Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including two zero-days already exploited in the wild.
Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, and Azure components, including two zero-days already exploited in the wild. CVE-2026-81963, an elevation of privilege flaw in the Windows Update Stack, is flagged as an exploited zero-day. The release includes numerous remote code execution and information disclosure fixes for Microsoft Excel and Word, plus patches for the Windows kernel, ALPC, Print Spooler, ReFS, Entra ID, and Azure CLI.
Russian GRU-linked BlueDelta (APT28) deployed HOOKEDGE backdoor via macro Word lures against European governments using webhook.site and Microsoft Edge for stealthy C2.
Recorded Future's Insikt Group documented a BlueDelta (APT28/Fancy Bear/Forest Blizzard) espionage campaign from late September 2025 through early April 2026 targeting government and diplomatic organizations in Romania, Spain and Türkiye. The group delivered HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents with diplomatic lures, including one impersonating Spain's Ministry of the Presidency after a Spanish-Moldovan meeting. HOOKEDGE uses webhook.site as C2, a scheduled task every 30 minutes that downloads commands through Microsoft Edge, and canary pixels like docopened.jpg to track phishing funnel progress. A second tier with 5-minute check-ins served high-value victims, and beaconing intervals were stretched to 61 minutes to evade sandboxes; code overlap ties HOOKEDGE to BlueDelta's earlier HEADLACE backdoor.
Aggah campaign abuses Bit.ly, BlogSpot, and Pastebin as multi-hop C2 to deliver RevengeRAT across the Middle East, US, Europe, and Asia.
Unit 42 details the Aggah campaign, which began with spearphishing emails in March 2019 spoofing a large financial institution and targeting education, media/marketing, and government organizations in the Middle East, later expanding to the US, Europe, and Asia. Delivery documents use Template Injection to load a remote OLE file whose macro runs mshta against a Bit.ly link redirecting to a BlogSpot post, which then uses Pastebin pastes to download RevengeRAT configured with a duckdns[.]org C2 domain. The embedded script also deletes Microsoft Defender signatures and kills Defender and Office processes, and modifies registry keys to enable macros. High-level TTPs resemble the Gorgon Group, but Unit 42 could not confirm attribution.
Unit 42 reports a spearphishing attack delivering the custom Rover Trojan to India's Ambassador to Afghanistan, exploiting CVE-2010-3333 in Word.
On December 24, 2015, Unit 42 identified a targeted spearphishing email spoofing Indian Defence Minister Manohar Parrikar, sent to India's Ambassador to Afghanistan. The RTF attachment exploited CVE-2010-3333 in Microsoft Word to download a downloader from newsumbrella.net, which retrieved the Rover Trojan and DLL plugins from 46.166.165.254. Rover uses OpenCV for webcam capture, OpenAL for audio recording and libsndfile for audio files, with data exfiltration over its C2 channel; separate payload versions target Windows XP and later systems.
Stack Buffer Overflow in Microsoft Office RTF Parsing Allows Remote Code Execution
CVE-2010-3333 is a stack-based buffer overflow in the way Microsoft Office parses RTF (Rich Text Format) data. An attacker triggers it by convincing a user to open a specially crafted RTF file, including an RTF email that is handed to Office for rendering, with no authentication required beyond the user's action. Successful exploitation allows remote code execution in the context of the logged-on user, giving the attacker a foothold on the workstation. Any Microsoft Office installation within the affected range identified in the December 2012 Microsoft security bulletin is exposed; the source data does not enumerate specific version numbers. The flaw is actively exploited: it is on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03, ransomware association unknown) and was used in targeted espionage, notably Kaspersky's 'Red October' campaign, with EPSS estimating an 89.5% probability of exploitation within 30 days (100th percentile).
