Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s September 8, 2026 security release does not establish the “97 CVEs” figure in the supplied headline. Zero Day Initiative (ZDI) counted 972 new Microsoft CVEs, or 997 when it included external and Chromium issues; TechRadar reported 974 vulnerabilities. Microsoft did confirm two Windows vulnerabilities were exploited before the updates became available: CVE-2026-85880 and CVE-2026-81963. ZDI also classified 20 CVEs as potentially “wormable” under its own criteria.

What Microsoft released on September 8, 2026

Microsoft’s September security updates arrived on September 8, 2026, the month’s scheduled Update Tuesday. The release covers Windows 11, Windows Server, Office, SharePoint, Exchange Server, SQL Server, .NET, Visual Studio, Dynamics 365 and Azure. Microsoft identifies Windows 11 versions and several Windows Server releases as Critical, with remote code execution listed as the maximum potential impact.

Microsoft’s Japan Security Team urged affected customers to install the applicable updates promptly and directed administrators to the Security Update Guide and product-specific support articles. The correct package depends on the exact product, edition, version and servicing channel.

How many CVEs were patched?

There is no single reconciled total in Microsoft’s accessible monthly post. Published figures use different scopes and should not be treated as interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Figure Source and scope
972 New Microsoft CVEs counted by ZDI analyst Dustin Childs on September 8, 2026
997 ZDI’s broader total when external and Chromium CVEs are included
974 Vulnerabilities reported by TechRadar on September 9, 2026
114 Critical vulnerabilities reported by both ZDI and TechRadar
723 Windows vulnerabilities in TechRadar’s breakdown
111 Office vulnerabilities in TechRadar’s breakdown

The headline’s “97 CVEs” is inconsistent with these published counts and should not be presented as an established Microsoft total. Childs summarized ZDI’s count this way:

“As always, counting this beast is tricky, but I see 972 new CVEs rolling out from Redmond this month.”

Dustin Childs, Zero Day Initiative, September 8, 2026

Which September vulnerabilities were already being exploited?

Microsoft explicitly confirmed two vulnerabilities had been exploited before the September updates were released. Both are Windows privilege-escalation flaws, so an attacker would generally need an initial foothold before using them to gain additional rights.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2026-85880: Windows ALPC elevation of privilege

This vulnerability affects Windows Advanced Local Procedure Call (ALPC). Microsoft lists it as exploited before release. Apply the update for every affected Windows installation and investigate whether exposed systems show signs of unauthorized privilege use.

CVE-2026-81963: Windows Update Stack elevation of privilege

This Windows Update Stack vulnerability was also exploited before release. Microsoft’s confirmation is the authoritative basis for describing both CVE-2026-85880 and CVE-2026-81963 as actively exploited or exploited before release.

ZDI’s overview contains an inconsistent reference to one vulnerability under active attack, but its detailed material identifies both issues. Microsoft’s own September post names both, so administrators should treat the count of confirmed exploited vulnerabilities as two.

What “wormable” means in this release

ZDI analyst Dustin Childs classified 20 CVEs as potentially “wormable.” That is ZDI’s assessment, not a Microsoft classification and not evidence that a worm is spreading.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ZDI’s criterion is a remote, unauthenticated arbitrary-code-execution vulnerability that requires no user interaction. Examples in its review involve DHCP, Active Directory Domain Services, DNS, Message Queuing, Routing and Remote Access Service, Netlogon, Internet Connection Sharing and Failover Cluster, among other components.

The criterion describes technical propagation potential. It does not mean every affected system is equally exposed, that exploitation is confirmed for all 20 CVEs, or that exploitation will automatically spread across a network. Internet reachability, authentication controls, segmentation, configuration and the vulnerable product version still determine practical risk.

Other vulnerabilities ZDI prioritized

CVE-2026-55007 in Exchange Server

ZDI describes CVE-2026-55007 as a remote-code-execution issue involving a malicious Visio attachment processed by Exchange Server. This technical description comes from ZDI’s analysis, not Microsoft’s short monthly summary. Confirm the affected versions, prerequisites and remediation in the relevant CVE record and Microsoft Exchange advisory before acting on detailed exploit assumptions.

SharePoint, Remote Desktop Services, SQL Server and Authenticator

ZDI also highlighted issues affecting SharePoint, Remote Desktop Services, SQL Server and Microsoft Authenticator. These are analyst prioritizations; the applicable Microsoft advisory for each product and version controls deployment decisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How administrators should prioritize the updates

When many applicable fixes arrive together, rank them using the following checks:

  1. Confirmed exploitation: Start with CVE-2026-85880 and CVE-2026-81963, which Microsoft says were exploited before release.
  2. Impact: Give remote code execution priority over lower-impact outcomes when exposure and applicability are comparable.
  3. Access requirements: Elevate unauthenticated, no-user-interaction issues, including those matching ZDI’s wormable criterion.
  4. Reachability: Identify internet-facing or broadly reachable services such as Exchange, DNS, DHCP and remote-access infrastructure.
  5. Exact asset match: Map each CVE to the installed product, edition, build and supported version rather than assuming every Microsoft device is affected.
  6. Known regressions: Check current release-health notices and out-of-band fixes before broad deployment.

Microsoft’s servicing criteria generally consider whether a vulnerability crosses a security boundary or affects a feature and whether its severity meets the servicing bar. That process explains why supported products may receive updates or guidance; it does not replace the product-specific advisory for a particular CVE.

Should you install the September Windows update now?

Organizations should move the applicable security updates through their normal emergency or accelerated change process, beginning with the two Microsoft-confirmed exploited vulnerabilities. Test representative workloads where practical, then deploy through the organization’s established channel: Windows Update, Windows Update for Business, WSUS or the Microsoft Update Catalog.

Do not equate the CVE count with the number of packages. Microsoft says cumulative or bundled updates can remediate many vulnerabilities through a relatively small number of update packages. Its machine-readable Vulnerability Exploitability eXchange (VEX) statements cover Microsoft-assigned CVEs and can help teams assess exposure before deployment; publishing VEX statements does not increase the number of updates that must be installed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Known Windows problems and out-of-band corrections

Microsoft’s Windows Release Health documentation recorded several problems after the September 8 update:

  • Some Hyper-V host-folder shares with Linux virtual machines became unavailable.
  • Remote Desktop Services stopped responding in some situations.
  • Some USB Audio Class 1.0 devices failed in multichannel modes.

Microsoft announced an out-of-band update on September 14 to address the listed issues. For Windows 11 version 26H1, the relevant support page provides package and installation-channel details and records known issues. Microsoft says File History problems were resolved by Windows updates released on or after September 22, 2026.

Issue status and applicable KB numbers can change. Check the current Release Health and support page for the specific Windows version before pausing, rolling back or approving a broad deployment.

What the September release means for different teams

Endpoint administrators

Inventory Windows versions and builds, confirm which cumulative update applies, and monitor Remote Desktop, Hyper-V, USB audio and File History workloads after installation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Exchange and collaboration administrators

Prioritize exposed Exchange and SharePoint systems, then validate product-specific advisories for the ZDI-highlighted issues, including CVE-2026-55007.

Security operations teams

Use the two Microsoft-confirmed exploited CVEs as detection and investigation priorities. Review privileged-account activity and unusual service behavior on systems that were unpatched during the exposure window.

Vulnerability-management teams

Use Microsoft’s VEX data and product advisories to distinguish affected assets from products that merely share a CVE family or update bundle. Track remediation by asset and applicable package, not by raw CVE count alone.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.