TLP:CLEAR
Microsoft September 2026 Threat & Deployment BriefTwo Exploited Zero-Days, a Zero-Click Outlook 9.8, and a Record 974 CVEs

Deploy the Windows September update first — two elevation-of-privilege zero-days are being exploited, and between them they cover every supported Windows build. Then five server updates on the five-day clock: SharePoint, Exchange, SQL Server, Skype for Business and Dynamics. Then Office, for two 9.8 flaws that need no click.

Deploy first
Windows client and server September 2026 security update (client: KB5124008 · KB5122880 · KB5124012 · KB5122878; server: KB5122871 · KB5122882 · KB5122876 · KB5123099 · KB5123065 · KB5123066)
Act units
6
Hunt required
1 unit — exploited pre-fix
No patch exists
2 — mitigate & monitor
Release
Microsoft 2026-09-08
CVEs
964–999 (by counter)
KEV read
2026-09-10
Report
ITS-EXV-2026-0908

The Windows update ships first, and there is no build it does not matter for. Two elevation-of-privilege flaws are being exploited in the wild, both to SYSTEM, and Microsoft's own product lists split them cleanly: CVE-2026-81963 in the Windows Update Stack affects only Windows 11 (23H2 through 26H1) and Windows Server 2025, while CVE-2026-85880 in ALPC (Advanced Local Procedure Call, the kernel's inter-process messaging channel) affects only Windows 10 and Windows Server 2012 through 2022. Every supported Windows generation carries exactly one exploited zero-day this month. The same update also closes 31 unauthenticated, no-interaction 9.8 remote-code-execution flaws, among them a DNS Server flaw Microsoft rates 'Exploitation More Likely' and a Netlogon flaw that runs on every domain controller.

This is a severity inversion at record scale. Microsoft's release note counts 974 CVEs — the largest Patch Tuesday it has ever shipped, more than double August — and rates 113 of them Critical. Neither exploited flaw is among them: both score 7.8 and are rated Important. Not one of the 113 Critical flaws has an exploitation signal today. Tenable's Satnam Narang put it plainly in a statement carried by Krebs on Security and SecurityWeek: AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it is not finding more needles. A queue sorted by CVSS spends its first week on flaws nobody is using and buries the two that someone is.

Patching does not answer whether you were already hit. Both zero-days were exploited before this fix existed. Microsoft has published no attribution and no scale; the discoverers are Proofpoint and Volexity for the ALPC flaw, and Romain Deperne and Microsoft's own threat-intelligence centre for the Update Stack flaw. The ALPC flaw is an AppContainer sandbox escape — the primitive that sits behind a browser or document exploit — so a clean patch state says nothing about a foothold that already escaped. Compromise assessment is a separate obligation on this unit.

Exposed servers and Office need their own changes. SharePoint Server Subscription Edition ships six network remote-code-execution fixes; SharePoint 2016 and 2019 left support on 14 July 2026 and receive nothing. Exchange fixes an unauthenticated mail-processing flaw (CVE-2026-55007) and two mailbox-takeover flaws. SQL Server ships 63 fixes, one of them a prompt-injection flaw in SQL Copilot. And Office carries two 9.8s that need no click at all — an Outlook flaw that fires when the Outlook Reading Pane draws the message, and a Word flaw that fires when the Windows Explorer preview pane renders the file — with no fix yet for Office on the Mac.

Next month is a support cliff, and this update is the rehearsal. On 13 October 2026 the third and final year of Extended Security Updates for Windows Server 2012 and 2012 R2 ends, the first year of Windows 10 ESU ends, Windows 11 24H2 Home and Pro reach end of updates, and Office LTSC 2021 leaves mainstream support. September's update is the second-to-last one Server 2012 and 2012 R2 will ever receive. If those hosts are still on the estate, the deployment problem this month is migration, not patching.

