The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Microsoft published its September 2026 security updates on September 8. The release includes critical remote code execution (RCE) updates for several Windows, Office and SQL Server product families, plus important RCE updates for SharePoint and Exchange. Microsoft also says attackers exploited two Windows privilege-escalation flaws before the updates were released; MS-ISAC separately reports in-the-wild exploitation of another flaw. Administrators should check which products and editions they run, prioritize exploited and exposed systems, then deploy and verify the applicable updates.
What did Microsoft fix on September 2026 Patch Tuesday?
Microsoft’s monthly security release was published September 8, 2026, U.S. time. Microsoft describes Update Tuesday as the second-Tuesday monthly cadence most commonly used for Windows security servicing. Its September announcement says 38 existing vulnerability records were updated; that figure is not an authoritative total count of vulnerabilities in the release.
Product families with critical RCE impact
| Product family | September 2026 impact listed |
|---|---|
| Windows 11 versions 26H1, 25H2, 24H2 and 23H2 | Critical; remote code execution |
| Windows Server 2025 and Windows Server 2022 | Critical; remote code execution |
| Windows Server 2019 and Windows Server 2016 | Critical; remote code execution |
| Microsoft Office | Critical; remote code execution |
| Microsoft SQL Server | Critical; remote code execution |
| SharePoint and Exchange | Important; remote code execution |
These are the product families and impact categories identified in Microsoft’s September announcement. Check the Security Update Guide and the relevant product KB for the affected versions and applicable packages in your environment.
Is there an Outlook spoofing or RCE vulnerability?
Yes. Microsoft Support says Outlook 2016 update KB5002919 resolves an Outlook spoofing vulnerability, an Outlook remote code execution vulnerability, and a Microsoft Office Word remote code execution vulnerability.
#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Check the Outlook 2016 installation type
KB5002919 applies to the MSI-based edition of Outlook 2016. Microsoft says it does not apply to Click-to-Run editions, including Office 2016 Click-to-Run. Confirm the installation type before deploying the package; Click-to-Run installations need the applicable Click-to-Run servicing path rather than this MSI update.
Which September vulnerabilities were reported as exploited?
Microsoft’s September announcement identifies two Windows privilege-escalation flaws that were exploited before release:
Rank #2
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
- CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) privilege escalation.
- CVE-2026-81963: Windows Update Stack privilege escalation.
These are privilege-escalation issues, not the Outlook spoofing and RCE vulnerabilities. MS-ISAC also reports that CVE-2026-65660 was exploited in the wild and added to Microsoft’s Known Exploited Vulnerability list. Treat the reports as prioritization signals and consult each CVE entry for affected products and the applicable update.
MS-ISAC warns that severe exploitation may let an attacker gain the privileges of the logged-on user. What the attacker can then do depends on those privileges; possible consequences include installing programs, viewing or changing data, deleting data, or creating accounts. A least-privileged account can limit the impact compared with an administrative account.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
How should administrators deploy the September updates?
Use the product, edition, architecture and servicing channel in your inventory to identify the correct update before deployment. Microsoft identifies Microsoft Update, Microsoft Update Catalog and enterprise deployment tooling as update paths; its Security Update Guide provides CVE, KB, product, release-date and exploitability details.
- Inventory affected products. Identify Windows, Office, Exchange, SharePoint, SQL Server and other Microsoft products in scope, including edition, architecture and servicing channel. Match each installation to the September 2026 entries in the Security Update Guide and the relevant KB articles.
- Prioritize exposure and exploitation. Put reported exploited CVEs, internet-facing services, domain controllers, mail servers and systems used by administrators near the front of the queue. Include CVE-2026-65660 as a concrete urgency signal because MS-ISAC reports in-the-wild exploitation.
- Validate update applicability. Check that the package matches the product and installation type. For example, KB5002919 is for MSI-based Outlook 2016, not Outlook 2016 Click-to-Run.
- Test, then deploy. Apply the relevant Microsoft updates after appropriate testing. Use Microsoft Update, the Microsoft Update Catalog or enterprise deployment tooling according to your environment and change controls.
- Verify and contain. Confirm installation, rescan for missing updates and monitor for service regressions. While remediation is in progress, use segmentation, least privilege and exploit-protection controls where appropriate.
- Track remediation over time. Record affected assets, update status and exceptions, and continue with automated patch management and recurring vulnerability scans as part of a documented vulnerability-management process.
What the September release figures do and do not establish
Microsoft’s announcement says 38 existing vulnerability records were updated, but the cited official passages do not give one authoritative total count of all September 2026 vulnerabilities. They also do not establish a universal CVSS ranking or a single remediation deadline. For severity and applicability decisions, use the individual CVE records in Microsoft’s Security Update Guide rather than infer a release-wide total or deadline.
Quick Recap
Best Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

