It’s the second Tuesday of September, which means it’s time for another Patch Tuesday recap. It’s also International Literacy Day, which is rather fitting since Microsoft has given us plenty of reading material lately. For the last few months, release notes have read like a trilogy. July dropped 570 CVEs and August came back with 398. My reading list has never been longer or less enjoyable.
So the question this month is whether we get another doorstopper or did Microsoft finally hand us a short story? Let’s find out.
Severity
Total exploits patched: 973
Critical patches: 113
Important: 860
Moderate: 0
Low: 0
Vulnerability impact
Remote code execution: 258
Elevation of privilege: 438
Information disclosure: 173
Spoofing: 16
Tampering: 13
Denial of service: 56
Feature bypass: 19
Availability
Publicly disclosed: 0
Actively exploited: 2
Some highlights (or lowlights)
CVE-2026-83711, CVE-2026-70352, CVE-2026-83941: Starting at the top of the leaderboard with two perfect 10.0s and a 9.9. All three are critical elevation of privilege vulnerabilities, hitting Azure Active Directory B2C, Azure AI Language, and Entra ID respectively. Before you panic, these are all Microsoft-hosted services, which means Microsoft found the hole, Microsoft fixed the hole, and Microsoft is now telling us about the hole. There's nothing here for you to deploy, which is the nicest thing I'll say about Microsoft all month.
CVE-2026-81963: Out of 973 CVEs, only two are actively exploited in the wild, and one of them is in the Windows Update Stack. You read that right; the bad actors are attacking the very thing we use to protect ourselves from bad actors with CVE-2026-81963. Come on Windows Update, you were the chosen one. You were supposed to destroy the vulnerabilities, not join them. This is a 7.8 rated elevation of privilege with a local attack vector and low privilege requirements, which means the bad guys have to already have some kind of foothold in your environment to take advantage of this. Time to patch your patcher.
The 9.8 club: We've got 35 CVEs rated 9.8 this month, and 34 of them are remote code execution. This is where the real action lies. A 9.8 means network attack vector, low complexity, no privileges, and no user interaction, a.k.a. the quadfecta. Sixteen of them target services that sit on a port waiting to be talked to, including DHCP, DNS, Netlogon, RRAS, and NFS. Another eleven are file and media parsers. My favorite detail is that only 18 of the 35 are rated critical, so apparently a 9.8 in the Windows kernel is merely "important."
CVE-2026-72983: Internet Connection Sharing (ICS) Remote Code Execution (Critical)
CVE-2026-69491: Microsoft DirectMusic Remote Code Execution (Important)
CVE-2026-73010: Microsoft Failover Cluster Remote Code Execution (Critical)
CVE-2026-78509: Microsoft Office Outlook Remote Code Execution (Critical)
CVE-2026-69824: Microsoft Standard XPS Remote Code Execution (Important)
CVE-2026-69276: Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution (Important)
CVE-2026-69408: Microsoft Windows Media Foundation Remote Code Execution (Important)
CVE-2026-69586: Microsoft Windows PDF Remote Code Execution (Important)
CVE-2026-78510: Microsoft Word Remote Code Execution (Critical)
CVE-2026-69819: RPC Runtime Library Remote Code Execution (Important)
CVE-2026-69525: Remote Desktop Services Remote Code Execution (Important)
CVE-2026-66302: Skype for Business Remote Code Execution (Critical)
CVE-2026-69431: Telnet Client Remote Code Execution (Important)
CVE-2026-69496: Windows Compressed Folder Remote Code Execution (Important)
CVE-2026-69845: Windows DHCP Server Remote Code Execution (Critical)
CVE-2026-72979: Windows DHCP Server Remote Code Execution (Critical)
CVE-2026-69730: Windows DNS Server Remote Code Execution (Critical)
CVE-2026-69715: Windows Direct Show Remote Code Execution (Important)
CVE-2026-69493: Windows Event Logging Service Remote Code Execution (Important)
CVE-2026-77493: Windows Graphics Component Remote Code Execution (Critical)
CVE-2026-69769: Windows HTTP Print Provider Remote Code Execution (Critical)
CVE-2026-69910: Windows Hyper-V Remote Code Execution (Important)
CVE-2026-70296: Windows Imaging Component Remote Code Execution (Critical)
CVE-2026-69669: Windows Kernel Remote Code Execution (Important)
CVE-2026-69579: Windows Message Queuing Remote Code Execution (Critical)
CVE-2026-69463: Windows NTFS Remote Code Execution (Important)
CVE-2026-72982: Windows Netlogon Remote Code Execution (Critical)
CVE-2026-69768: Windows RNDIS Remote Code Execution (Important)
CVE-2026-69590: Windows Routing and Remote Access Service (RRAS) Remote Code Execution (Critical)
CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution (Critical)
CVE-2026-69595: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution (Critical)
CVE-2026-78445: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution (Critical)
CVE-2026-69829: Windows Shell Remote Code Execution (Critical)
CVE-2026-68839: Windows USB Mass Storage Class Driver Remote Code Execution (Important)
CVE-2026-73025: Windows iSCSI Security Feature Bypass (Important)
Wrapping up
That wraps up this Patch Tuesday recap, but I thought I would regale you with one of my favorite Lord of the Rings quotes in celebration of International Literacy Day. As Bilbo Baggins would say, “It’s a dangerous business, deploying updates. You click approve, and if you don’t keep your footing, there’s no telling where the rest of your week ends up.” Or something like that. Which just goes to show you that even Bilbo knew you should be testing your updates before you deploy them. Just don’t wait too long or Sauron-bot might become the Lord of the Pings on your network.