Heap-Based Buffer Overflow RCE in Windows Print Spooler Components (CVE-2026-85877)
CVE-2026-85877 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler components, fixed by Microsoft in its September 2026 Patch Tuesday release. A remote, unauthenticated attacker can trigger the flaw by sending crafted input to the Print Spooler service over the network, though the CVSS vector (UI:R) indicates some form of user interaction is required for successful exploitation. If exploited, the attacker gains arbitrary code execution on the target system, with the CVSS base metrics indicating high impact to confidentiality, integrity, and availability. Any Windows system with the Print Spooler service enabled is affected; the available data does not enumerate specific vulnerable Windows versions or builds. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation within the next 30 days (37th percentile).
· Microsoft Windows Print Spooler Components (Windows systems with the Print Spooler service enabled)mass
Use-After-Free RCE in Windows Message Queuing (MSMQ)
CVE-2026-83997 is a use-after-free (CWE-416) vulnerability in Microsoft's Windows Message Queuing (MSMQ) service that permits an unauthenticated, remote attacker to execute arbitrary code over the network. It is triggered when the MSMQ service processes specially crafted network traffic that causes memory to be used after it has been freed, with the high attack-complexity rating (AC:H) indicating the attacker likely needs to win a timing or state race to land the free-then-use condition. Successful exploitation yields code execution in the context of the MSMQ service, with high confidentiality, integrity, and availability impact, meaning an attacker could take over the affected host. Only Windows systems that have the optional Message Queuing (MSMQ) feature installed and running are exposed, since MSMQ is not enabled by default on most Windows installations and is typically found on legacy application and queuing servers. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, EPSS is 0.5% (42nd percentile), and the two actively exploited zero-days mentioned in September 2026 Patch Tuesday headlines are separate issues fixed in the same release.
· Microsoft Windows Message Queuing (MSMQ) - Windows releases with the optional Message Queuing feature installed and runninglarge
Heap Buffer Overflow in Windows Biometric Service Enables Local Privilege Escalation
CVE-2026-83985 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service (WbioSrvc) on supported Windows 10, Windows 11, and Windows Server releases. A local, already-authenticated user with low privileges and no user interaction can trigger the overflow via a crafted request or operation handled by the service. Successful exploitation yields elevated privileges on the local host, with high impact on confidentiality, integrity, and availability — effectively a full local compromise. Any organization or individual running the listed Windows 10/11 client versions or Windows Server 2016–2025 is exposed, though exploitation requires local code execution first. The flaw is not in CISA KEV, has no known public PoC, a modest 0.3% EPSS, and is believed unexploited; it was addressed in Microsoft's September 2026 Patch Tuesday release, which fixed 973 vulnerabilities (two of them already-exploited zero-days, though not this one).
· microsoft Windows 10 1607, 1809, 21H2, 22H2 · microsoft Windows 11 23H2, 24H2, 25H2, 26H1mass
Use-After-Free Privilege Escalation in Windows Biometric Service
CVE-2026-83979 is a use-after-free flaw (CWE-416) in the Windows Biometric Service, the component that handles fingerprint, facial, and other biometric authentication on Windows. An attacker who is already authorized on the machine with low privileges can trigger the bug, presumably by sending crafted input to the service that causes memory to be used after it has been freed. Successful exploitation allows local elevation of privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The affected range spans mainstream Windows 10 and Windows 11 client releases plus Windows Server 2016 through 2025, covering nearly the entire currently supported Windows estate. As of the September 2026 Patch Tuesday disclosure there is no CISA KEV listing, no known public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days; the flaw is not identified as one of the two zero-days actively exploited that month.
