Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A September patch record tells you which Windows components Microsoft changed. It does not tell you which of those components are running, listening on a port, or reachable from the network you care about. An interface is reachable only from a stated source, and only when four things hold: the component is installed, its service is running, nothing on the host or in the network path blocks the port, and a route exists between the two. Microsoft’s September 2026 material identifies what was patched. Establishing the other three conditions is the work this article covers.

What Microsoft’s September 2026 release establishes

  • Release date. Microsoft’s monthly security summary, published by the Microsoft Japan Security Team on September 7, 2026, gives the release date as September 8, 2026 in U.S. time.
  • Product families. The summary lists Windows 11 versions 23H2 through 26H1 and Windows Server 2016, 2019, 2022, and 2025. For the Windows families it covers, it gives a maximum severity of Critical and names remote code execution as the largest impact. The same release also covers non-Windows product families, which this article does not address.
  • Record count. Microsoft says it updated 38 existing vulnerability records on September 8, 2026. These are updated records, not 38 new vulnerabilities and not a count of exposed systems.
  • Named server components. Windows DNS Server, Windows DHCP Server, and Windows Deployment Services TFTP Server appear among the updated records. That makes them useful for triage on servers that run those roles. The record does not say which hosts run them.

What a CVSS network vector does and does not tell you

The network attack vector in CVSS describes the scored context of an exploit: it can be exploited across one or more network hops. Microsoft’s Security Update Guide uses this definition for its vulnerability entries; its entry for CVE-2026-21527 is one place the definition appears. The vector is a property of the vulnerability assessment. It is not a scan of your environment, and it is not evidence that a service is enabled, listening, permitted through a firewall, or reachable from the Internet. A record marked network-exploitable can sit behind a stopped service on a host that no one can reach.

Define the vantage point before you test

“Reachable” means nothing until you name the source. Pick the vantage point that matches the question you are answering, and write it down with every result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Vantage point Question it answers Typical use
Internet Can a host outside your perimeter reach the port through your edge devices? Perimeter review and external attack-surface checks
Corporate user subnet Can ordinary client networks reach the service? Internal segmentation review
Server or management subnet Can other servers or administrative networks reach the service? Server-zone and admin-path policy checks
Host already inside the network What would a machine an attacker already controls be able to reach? Lateral-movement assessment

A measurement workflow for Windows server interfaces

Run these steps in order, from an elevated PowerShell session on the host, and only against systems you are authorized to assess.

#1 Best Overall
  1. Confirm the build and the update. Run Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion' | Select-Object ProductName, DisplayVersion, CurrentBuild, UBR, then Get-HotFix -Id KB5122871 for the Windows Server 2025 example used later in this article. Expected result: the build number is at or above the one Microsoft lists for the update you are checking. If you are assessing a different CVE, use the KB and build from its Security Update Guide entry.
  2. Confirm the server role is installed. On Windows Server, run Get-WindowsFeature DNS, DHCP, WDS. An InstallState of Installed means the role’s binaries are present. Get-WindowsFeature is a Windows Server cmdlet, so on client editions use step 3 to answer the question.
  3. Confirm the service is running. Run Get-Service DNS, DHCPServer, WDSServer. A stopped service does not listen, which means step 4 will return nothing for it.
  4. Map the listeners. Run Get-NetTCPConnection -State Listen -LocalPort 53, 3389 | Select-Object LocalAddress, LocalPort, OwningProcess and Get-NetUDPEndpoint -LocalPort 53, 67, 69 | Select-Object LocalAddress, LocalPort, OwningProcess. A LocalAddress of 0.0.0.0 or :: means the service listens on all addresses of that IP version. Match OwningProcess to the expected service in Task Manager or with Get-Process -Id.
  5. Review inbound filtering on the host. Open Windows Defender Firewall with Advanced Security (wf.msc) and go to Inbound Rules. For each rule that matches your port, check Enabled, Action, the Profile (Domain, Private, or Public), and the Remote Addresses scope. Then review network firewalls and access control lists on routers and switches, which the host cannot show you.
  6. Test from the stated vantage point. From the source you defined, run Test-NetConnection -ComputerName dns01.corp.example -Port 53. Test-NetConnection checks TCP only. UDP services such as DHCP on 67, TFTP on 69, and DNS queries on 53 need a UDP-capable test run from the same vantage point. DHCP clients normally use local broadcast, and off-subnet clients reach the server through a relay agent, so a routed test to UDP 67 can misrepresent real client behavior.
  7. Record and recheck. Log the host name, build, source, timestamp, protocol and port, and result. Repeat the test after any update and after any firewall, routing, or role change, because each can change the answer.

Reading the results

The same port can produce different conclusions depending on which step failed. Use this table to decide what each observed state establishes and what to do next.

