microsoft Office Outlook Remote Code Execution Vulnerability
Use of an uninitialized resource in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
CVE-2026-78520: Microsoft Office Outlook Information Disclosure Vulnerability
An out-of-bounds read flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
CVE-2026-78525: Microsoft Office Outlook Remote Code Execution Vulnerability
A use-after-free flaw in Microsoft Office Outlook may allow an unauthenticated attacker to execute code over a network.
CVE-2026-80083: Windows Hyper-V Remote Code Execution Vulnerability
An untrusted pointer dereference flaw in Windows Hyper-V may allow an authenticated attacker to execute code locally.
CVE-2026-80098: Copilot Studio Elevation of Privilege Vulnerability
An improper verification of a cryptographic signature in Copilot Studio may allow an unauthenticated attacker to elevate privileges over a network.
CVE-2026-81352: Web Media Extensions Remote Code Execution Vulnerability
The heap-based buffer overflow in the Microsoft Windows Codecs Library may allow an unauthenticated attacker to execute code over a network.
CVE-2026-81355: Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability
The heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver may allow an authenticated attacker to execute code locally.
CVE-2026-81949: Microsoft Excel Remote Code Execution Vulnerability
An integer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
CVE-2026-81950: Microsoft Excel Remote Code Execution Vulnerability
A double-free flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
CVE-2026-81952: Microsoft Word Remote Code Execution Vulnerability
The heap-based buffer overflow in Microsoft Office Word may allow an unauthenticated attacker to execute code over a network.
CVE-2026-81953: Microsoft Excel Remote Code Execution Vulnerability
The stack-based buffer overflow flaw in Microsoft Office Excel may allow an unauthenticated attacker to execute code locally.
CVE-2026-81955: Windows Graphics Component Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Microsoft Graphics Component may allow an unauthenticated attacker to execute code over a network.
CVE-2026-83711: Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
An authorization bypass through a user-controlled key in Microsoft Azure Active Directory B2C may allow an unauthenticated attacker to elevate privileges over a network.
CVE-2026-83941: Entra ID Elevation of Privilege Vulnerability
A missing authorization flaw in Entra ID may allow an authenticated attacker to elevate privileges over a network.
CVE-2026-83498: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
An untrusted pointer dereference flaw in Windows Virtualization-Based Security (VBS) Enclave may allow an authenticated attacker to elevate privileges locally.
CVE-2026-83501: Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
An out-of-bounds read flaw in Windows Virtualization-Based Security (VBS) Enclave may allow an authenticated attacker to disclose information locally.
CVE-2026-69649: Raw Image Extension Remote Code Execution Vulnerability
The heap-based buffer overflow flaw in Windows Raw Image Extension may allow an unauthenticated attacker to execute code over a network.
CVE-2026-69827: Windows DNS Server Remote Code Execution Vulnerability
A race condition flaw in the DNS Server may allow an unauthenticated attacker to execute code over a network.
Other Microsoft Vulnerability Highlights
- CVE-2026-69467 is an elevation of privilege vulnerability in the Microsoft Graphics Component. A stack-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-68846 is an elevation of privilege vulnerability in the Windows Kernel. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-68876 is an elevation of privilege vulnerability in the Windows Program Compatibility Assistant Service. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-68880 is an elevation of privilege vulnerability in the Windows Win32k. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-68884 is an elevation of privilege vulnerability in the Windows Kernel. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69274 is an elevation of privilege vulnerability in the Windows Win32k. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69277 is an elevation of privilege vulnerability in the Microsoft Local Security Authority (LSA) Server. A stack-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69301 is an elevation of privilege vulnerability in the Windows Win32k. A stack-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69305 is an elevation of privilege vulnerability in the Microsoft Windows Search Component. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69310 is an elevation of privilege vulnerability in Windows DNS. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69337 is an elevation of privilege vulnerability in the Windows Registry. A double-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69364 is an elevation of privilege vulnerability in the Windows Print Spooler Components. A race condition flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69366 is an elevation of privilege vulnerability in the Windows Kernel. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69385 is an elevation of privilege vulnerability in the Windows TCP/IP. A race condition flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69391 is an elevation of privilege vulnerability in the Windows Broker Infrastructure Service. A stack-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69406 is an elevation of privilege vulnerability in the Windows Kernel. A type confusion vulnerability may allow an attacker to gain privileges.
