Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1
Canada's Cyber Centre relays Microsoft's September 2026 rollup; CISA added exploited zero-days CVE-2026-85880 and CVE-2026-81963 to KEV.
Advisory AV26-896 from the Canadian Centre for Cyber Security summarizes Microsoft's September 2026 monthly security rollup, listing affected products across Windows, Office, .NET, Azure, Exchange and SQL Server. It notes Microsoft confirmed CVE-2026-81963 and CVE-2026-85880 have been exploited. On September 8, 2026, CISA added both CVEs to its Known Exploited Vulnerabilities catalog, and administrators are urged to apply the updates.
- CISA added CVE-2026-81963 and CVE-2026-85880 to the KEV database on September 8, 2026
- Affected products span Windows, Windows Server, Office, .NET, ASP.NET Core, Exchange, SharePoint and Azure services
- Cyber Centre recommends administrators review links and apply Microsoft's September 2026 updates promptly
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81963 +1 in the same advisory: …85880 | Local Privilege Escalation via Link Following in Windows Update Stack CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use. Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems. | 7.8 | <1% | KEV |
| masswell over 1,000,000 |
Full article446 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-896
Date: September 8, 2026
As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products:
- .NET 10.0 installed on Linux
- .NET 10.0 installed on Mac OS
- .NET 10.0 installed on Windows
- .NET 11.0 installed on Linux
- .NET 11.0 installed on Mac OS
- .NET 11.0 installed on Windows
- .NET 8.0 installed on Linux
- .NET 8.0 installed on Mac OS
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- ASP.NET Core 10.0
- ASP.NET Core 11.0
- ASP.NET Core 8.0
- ASP.NET Core 9.0
- Azure AI Language Authoring
- Azure Arc SQL Server Extension
- Azure Cosmos DB
- Azure CycleCloud
- Azure HDInsight
- HEIF Image Extension
- HEVC Video Extensions
- HEVC Video Extensions for Licensed Applications
- HEVC Video Extensions from Device Manufacturer
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2
- Microsoft .NET Framework 3.5 AND 4.7.2
- Microsoft .NET Framework 3.5 AND 4.8
- Microsoft .NET Framework 3.5 AND 4.8.1
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
- Microsoft .NET Framework 4.8
- Microsoft .NET Framework 4.8.1
- Microsoft 365 Apps for Enterprise
- Microsoft Access 2016
- Microsoft Authentication Library (MSAL)
- Microsoft Authenticator for Android
- Microsoft Azure Active Directory B2C
- Microsoft Azure CLI
- Microsoft Copilot Studio
- Microsoft Discovery Studio
- Microsoft Dynamics 365 (on-premises)
- Microsoft Dynamics 365 Customer Engagement
- Microsoft Entra ID
- Microsoft Excel 2016
- Microsoft Exchange Server 2016
- Microsoft Exchange Server 2019
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Fabric
- Microsoft Office 2016
- Microsoft Office 2019
- Microsoft Office 365 for Mac
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
- Microsoft Office LTSC for Mac
- Microsoft Office for Android
- Microsoft Outlook 2016
- Microsoft Power Platform
- Microsoft PowerPoint 2016
- Microsoft Publisher 2016
- Microsoft SQL Server 2017
- Microsoft SQL Server 2019
- Microsoft SQL Server 2022
- Microsoft SQL Server 2025
- Microsoft SharePoint Server Subscription Edition
- Microsoft Teams for Android
- Microsoft Visual Studio 2022
- Microsoft Visual Studio 2026
- Microsoft Word 2016
- Microsoft.AspNetCore.OData
- Microsoft.Diagnostics.Runtime
- Office Online Server
- Power Automate agent for virtual desktops
- Power Automate for Desktop
- Raw Image Extension
- Remote Desktop client for Windows Desktop
- SQL Server Management Studio 22
- Skype for Business Server 2015
- Skype for Business Server 2019
- Skype for Business Server Subscription Edition CU1
- Spring Cloud Azure
- Visual Studio Code
- Web Media Extensions
- WebP Image Extension
- Windows 10
- Windows 11
- Windows Server 2012
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- Windows Server 2025
Microsoft has indicated that CVE-2026-81963 and CVE-2026-85880 have been exploited.
Update 1
On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81963 and CVE-2026-85880 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-september-2026-monthly-rollup-av26-896