Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities across Windows and Office, including two actively exploited Windows privilege-escalation zero-days.
Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities spanning Windows, Office, SQL Server, SharePoint, Exchange, Azure, and developer tools. Two Windows zero-days are confirmed exploited in attacks: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a Windows Update Stack privilege-escalation flaw involving link following. The release also includes Critical fixes for Windows Secure Kernel Mode, VBS Enclave, Excel, and Word.
Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation
CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain.
· Microsoft Windows 10 1607, 1809, 21H2, 22H2 · Microsoft Windows Server 2012, 2016, 2019, 2022 KEVmass
Missing Authorization in Microsoft Entra ID Enables Privilege Escalation
CVE-2026-83941 is a missing-authorization flaw (CWE-862) in Microsoft Entra ID, the cloud identity service behind Microsoft 365 and Azure. An already-authenticated, low-privileged user can send a network request to an Entra ID endpoint that fails to enforce proper authorization checks, requiring no user interaction. Exploitation lets the attacker elevate their privileges within the directory, with high confidentiality and integrity impact (CVSS 9.9, scope changed). Any organization that uses Microsoft Entra ID is in the affected population. The flaw was patched in Microsoft's September 2026 Patch Tuesday release; it is not in CISA KEV, has no known public proof-of-concept, and carries a low EPSS of roughly 0.7%.
Heap-Based Buffer Overflow RCE in Windows Print Spooler Components (CVE-2026-85877)
CVE-2026-85877 is a heap-based buffer overflow (CWE-122) in the Windows Print Spooler components, fixed by Microsoft in its September 2026 Patch Tuesday release. A remote, unauthenticated attacker can trigger the flaw by sending crafted input to the Print Spooler service over the network, though the CVSS vector (UI:R) indicates some form of user interaction is required for successful exploitation. If exploited, the attacker gains arbitrary code execution on the target system, with the CVSS base metrics indicating high impact to confidentiality, integrity, and availability. Any Windows system with the Print Spooler service enabled is affected; the available data does not enumerate specific vulnerable Windows versions or builds. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation within the next 30 days (37th percentile).
· Microsoft Windows Print Spooler Components (Windows systems with the Print Spooler service enabled)mass
Heap Buffer Overflow RCE in Microsoft Word (Office 2016-2024, Microsoft 365 & Apps)
A heap-based buffer overflow (CWE-122) in Microsoft Word's document processing allows an unauthorized, remote attacker to execute arbitrary code when the user opens or previews attacker-supplied Word document content, with the CVSS vector indicating no privileges required but user interaction needed. A successful attacker gains code execution in the context of the logged-in user, with high impact on confidentiality, integrity, and availability. Anyone running Word from Office 2016, 2019, 2021, or 2024, Microsoft 365, or Microsoft 365 Apps is affected. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns roughly a 0.6% probability of exploitation within 30 days, indicating no known exploitation in the wild.
Untrusted Pointer Dereference LPE in Windows Secure Kernel Mode
CVE-2026-83939 is an untrusted pointer dereference (CWE-822) in the Windows Secure Kernel Mode, the high-privilege virtualization-based security component of Windows. A local attacker who is already authorized and holds high privileges on the system can trigger the flaw by causing the Secure Kernel to dereference an attacker-influenced pointer, gaining local elevation of privileges. Because the CVSS scope is 'changed' (S:C), the flaw lets an attacker cross a security boundary beyond the process they started in, with high impact on confidentiality, integrity and availability. Any Windows installation whose Secure Kernel component is affected is at risk, per Microsoft's September 2026 Patch Tuesday advisory; exact version ranges are listed in Microsoft's bulletin. There is no known in-the-wild exploitation, no public proof-of-concept, and a low 0.3% EPSS probability of exploitation in the next 30 days, but a fix shipped as part of the 974-vulnerability September 2026 release.
· Microsoft Windows (Secure Kernel Mode component)mass
Use-After-Free RCE in Windows Message Queuing (MSMQ)
CVE-2026-83997 is a use-after-free (CWE-416) vulnerability in Microsoft's Windows Message Queuing (MSMQ) service that permits an unauthenticated, remote attacker to execute arbitrary code over the network. It is triggered when the MSMQ service processes specially crafted network traffic that causes memory to be used after it has been freed, with the high attack-complexity rating (AC:H) indicating the attacker likely needs to win a timing or state race to land the free-then-use condition. Successful exploitation yields code execution in the context of the MSMQ service, with high confidentiality, integrity, and availability impact, meaning an attacker could take over the affected host. Only Windows systems that have the optional Message Queuing (MSMQ) feature installed and running are exposed, since MSMQ is not enabled by default on most Windows installations and is typically found on legacy application and queuing servers. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, EPSS is 0.5% (42nd percentile), and the two actively exploited zero-days mentioned in September 2026 Patch Tuesday headlines are separate issues fixed in the same release.