- CVE-2026-69436 is an elevation of privilege vulnerability in the Windows Error Reporting. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69450 is an elevation of privilege vulnerability in the Windows Error Reporting. An out-of-bounds read flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69451 is an elevation of privilege vulnerability in the Windows Management Instrumentation. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69459 is an elevation of privilege vulnerability in the Windows Power Dependency Coordinator. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69460 is an elevation of privilege vulnerability in the Windows Modern Device Management (MDM). Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69466 is an elevation of privilege vulnerability in the Windows Kernel. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
- CVE-2026-69473 is an elevation of privilege vulnerability in the Windows Kernel. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69478 is an elevation of privilege vulnerability in the Windows Device Association Service. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69498 is an elevation of privilege vulnerability in the Windows Win32k. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69525 is a remote code execution vulnerability in Remote Desktop Services. A use-after-free flaw may allow an attacker to achieve remote code execution.
- CVE-2026-69541 is an elevation of privilege vulnerability in the Virtual Hard Disk (VHD) Miniport Driver. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69585 is an elevation of privilege vulnerability in the Microsoft Windows Search Component. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
- CVE-2026-69600 is an elevation of privilege vulnerability in the Microsoft Windows Search Component. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69605 is an elevation of privilege vulnerability in the Microsoft Install Service. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69623 is a remote code execution vulnerability in the Windows HTTP Print Provider. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69714 is an elevation of privilege vulnerability in the Windows Device Association Service. A stack-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69723 is an information disclosure vulnerability in the Windows Kernel. An attacker who successfully exploited this vulnerability could elevate privileges.
- CVE-2026-69757 is an elevation of privilege vulnerability in Windows TCP/IP. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69777 is an elevation of privilege vulnerability in the Windows DHCP Client. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69779 is an elevation of privilege vulnerability in the Windows Win32k. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
- CVE-2026-69832 is an information disclosure vulnerability in win32k. Successful exploitation of the vulnerability may allow an authenticated attacker to disclose information locally.
- CVE-2026-69911 is an elevation of privilege vulnerability in the Microsoft Windows Search Component. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-69921 is an elevation of privilege vulnerability in Windows Print Spooler Components. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-70289 is an elevation of privilege vulnerability in the Windows Win32k. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-70342 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-70562 is an elevation of privilege vulnerability in the Windows Audio Service. A double-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-70583 is an elevation of privilege vulnerability in the Windows Core Messaging. A heap-based buffer overflow flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-71340 is an elevation of privilege vulnerability in the Windows File History Service. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
- CVE-2026-71343 is a remote code execution vulnerability in the Windows Remote Access Connection Manager. A heap-based buffer overflow flaw may allow an attacker to execute code.
- CVE-2026-72936 is a remote code execution vulnerability in the Windows SMB Client. A use-after-free flaw may allow an attacker to execute code.
- CVE-2026-72940 is a remote code execution vulnerability in the Windows Schannel. A heap-based buffer overflow flaw may allow an attacker to execute code.
- CVE-2026-77500 is an elevation of privilege vulnerability in the Windows Device Association Service. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
- CVE-2026-78454 is an information disclosure vulnerability in the Windows CD-ROM Driver. An out-of-bounds read flaw may allow an attacker to disclose information locally.
- CVE-2026-80093 is an elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver. Use-after-free flaw may allow an attacker to gain SYSTEM privileges.
