Microsoft’s September updates repair a report 973 safety flaws
The subsequent Patch Tuesday is scheduled for October thirteenth, 2026.
Home windows safety vulnerabilities
Numerous the vulnerabilities—over 700 this time—are unfold throughout the varied Home windows variations (10, 11, Server) for which Microsoft nonetheless offers safety updates.
This month, two Home windows vulnerabilities categorised as excessive threat are already being exploited within the wild. The CVE-2026-81963 vulnerability within the Home windows Replace stack permits attackers to achieve elevated privileges, enabling them to execute code with system privileges by combining this exploit with an RCE vulnerability.
The second zero-day vulnerability, CVE-2026-85880, is in Home windows Superior Native Process Name (ALPC) and it’s additionally an elevation of privilege (EoP) vulnerability. On this case, the exploit code have to be hid inside a doc so {that a} consumer can set off it. For each zero-days, it’s unclear how widespread the assaults are.
Important Home windows vulnerabilities
Microsoft has categorised 77 Home windows vulnerabilities as essential, together with 56 RCE vulnerabilities. These embrace CVE-2026-69525 within the Home windows Distant Desktop Service, a use-after-free (UAF) vulnerability that an attacker may exploit to remotely execute injected code with out authentication or consumer interplay.
Home windows Hi there additionally has 9 vulnerabilities, eight of that are EoP vulnerabilities categorised as essential. Microsoft needed to patch 64 vulnerabilities within the biometric service, most of them similar to each other and following the identical sample. In 56 instances, there are buffer overflows. CVE-2026-69727 permits elevated privileges over the community, whereas CVE-2026-73008 exposes private knowledge—hardly what one would need or count on from a biometric service.