· Microsoft Windows 10 1607 (builds prior to the September 2026 security updates) · Microsoft Windows 10 1809 (builds prior to the September 2026 security updates)mass
Heap Buffer Overflow in Microsoft Graphics Component Enables Local Code Execution
CVE-2026-84000 is a heap-based buffer overflow (CWE-122) involving an integer-overflow condition (CWE-190) in the Microsoft Graphics Component. An attacker who is already authorized on the machine with low privileges can trigger the overflow locally, with no user interaction required per the CVSS vector (AV:L/AC:L/PR:L/UI:N). Successful exploitation yields local code execution with high impact on confidentiality, integrity and availability (C:H/I:H/A:H), consistent with an elevation-of-privilege outcome on the affected system. Any supported Windows system containing the Graphics Component is affected, and Microsoft addressed the flaw among the 973 vulnerabilities fixed in the September 2026 Patch Tuesday release. Exploitation has not been observed: the bug is not on CISA's KEV, no public proof-of-concept is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
· Microsoft Graphics Component (shipped with Windows client and server editions)mass
Local Privilege Elevation via Heap Buffer Overflow in Windows Biometric Service
CVE-2026-83978 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service, the built-in component that handles fingerprint, face, and other biometric authentication on Windows. An attacker who already has a standard (low-privileged) account on the machine can trigger the flaw locally, with no user interaction required, causing memory corruption in the service. Successful exploitation allows the attacker to elevate privileges on the local host, gaining high confidentiality, integrity, and availability impact — a classic local privilege escalation to administrative/SYSTEM-level access. Anyone running the affected Windows 10 (1607, 1809, 21H2, 22H2) and Windows 11 (23H2, 24H2, 25H2, 26H1) client builds, or Windows Server 2016, 2019, 2022, or 2025, is in scope, and because the Biometric Service ships with Windows by default the exposure spans essentially the entire installed base on those branches. As of the September 2026 Patch Tuesday release (which fixed 973 vulnerabilities and two other actively exploited zero-days), no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and its EPSS of 0.3% (25th percentile) points to low near-term exploitation risk.
· Microsoft Windows 10 1607 1607 · Microsoft Windows 10 1809 1809mass
Out-of-bounds Read in Windows Kerberos KDC Enables Network Denial of Service
CVE-2026-84001 is an out-of-bounds read (CWE-125) in the Windows Key Distribution Center (KDC), the Kerberos authentication component built into Windows. An unauthorized, remote attacker can trigger it by sending specially crafted network requests to the KDC service, causing the service to read beyond allocated memory. According to the CVSS vector, the impact is availability-only (C:N/I:N/A:H): the attacker gains denial of service, not code execution, data theft, or tampering, though taking down the KDC on domain controllers can disrupt Kerberos authentication for an entire Active Directory domain. Any Windows system running the KDC is affected, chiefly Windows domain controllers and servers, although the specific affected Windows version ranges are not enumerated in the available data. There is no known public proof-of-concept, the CVE is not in CISA's KEV catalog, and its EPSS probability of ~0.6% suggests exploitation risk is currently low; the fix shipped in Microsoft's September 2026 Patch Tuesday release.
· Microsoft Windows (Key Distribution Center / Kerberos KDC service, primarily on Windows domain controllers and servers)mass
Use-After-Free Local Privilege Escalation in Windows Kernel (CVE-2026-85360)
CVE-2026-85360 is a use-after-free (CWE-416) memory-safety flaw in the Windows kernel. An attacker with valid low-privileged local access must execute code that triggers the flawed kernel memory handling (rated high attack complexity, suggesting a timing- or race-sensitive trigger), causing the kernel to reference freed memory. Successful exploitation elevates the attacker's privileges locally, typically to SYSTEM, giving full control of the affected machine. It affects a broad range of supported Windows 10 and Windows 11 client builds as well as Windows Server 2012 through 2022, so nearly any Windows endpoint or server in an organization's fleet may be in scope. No public proof-of-concept, no CISA KEV listing, and a low EPSS (0.2%, 14th percentile) indicate exploitation is not known at publication, though the flaw was disclosed amid Microsoft's September 2026 Patch Tuesday, which fixed 973 vulnerabilities including two exploited zero-days.
· microsoft Windows 10 1607 · microsoft Windows 10 1809mass
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.