Microsoft Release Summary
This month’s release notes cover multiple Microsoft product families affected, including, but not limited to, .NET, .NET and Visual Studio, ASP.NET Core, Active Directory Certificate Services (AD CS), Active Directory Domain Services, Active Directory Federation Services (AD FS), Audio Video Control Transport Protocol, Azure AI Language, Azure Arc, Azure Cosmos DB, Azure CycleCloud, Azure HDInsights, BranchCache, Connected Devices Platform Service (Cdpsvc), Graphic Fonts, HID class driver, IP Helper, Internet Storage Name Service, Kernel Streaming WOW Thunk Service Driver, Microsoft Account, Microsoft Authentication Library for JavaScript, Microsoft Authenticator, Microsoft Azure Active Directory B2C, Microsoft Azure CLI, Microsoft COM for Windows, Microsoft Discovery Studio, Microsoft Dynamics 365, Microsoft Edge (Chromium-based), Microsoft Entra ID, Microsoft Fabric, Microsoft Graphics Component, Microsoft Install Service, Microsoft JScript, Microsoft Local Security Authority Server (lsasrv), Microsoft Office, Microsoft Office Access, Microsoft Office Excel, Microsoft Office Outlook, Microsoft Office PowerPoint, Microsoft Office Publisher, Microsoft Office SharePoint, Microsoft Office Word, Microsoft Standard XPS, Microsoft Teams for Android, Microsoft Trace Data Helper, Microsoft UxTheme Library (uxtheme.dll), Microsoft WDAC OLE DB provider for SQL, Microsoft WebP Image Extension, Microsoft Windows Codecs Library, Microsoft Windows Media Foundation, Microsoft Windows PDF, Microsoft Windows SCSI Class System File, Microsoft Windows Search Component, Microsoft Windows Speech, OpenSSH for Windows, Power Automate, Push Message Routing Service, RPC Runtime, Reliable Multicast Transport Driver (RMCAST), Remote Desktop Client, Remote Desktop Gateway Service, Role: DNS Server, Role: Windows Fax Service, SQL Server, Skype for Business, Spring Cloud Azure, Storage Port Driver, Telnet Client, Virtual Hard Disk (VHD) Miniport Driver, Visual Studio, Visual Studio Code, Volume Manager Driver, Windows AF_UNIX Socket Provider, Windows ALPC, Windows Accounts Control, Windows Ancillary Function Driver for WinSock, Windows Audio Service, Windows Authentication Methods, Windows Autopilot, Windows Bind Filter Driver, Windows Biometric Service, Windows BitLocker, Windows Bluetooth Port Driver, Windows Bluetooth Service, Windows Boot Manager, Windows Broadcast DVR User Service, Windows Broker Infrastructure Service, Windows CD-ROM Driver, Windows Camera Frame Server Monitor, Windows Cloud Files Mini Filter Driver, Windows Compressed Folder, Windows Connected User Experiences and Telemetry, Windows Container Manager Service, Windows Core Messaging, Windows Credential Guard, Windows Credential Providers, Windows DCOM Server, Windows DHCP Client, Windows DHCP Server, Windows DNS, Windows DWM Core Library, Windows Defender Firewall Service, Windows Deployment Services, Windows Device Association Broker service, Windows Device Association Service, Windows Device Health Attestation (DHA), Windows Devices Human Interface, Windows Direct Show, Windows Display Enhancement Service, Windows Distributed File System (DFS), Windows Embedded Mode Service, Windows Encrypting File System (EFS), Windows Enterprise App Management, Windows Error Reporting, Windows Event Logging Service, Windows Failover Cluster, Windows Fast FAT Driver, Windows File History Service, Windows GDI, Windows GDI+, Windows Graphics Kernel, Windows Group Policy, Windows HTTP Print Provider, Windows Hello, Windows Host Guardian Service, Windows IKE Extension, Windows IP Address Management (IPAM) Service, Windows Image Acquisition, Windows Imaging Component, Windows Installer, Windows Internet Connection Sharing (ICS), Windows Kerberos, Windows Kernel, Windows Kernel Mode Driver, Windows Key Distribution Center, Windows LDAP – Lightweight Directory Access Protocol, Windows License Manager, Windows Link Layer Topology Discovery Protocol, Windows MIDI Service Module, Windows Management Instrumentation, Windows Management Services, Windows Media, Windows Media Player, Windows Message Queuing, Windows Message Queuing Queue Manager, Windows Microsoft DirectMusic, Windows Mobile Broadband, Windows Modern Device Management (MDM), Windows Modern Execution Server, Windows NDIS, Windows NFS Portmapper, Windows NTFS, Windows Netlogon, Windows Network Connection Broker, Windows Network File System, Windows Notification, Windows OLE DB, Windows Online Certificate Status Protocol (OCSP), Windows Overlay Filter, Windows Paint, Windows Partition Management Driver, Windows Performance Monitor, Windows Power Dependency Coordinator, Windows PowerShell, Windows Print Spooler Components, Windows PrintWorkflowUserSvc, Windows Program Compatibility Assistant Service, Windows Push Notifications, Windows RDP Client, Windows RNDIS, Windows Raw Image Extension, Windows Registry, Windows Remote Access Connection Manager, Windows Remote Desktop, Windows Remote Desktop Licensing Service, Windows Remote Desktop Protocol, Windows Remote Desktop Services, Windows Resilient File System (ReFS), Windows Resilient File System (ReFS) Deduplication Service, Windows Routing and Remote Access Service (RRAS), Windows SMB Client, Windows SMB Server, Windows SMB Server Network Transport Driver (srvnet.sys), Windows Schannel, Windows Secure Boot, Windows Secure Kernel Mode, Windows Secure Socket Tunneling Protocol (SSTP), Windows Security Center, Windows Security Health Service, Windows Server, Windows Services for NFS ONCRPC XDR Driver, Windows Setup Files Cleanup, Windows Shell, Windows Smart Card, Windows Spaceport.sys, Windows Storage, Windows Storage Management Provider, Windows Storage Port Driver, Windows Storage Spaces Controller, Windows TCP/IP, Windows Task Scheduler, Windows Text Shaping, Windows URL Moniker, Windows USB Audio Class driver (usbaudio.sys), Windows USB Driver, Windows USB Hub Driver, Windows USB Mass Storage Class Driver, Windows USB Video Driver, Windows Universal Disk Format File System Driver (UDFS), Windows Universal Plug and Play (UPnP) Device Host, Windows Update Stack, Windows VHD miniport driver, Windows VOLSNAP.SYS, Windows Virtual Trusted Platform Module, Windows Volume Manager Extension Driver, Windows Volume Shadow Copy, Windows Web Platform Storage, Windows WebClient Service, Windows Win32 Kernel Subsystem, Windows Win32K, Windows Wireless Networking, Windows Wireless Wide Area Network Service, Windows Work Folder Service, Windows Work Folders, Windows exFAT File System, Windows iSCSI, Windows iSCSI Target Service, Winsock, XBox Gaming Services, Xbox.
The next Patch Tuesday is scheduled for October 13, and we will provide details and patch analysis then. Until next Patch Tuesday, stay safe and secure. Be sure to subscribe to the ‘This Month in Vulnerabilities and Patches’ webinar.’
Qualys Monthly Webinar Series
The Qualys Research team hosts a monthly webinar series to help our existing customers leverage the seamless integration between Qualys Vulnerability Management, Detection & Response (VMDR), and Qualys Patch Management. Combining these two solutions can reduce the median time to remediate critical vulnerabilities.
During the webcast, we will discuss this month’s high-impact vulnerabilities, including those highlighted in this month’s Patch Tuesday alert. We will walk you through the necessary steps to address the key vulnerabilities using Qualys VMDR and Qualys Patch Management.

Leave A Comment