The worklist

1

Windows client and server September 2026 security update (client: KB5124008 · KB5122880 · KB5124012 · KB5122878; server: KB5122871 · KB5122882 · KB5122876 · KB5123099 · KB5123065 · KB5123066)

Per-product servicing — see table
ACT · under attack
emergency change, ≤72h

Why now. Two flaws in this update are being exploited in the wild, and CISA has given federal agencies until 22 September to close them. Both are local elevations of privilege to SYSTEM, so on their labels they look deferrable: an attacker needs a foothold first. Active exploitation is the reason they cannot wait, and the shape of the two flaws is the reason nobody gets to sit this one out. Microsoft's product lists split them cleanly. CVE-2026-81963, in the Windows Update Stack, affects only Windows 11 (23H2 through 26H1) and Windows Server 2025. CVE-2026-85880, in ALPC, affects only Windows 10 and Windows Server 2012 through 2022 — and it is an AppContainer sandbox escape, the primitive an attacker reaches for after a browser or document exploit lands in a sandbox. Every supported Windows generation therefore carries exactly one exploited zero-day this month, and this update is the only fix for either. The same update is also the only route to 31 unauthenticated, no-interaction 9.8 remote-code-execution flaws, including a DNS Server flaw Microsoft rates 'Exploitation More Likely' — ZDI calls it SigRed's spiritual successor — a Netlogon flaw that gives an unauthenticated attacker code execution on a domain controller, and a Remote Desktop Services flaw, also 'Exploitation More Likely', that Microsoft rated Important rather than Critical. Those are the ways in that the two exploited escalations are built to follow. One deployment closes both halves.

This unit cannot slip. Assessed to cut 3 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.

ProductPackageCarries (named in this brief)
Windows 11 24H2 / 25H2 (OS builds 26100.9445 / 26200.9445)KB5124008CVE-2026-81963, CVE-2026-69525, CVE-2026-72982, CVE-2026-69676
Windows 11 23H2 Enterprise / Education (OS build 22631.7582 per the CVRF fixed build; Microsoft's KB page heading reads 22621.7582; Home and Pro already past end of updates)KB5122880CVE-2026-81963, CVE-2026-69525, CVE-2026-72982, CVE-2026-69676
Windows 11 26H1 (new devices only; OS build 28000.2954)KB5124012CVE-2026-81963, CVE-2026-69525, CVE-2026-72982, CVE-2026-69676
Windows 10 22H2 (Extended Security Updates) and Windows 10 21H2 Enterprise LTSC (OS builds 19045.7725 / 19044.7725)KB5122878CVE-2026-85880, CVE-2026-69525, CVE-2026-72982, CVE-2026-69676
Windows Server 2025 (OS build 26100.33438)KB5122871CVE-2026-81963, CVE-2026-69730, CVE-2026-72982, CVE-2026-69676, CVE-2026-69712, CVE-2026-69525
Windows Server 2022 (OS build 20348.5622)KB5122882CVE-2026-85880, CVE-2026-69730, CVE-2026-72982, CVE-2026-69676, CVE-2026-69712, CVE-2026-69525
Windows Server 2019 and Windows 10 1809 Enterprise LTSC (OS build 17763.9245)KB5122876CVE-2026-85880, CVE-2026-69730, CVE-2026-72982, CVE-2026-69676, CVE-2026-69712, CVE-2026-69525
Windows Server 2016 and Windows 10 1607 Enterprise LTSB (OS build 14393.9512; install servicing stack update KB5122874 first — on this build the SSU is also Microsoft's listed fix for CVE-2026-81955)KB5123099CVE-2026-85880, CVE-2026-69730, CVE-2026-72982, CVE-2026-69676, CVE-2026-69712, CVE-2026-69525
Windows Server 2012 (Extended Security Updates; Monthly Rollup)KB5123065CVE-2026-85880, CVE-2026-69730, CVE-2026-72982, CVE-2026-69676, CVE-2026-69712, CVE-2026-69525
Windows Server 2012 R2 (Extended Security Updates; Monthly Rollup)KB5123066CVE-2026-85880, CVE-2026-69730, CVE-2026-72982, CVE-2026-69676, CVE-2026-69712, CVE-2026-69525

