Microsoft’s September 8, 2026 security release does not establish the “97 CVEs” figure in the supplied headline. Zero Day Initiative (ZDI) counted 972 new Microsoft CVEs, or 997 when it included external and Chromium issues; TechRadar reported 974 vulnerabilities. Microsoft did confirm two Windows vulnerabilities were exploited before the updates became available: CVE-2026-85880 and CVE-2026-81963. ZDI also classified 20 CVEs as potentially “wormable” under its own criteria.
What Microsoft released on September 8, 2026
Microsoft’s September security updates arrived on September 8, 2026, the month’s scheduled Update Tuesday. The release covers Windows 11, Windows Server, Office, SharePoint, Exchange Server, SQL Server, .NET, Visual Studio, Dynamics 365 and Azure. Microsoft identifies Windows 11 versions and several Windows Server releases as Critical, with remote code execution listed as the maximum potential impact.
Microsoft’s Japan Security Team urged affected customers to install the applicable updates promptly and directed administrators to the Security Update Guide and product-specific support articles. The correct package depends on the exact product, edition, version and servicing channel.
How many CVEs were patched?
There is no single reconciled total in Microsoft’s accessible monthly post. Published figures use different scopes and should not be treated as interchangeable.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
| Figure | Source and scope |
|---|---|
| 972 | New Microsoft CVEs counted by ZDI analyst Dustin Childs on September 8, 2026 |
| 997 | ZDI’s broader total when external and Chromium CVEs are included |
| 974 | Vulnerabilities reported by TechRadar on September 9, 2026 |
| 114 | Critical vulnerabilities reported by both ZDI and TechRadar |
| 723 | Windows vulnerabilities in TechRadar’s breakdown |
| 111 | Office vulnerabilities in TechRadar’s breakdown |
The headline’s “97 CVEs” is inconsistent with these published counts and should not be presented as an established Microsoft total. Childs summarized ZDI’s count this way:
“As always, counting this beast is tricky, but I see 972 new CVEs rolling out from Redmond this month.”
Dustin Childs, Zero Day Initiative, September 8, 2026
Which September vulnerabilities were already being exploited?
Microsoft explicitly confirmed two vulnerabilities had been exploited before the September updates were released. Both are Windows privilege-escalation flaws, so an attacker would generally need an initial foothold before using them to gain additional rights.
Recommended Free Tools
CVE-2026-85880: Windows ALPC elevation of privilege
This vulnerability affects Windows Advanced Local Procedure Call (ALPC). Microsoft lists it as exploited before release. Apply the update for every affected Windows installation and investigate whether exposed systems show signs of unauthorized privilege use.
CVE-2026-81963: Windows Update Stack elevation of privilege
This Windows Update Stack vulnerability was also exploited before release. Microsoft’s confirmation is the authoritative basis for describing both CVE-2026-85880 and CVE-2026-81963 as actively exploited or exploited before release.
ZDI’s overview contains an inconsistent reference to one vulnerability under active attack, but its detailed material identifies both issues. Microsoft’s own September post names both, so administrators should treat the count of confirmed exploited vulnerabilities as two.
What “wormable” means in this release
ZDI analyst Dustin Childs classified 20 CVEs as potentially “wormable.” That is ZDI’s assessment, not a Microsoft classification and not evidence that a worm is spreading.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesZDI’s criterion is a remote, unauthenticated arbitrary-code-execution vulnerability that requires no user interaction. Examples in its review involve DHCP, Active Directory Domain Services, DNS, Message Queuing, Routing and Remote Access Service, Netlogon, Internet Connection Sharing and Failover Cluster, among other components.
The criterion describes technical propagation potential. It does not mean every affected system is equally exposed, that exploitation is confirmed for all 20 CVEs, or that exploitation will automatically spread across a network. Internet reachability, authentication controls, segmentation, configuration and the vulnerable product version still determine practical risk.
Other vulnerabilities ZDI prioritized
CVE-2026-55007 in Exchange Server
ZDI describes CVE-2026-55007 as a remote-code-execution issue involving a malicious Visio attachment processed by Exchange Server. This technical description comes from ZDI’s analysis, not Microsoft’s short monthly summary. Confirm the affected versions, prerequisites and remediation in the relevant CVE record and Microsoft Exchange advisory before acting on detailed exploit assumptions.
SharePoint, Remote Desktop Services, SQL Server and Authenticator
ZDI also highlighted issues affecting SharePoint, Remote Desktop Services, SQL Server and Microsoft Authenticator. These are analyst prioritizations; the applicable Microsoft advisory for each product and version controls deployment decisions.
How administrators should prioritize the updates
When many applicable fixes arrive together, rank them using the following checks:
- Confirmed exploitation: Start with CVE-2026-85880 and CVE-2026-81963, which Microsoft says were exploited before release.
- Impact: Give remote code execution priority over lower-impact outcomes when exposure and applicability are comparable.
- Access requirements: Elevate unauthenticated, no-user-interaction issues, including those matching ZDI’s wormable criterion.
- Reachability: Identify internet-facing or broadly reachable services such as Exchange, DNS, DHCP and remote-access infrastructure.
- Exact asset match: Map each CVE to the installed product, edition, build and supported version rather than assuming every Microsoft device is affected.
- Known regressions: Check current release-health notices and out-of-band fixes before broad deployment.
Microsoft’s servicing criteria generally consider whether a vulnerability crosses a security boundary or affects a feature and whether its severity meets the servicing bar. That process explains why supported products may receive updates or guidance; it does not replace the product-specific advisory for a particular CVE.
Should you install the September Windows update now?
Organizations should move the applicable security updates through their normal emergency or accelerated change process, beginning with the two Microsoft-confirmed exploited vulnerabilities. Test representative workloads where practical, then deploy through the organization’s established channel: Windows Update, Windows Update for Business, WSUS or the Microsoft Update Catalog.
Do not equate the CVE count with the number of packages. Microsoft says cumulative or bundled updates can remediate many vulnerabilities through a relatively small number of update packages. Its machine-readable Vulnerability Exploitability eXchange (VEX) statements cover Microsoft-assigned CVEs and can help teams assess exposure before deployment; publishing VEX statements does not increase the number of updates that must be installed.
Best Value
Known Windows problems and out-of-band corrections
Microsoft’s Windows Release Health documentation recorded several problems after the September 8 update:
- Some Hyper-V host-folder shares with Linux virtual machines became unavailable.
- Remote Desktop Services stopped responding in some situations.
- Some USB Audio Class 1.0 devices failed in multichannel modes.
Microsoft announced an out-of-band update on September 14 to address the listed issues. For Windows 11 version 26H1, the relevant support page provides package and installation-channel details and records known issues. Microsoft says File History problems were resolved by Windows updates released on or after September 22, 2026.
Issue status and applicable KB numbers can change. Check the current Release Health and support page for the specific Windows version before pausing, rolling back or approving a broad deployment.
What the September release means for different teams
Endpoint administrators
Inventory Windows versions and builds, confirm which cumulative update applies, and monitor Remote Desktop, Hyper-V, USB audio and File History workloads after installation.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Exchange and collaboration administrators
Prioritize exposed Exchange and SharePoint systems, then validate product-specific advisories for the ZDI-highlighted issues, including CVE-2026-55007.
Security operations teams
Use the two Microsoft-confirmed exploited CVEs as detection and investigation priorities. Review privileged-account activity and unusual service behavior on systems that were unpatched during the exposure window.
Vulnerability-management teams
Use Microsoft’s VEX data and product advisories to distinguish affected assets from products that merely share a CVE family or update bundle. Track remediation by asset and applicable package, not by raw CVE count alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