· Microsoft Windows Message Queuing (MSMQ) - Windows releases with the optional Message Queuing feature installed and runninglarge
Heap Buffer Overflow in Microsoft Excel Allows Local Code Execution (CVE-2026-81959)
CVE-2026-81959 is a heap-based buffer overflow (CWE-122) in Microsoft Office Excel, with an associated integer overflow/wraparound (CWE-190) that Microsoft notes as part of the flaw. Because the attack vector is local and requires user interaction, exploitation requires a user to open a specially crafted spreadsheet file in an affected Excel or Office installation, for example one delivered via email or downloaded from an untrusted source. Successful exploitation allows an unauthorized attacker to execute arbitrary code in the context of the current user, with high impact on confidentiality, integrity, and availability on the victim machine. Anyone running Excel in Microsoft 365 Apps or perpetual Office 2016, 2019, 2021, or 2024 is affected. The flaw was addressed in Microsoft's September 2026 Patch Tuesday (a release covering 974 vulnerabilities); it is not in CISA KEV, no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at just 0.4%, so no confirmed in-the-wild exploitation is known.
Out-of-bounds Read in Windows Kerberos KDC Enables Network Denial of Service
CVE-2026-84001 is an out-of-bounds read (CWE-125) in the Windows Key Distribution Center (KDC), the Kerberos authentication component built into Windows. An unauthorized, remote attacker can trigger it by sending specially crafted network requests to the KDC service, causing the service to read beyond allocated memory. According to the CVSS vector, the impact is availability-only (C:N/I:N/A:H): the attacker gains denial of service, not code execution, data theft, or tampering, though taking down the KDC on domain controllers can disrupt Kerberos authentication for an entire Active Directory domain. Any Windows system running the KDC is affected, chiefly Windows domain controllers and servers, although the specific affected Windows version ranges are not enumerated in the available data. There is no known public proof-of-concept, the CVE is not in CISA's KEV catalog, and its EPSS probability of ~0.6% suggests exploitation risk is currently low; the fix shipped in Microsoft's September 2026 Patch Tuesday release.
· Microsoft Windows (Key Distribution Center / Kerberos KDC service, primarily on Windows domain controllers and servers)mass
Capture-replay authentication bypass in Microsoft MSAL for Node.js
CVE-2026-84003 is an authentication bypass by capture-replay (CWE-294) in the Microsoft Authentication Library (MSAL) for Node.js, the library Node.js applications use to authenticate users and services against Microsoft's identity platform. An attacker positioned on the network who can capture authentication material in transit can replay it to authenticate as a legitimate user or client, with no privileges or user interaction required; the high attack complexity reflects the difficulty of intercepting and replaying the exchange while it remains valid. Successful exploitation enables spoofing with high impact on confidentiality and integrity (the attacker can act as the victim), though there is no availability impact. Any organization running Node.js server applications, APIs, daemons, or CLIs that depend on MSAL for Node.js is affected, with end users of those applications exposed through them. As of this writing there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at 0.4% (37th percentile); the fix shipped in Microsoft's September 2026 Patch Tuesday.
· Microsoft Authentication Library (MSAL) for Node.js (@azure/msal-node)mass
Out-of-Bounds Read in Windows Virtualization-Based Security (VBS) Enclave
An out-of-bounds read (CWE-125) in the Windows Virtualization-Based Security (VBS) Enclave allows a locally authenticated, low-privilege attacker to read memory beyond the enclave's intended boundary. It is triggered by code running locally under an authorized account that interacts with the enclave, with no user interaction required. The result is information disclosure only - potentially leaking data the enclave was meant to isolate, such as secrets or protected content - with no impact on integrity or availability. Any Windows system with VBS Enclave support is affected; Microsoft patched the issue in its September 2026 Patch Tuesday release, which fixed 974 vulnerabilities. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 0.3 percent 30-day exploitation probability, so no exploitation is currently known.
· Microsoft Windows Virtualization-Based Security (VBS) Enclavemass
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.