Also inside: 715 CVEs ride this update across its ten KBs — 72 Critical, 31 at 9.8 with a network vector and no privileges or interaction required, and 56 carrying Microsoft's 'Exploitation More Likely' rating. Two honesty notes on the 9.8s. First, for several of them (RPC Runtime, Windows Shell, USB Mass Storage, UxTheme, Media Foundation, Telnet Client, NTFS, Compressed Folder, Windows PDF, RNDIS, XPS, HTTP Print Provider, Event Logging) Microsoft's own advisory says nothing more specific than that an 'in-network attacker calling arbitrary endpoints' could gain code execution; the score says unauthenticated and network, the description does not say how. The flaws Microsoft describes concretely — a crafted packet to a listening service — are DNS Server, Netlogon, MSMQ, RRAS, DHCP Server, SSTP, Internet Connection Sharing, Failover Cluster, NFS and the SMB client, and those are the ones the Exvora AI team treats as this month's substantive entry points. Second, the Hyper-V 9.8 (CVE-2026-69910) is scored unauthenticated-network but its two FAQ answers both describe an attacker inside a guest VM; read it as a guest-to-host escape, not an internet-facing one. Also here: a network-reachable SYSTEM escalation in afd.sys (CVE-2026-70342, 8.1, 'Exploitation More Likely') in the same driver as August's exploited zero-day; a Critical Kerberos and KDC pair on domain controllers (CVE-2026-69676, CVE-2026-69712, both 8.8); a Schannel client flaw (CVE-2026-72940, 8.8, 'Exploitation More Likely') triggered by connecting to a hostile server; nine Critical Windows Hello flaws, eight of them elevation and one a security feature bypass, inside a 64-CVE Windows Biometric Service cluster; and Secure Kernel, VBS and Credential Guard escalations that reach the virtual trust boundary. ZDI counts 20 patches in this release that could be classified as wormable; every one of them is in this update.

Patching is not remediation. Both CVE-2026-81963 and CVE-2026-85880 were exploited as zero-days, before this fix existed, so deployment and compromise assessment are two obligations and this unit discharges only the first. Microsoft has published no attribution and no indication of scale; The Register records 'no word yet on who is exploiting this bug, and to what end'. The shape of the flaws tells you where to look. CVE-2026-85880 is an AppContainer escape: the foothold it completes is a sandboxed process — a browser renderer, an Office document handler, a PDF viewer — so hunt on Windows 10 and Server 2012 through 2022 for AppContainer-hosted processes spawning children at integrity levels they should never reach, and for unexpected SYSTEM-level process creation whose parent chain starts in a user application. CVE-2026-81963 abuses how the Windows Update Stack follows links before it touches files, so on Windows 11 and Server 2025 hunt for reparse points, junctions and symbolic links created by low-privileged accounts under update-staging and servicing paths, and for system components replaced outside a genuine servicing event — Rapid7's inference, not Microsoft's statement, is that the fix stops the update stack from 'overwriting a system component with an attacker-controlled imposter'. On any host where either escalation ran, assume SYSTEM was reached and scope from there.

Then. Deploy the update for each build and reboot. Order inside the unit by role: domain controllers first — DNS Server, Netlogon, Kerberos and the KDC all ride the DC — then any host that exposes Remote Desktop, RRAS or SSTP, MSMQ, NFS, Internet Connection Sharing or Failover Cluster to a segment you do not fully trust, then the rest of the fleet. Where MSMQ, RRAS or NFS are installed but unused, disabling the role or filtering it at the host firewall closes the entry ahead of the reboot window; the SANS Internet Storm Center makes the same recommendation for MSMQ on TCP 1801. Windows Server 2016 needs the servicing stack update KB5122874 installed first and both approved in WSUS, or the security update is not offered. Windows 10 22H2 receives KB5122878 only under Extended Security Updates, and Microsoft published a new ESU licensing preparation package, KB5126256, on 8 September that supersedes the earlier one. Windows Server 2012 and 2012 R2 receive KB5123065 and KB5123066 only under ESU — and that programme's third and final year ends on 13 October 2026, one month from now. Windows 11 26H1 is a new-device-only version and is not offered as an in-place update to existing 24H2 or 25H2 devices; its KB is KB5124012. What will break: one reboot per host, and Microsoft lists no known issues on eight of the ten update pages. The two exceptions are Server 2025 (KB5122871) and Server 2022 (KB5122882), which carry forward an existing WSUS defect — synchronisation error details are not displayed, a function Microsoft removed to fix an older remote-code-execution flaw. Then treat the two exploited flaws as a hunt, not only a patch — see the compromise-assessment note.

The analyst's judgment in this unit

It ships first because two flaws in it are being exploited right now. Both are local escalations: they help an attacker who is already on the machine, they do not get one in. The honest caveat is the same one this brief made in August. The evidence is why this cannot wait, not the reachability. Two things still put it first. You do not get to assume nothing is already inside; the compromise-assessment step exists for that. And the same update carries the DNS Server, Netlogon and Remote Desktop flaws, which are ways in. One more judgment sits in this unit. Microsoft's own descriptions for many of the 9.8 flaws are a generic sentence, so the Exvora AI team leans on the ones Microsoft describes concretely. If you weight every 9.8 equally, the order inside this unit changes; the decision to deploy it first does not. The claim below that this update breaks the most attack chains is the Exvora AI team's analysis, not something Microsoft attests.