Observed state What it establishes Next step
Role not installed This host has no listener for that component. The CVE record may still matter on other hosts. Record the host as not applicable. Recheck after any role change.
Role installed, service stopped No listener exists right now. Starting the service would create one. Confirm the build matches the CVE entry, record the service owner, and monitor for service start changes.
Listening, but blocked by a host or network control from the vantage point The port is not reachable from that source. Confirm the rule’s profile, remote address scope, and port cover the actual source. Retest after every change.
Listening, and allowed from the vantage point The port is reachable from that source. Verify the installed build includes the fix. Narrow the permitted source range if the service does not need that reach.
Build unknown Patch status cannot be confirmed, so the rest of the assessment is unreliable. Collect the build number first, then repeat the workflow.

Worked example: the September 2026 Remote Desktop Services issue

Remote Desktop Services is a useful example because Microsoft documented a post-update problem with it in September 2026. The example concerns availability after patching. It does not measure exposure.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Windows Server 2025 (KB5122871)

Microsoft’s support article for KB5122871 (OS Build 26100.33438) includes a known-issue entry that reads: “After installing the September 2026 Windows security update, some organizations might experience issues with Remote Desktop Services (RDS).” The entry lists RDP connections that fail after several minutes, sign-in problems, and servers that hang at “Please wait for the Remote Desktop Configuration.” Microsoft says Windows updates released on and after September 14, 2026 resolve the issue, and gives KB5129235 as one example. The same entry states: “This issue does not affect Windows 365 or Azure Virtual Desktop.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Affected platforms

Microsoft’s Learn page for Windows 11, version 26H1 known issues and notifications records the RDS issue across the following platforms.

Rank #3
HP OmniBook 3 17.3 inch Laptop PC, FHD Display, AMD Ryzen 3 30, 8 GB RAM, 512 GB SSD, AMD Radeon 610M Graphics, Windows 11 Home, Mica Silver, 17-dp0199nr
  • FULL HD IPS DISPLAY - Enjoy vibrant, crystal-clear images with 178-degree wide-viewing angles
  • AMD RYZEN 3 30 PROCESSOR - Everyday performance you can count on; Multitask, stream, game casually, and edit photos smoothly with responsive power and vibrant HDR visuals
  • ENJOY UP TO 14 HOURS AND 15 MINUTES OF BATTERY LIFE - HP Fast Charge restores battery from 0 to 50% in approximately 45 minutes
  • AMD RADEON 610M GRAPHICS - Experience smooth entertainment; Built for streaming and multitasking, enjoy realistic visuals and efficient performance for work and play
  • STORAGE AND MEMORY - 512 GB PCIe NVMe M.2 SSD offers fast speed and efficient storage; and 8 GB LPDDR5 RAM memory boosts performance with higher bandwidth
Platform family Status for the RDS issue, per Microsoft
Windows 11 versions 23H2 through 26H1 Affected (client)
Windows 10 releases Affected (client)
Windows Server 2012 through 2025 Affected (server)
Windows 365 and Azure Virtual Desktop Not affected

The same page gives September 14, 2026 as the resolution date.

Windows 11, version 26H1 (KB5129194)

The out-of-band update KB5129194 (OS Build 28000.2956), released September 14, 2026, includes the RDS fix. Its notes also cover a Hyper-V Plan9 folder-sharing issue and USB Audio Class 1.0 multichannel modes. Microsoft describes the audio fix as partial, because other audio symptoms were not addressed by that update. Those items fall outside the reachability question this article addresses.

Rank #4
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
  • 14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics,
  • Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
  • 3x USB Type A,1x SD Card Reader, 1x Headphone/Microphone
  • 802.11a/b/g/n/ac (2x2) Wi-Fi and Bluetooth, HP Webcam with Integrated Digital Microphone
  • Windows 11 OS, Dale Blue

What this example does and does not show

The example shows that a patch can change whether a remote-access service works at all, which is why the test in step 6 belongs both before and after applying an update. It does not show that a Remote Desktop interface was reachable from outside a network, and it is not an exploit. The reported symptoms are connection failures and service instability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the public record does not establish

  • Microsoft’s September material does not provide a complete map from each September CVE to the default enablement state, listening socket, port, and exposure of every vulnerable Windows component.
  • No published source gives the number of reachable Windows interfaces in any particular organization. That number requires inventory and network measurement in that environment.
  • Listing a component in a release does not mean it is enabled on every Windows installation.

Before acting on any individual CVE record, check its entry in Microsoft’s Security Update Guide for revisions made after the September 8, 2026 release, since a revision can change the affected builds you should test.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$245.99
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$285.00
Bestseller No. 4
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Blue (Renewed)
14” Diagonal HD BrightView WLED-Backlit (1366 x 768), Intel Graphics,; Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD
$247.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.