Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Imported from official source

Cybersecurity Classified by Officially

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."

Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:

CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.

CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). CVE-2026-85880 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Use of Uninitialized Resource and has a CVSS base score of 7.8.

Out of 113 "critical" vulnerabilities, 82 are remote code execution (RCE) vulnerabilities.

Microsoft considers exploitation of the following vulnerabilities more likely:

CVE-2026-69676 affects Windows Kerberos. CVE-2026-69676 is a remote code execution vulnerability associated with Authentication Bypass by Capture-replay and has a CVSS base score of 8.8.

CVE-2026-69852 affects Windows Routing and Remote Access Service (RRAS). CVE-2026-69852 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.5.

CVE-2026-72957 affects Windows Deployment Services. CVE-2026-72957 is a remote code execution vulnerability associated with Heap-based Buffer Overflow and has a CVSS base score of 7.8.

CVE-2026-69854 affects Spring Cloud Azure. CVE-2026-69854 is a elevation of privilege vulnerability associated with Improper Authentication and has a CVSS base score of 9.0.

CVE-2026-83501 affects Windows Virtualization-Based Security (VBS). CVE-2026-83501 is a information disclosure vulnerability associated with Out-of-bounds Read and has a CVSS base score of 5.5.

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/

Officially imported this from Cisco Talos Intelligence’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Cisco Talos Intelligence — imported from official source
Official source
https://blog.talosintelligence.com/rss/ RSS
Imported
September 18, 2026 11:34
Versions
1 recorded
Identity
6aa0887d3930c20001ad11a5

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.