2

SharePoint Server Subscription Edition September 2026 security update (KB5002908)

Per-product servicing — see table
ACT · structural
≤5 days

Why now. SharePoint is a listed exposed technology: a collaboration server reachable from an untrusted network by design, and the product family that has been exploited more often than any other Microsoft server this year — April's CVE-2026-32201 and July's chain, which Ivanti records as exploited within hours of Rapid7's 11 August write-up. This release ships sixteen SharePoint fixes, six of them network remote code execution, every one requiring an authenticated user. ZDI singles out CVE-2026-69465, a control-safety bypass that makes the server load a code library from a location the attacker controls, as the type of bug recently exploited. None has an exploitation signal yet, which is why this unit sits behind the Windows update rather than beside it — but an internet-facing farm with an unpatched network code-execution flaw is a five-day decision, not a normal-cycle one.

ProductPackageCarries (named in this brief)
SharePoint Server Subscription EditionKB5002908CVE-2026-69465, CVE-2026-69268, CVE-2026-69273, CVE-2026-69282, CVE-2026-69724, CVE-2026-69464

Also inside: Only Subscription Edition receives this update. SharePoint Server 2016 and 2019 left extended support on 14 July 2026 and Microsoft lists no September fix for either; the CVRF product list for every one of the sixteen SharePoint CVEs contains Subscription Edition alone. If you still run 2016 or 2019, there is nothing to deploy — the honest lane is mitigate and monitor, and the fix is migration. Office Online Server receives its own update, KB5002910, in the same cycle.

Then. Installing the Windows update does not patch a SharePoint farm. SharePoint servicing is its own path, with its own change window, its own validation and a Configuration Wizard run after KB5002908 installs. Where a farm is published to the internet, treat this as the five-day structural-Act item it is; where it sits behind an authenticating proxy, the soft call below applies.

The analyst's judgment in this unit

This unit is Act, not Prioritise, for two reasons. SharePoint is internet-facing by design, and a network code-execution flaw clears the gate. But every one of these six flaws needs an authenticated account, and none is being exploited. A farm behind an authenticating reverse proxy drops to Prioritise and a 14-day clock. If you run SharePoint 2016 or 2019, this unit has nothing to deploy for you. The honest lane there is mitigate and monitor, and the real fix is migration. If you run no on-premises SharePoint, this unit does not apply.

3

Exchange Server September 2026 security update (KB5121608 Subscription Edition RTM · KB5121609 2019 CU15 · KB5121610 2019 CU14 · KB5121611 2016 CU23)

Per-product servicing — see table
ACT · structural
≤5 days

Why now. Exchange is the mail edge — exposed technology in the frozen list. CVE-2026-55007 is the flaw to read first: an unauthenticated attacker sends an email with a crafted Visio attachment and the server executes code while it indexes the content. Nobody has to open anything; ZDI notes it does not even need the Preview Pane. Microsoft scores it 8.1 because exploitation is reliable only when the server is under sustained memory pressure, and ZDI's Dustin Childs answers that the way an operator should: the attacker only needs to get it right once. Beside it sit an authenticated code-execution flaw (CVE-2026-69355, 8.8), a 9.3 cross-site-scripting flaw that runs script inside a user's Outlook on the web session from a calendar invitation, and two mailbox-takeover flaws — CVE-2026-69641 for a highly privileged role member and CVE-2026-69380 for any user with a mailbox, which Tenable highlights precisely because its 'Exploitation Less Likely' rating understates what it does. None has an exploitation signal today, so this is a structural five-day item, not an emergency — but unauthenticated code execution on an internet-facing mail server is not something to leave on the normal cycle.

ProductPackageCarries (named in this brief)
Exchange Server Subscription Edition RTMKB5121608CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69641, CVE-2026-69380
Exchange Server 2019 CU15 (Extended Security Updates)KB5121609CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69641, CVE-2026-69380
Exchange Server 2019 CU14 (Extended Security Updates)KB5121610CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69641, CVE-2026-69380
Exchange Server 2016 CU23 (Extended Security Updates; not affected by CVE-2026-55007)KB5121611CVE-2026-69355, CVE-2026-69356, CVE-2026-69641, CVE-2026-69380

Then. Exchange servicing is its own path, separate from the Windows update. Exchange 2016 and 2019 both left extended support on 14 October 2025 and receive these updates only under Extended Security Updates; Rapid7 records that the ESU arrangement for both is itself due to end in October 2026 after two six-month reprieves. Exchange 2016 CU23 is not affected by CVE-2026-55007 but needs KB5121611 for the other four. If you run 2016 or 2019 without ESU, this unit has no deployable artifact for you and the mitigation lane is the only lane you have.

The analyst's judgment in this unit

Exchange ranks below SharePoint by a narrow margin. SharePoint's six code-execution flaws are low-complexity, and SharePoint has been exploited more often this year. Exchange's one unauthenticated flaw needs a memory-pressure condition Microsoft calls uncommon. If your Exchange is exposed and your SharePoint is not, swap ranks 2 and 3. Nothing above them changes. The 9.3 cross-site-scripting flaw is in this unit because the model treats script in an authenticated mail session as a gate-passing impact on a mail edge. That rule was written after an Exchange flaw of exactly this class was exploited in May.

4

SQL Server September 2026 security updates (SQL 2025: KB5122770 GDR · KB5122769 CU8; SQL 2022: KB5122771 GDR · KB5122768 CU26; SQL 2019: KB5122773 GDR · KB5122772 CU32; SQL 2017: KB5122775 GDR · KB5122774 CU31) and SQL Server Management Studio 22

Per-product servicing — see table
ACT · structural
≤5 days

Why now. SQL Server is core infrastructure — the data platform everything trusts — and this release ships 63 CVEs for it, 24 of them remote code execution. One of those, CVE-2026-47297, is the flaw to read first: Microsoft scores it AV:N/PR:N/UI:N and describes it as deserialization of untrusted data that lets an unauthorized attacker execute code over a network, which on the score alone is an unauthenticated remote takeover of the database host. Its own FAQ then says an authenticated attacker with explicit permissions would have to log in first. The Exvora AI team cannot reconcile the two and does not try: treat any SQL instance reachable from a segment you do not trust as exposed until Microsoft corrects one or the other. Of the remaining 23, twenty need an authenticated SQL principal and three are client-side flaws triggered by connecting to a hostile server. That authentication requirement is the point rather than the comfort: on most estates, application logins held by web tiers are exactly the principals an intruder ends up with, and a crafted query that executes code as the SQL service account turns a stolen connection string into a foothold on the database host. Four of the code-execution flaws are rated Critical — CVE-2026-67631, CVE-2026-67643, CVE-2026-67378 and CVE-2026-67636 — and only CVE-2026-67631, which Microsoft credits to its own red team, reaches every supported version back to SQL 2017; CVE-2026-67643 affects SQL 2022 and 2025 only. The 9.6 is a different animal: CVE-2026-65669 is a prompt-injection flaw in SQL Copilot inside Management Studio 22 — instructions pasted into the assistant bypass its read-only guardrail and act with whatever rights the connected account holds. Automox's line is the right one: a prompt-injection problem wearing a CVE number. It grants no new permission; it exposes the ones already there.

ProductPackageCarries (named in this brief)
SQL Server 2025 — GDR branchKB5122770CVE-2026-47297, CVE-2026-67631, CVE-2026-67643, CVE-2026-67378, CVE-2026-67636
SQL Server 2025 — CU branch (CU8)KB5122769CVE-2026-47297, CVE-2026-67631, CVE-2026-67643, CVE-2026-67378, CVE-2026-67636
SQL Server 2022 — GDR branchKB5122771CVE-2026-47297, CVE-2026-67631, CVE-2026-67643, CVE-2026-67378, CVE-2026-67636
SQL Server 2022 — CU branch (CU26)KB5122768CVE-2026-47297, CVE-2026-67631, CVE-2026-67643, CVE-2026-67378, CVE-2026-67636
SQL Server 2019 — GDR branch (Windows and Linux)KB5122773CVE-2026-47297, CVE-2026-67631, CVE-2026-67378, CVE-2026-67636
SQL Server 2019 — CU branch (CU32)KB5122772CVE-2026-47297, CVE-2026-67631, CVE-2026-67378, CVE-2026-67636
SQL Server 2017 — GDR branch (Windows and Linux)KB5122775CVE-2026-67631
SQL Server 2017 — CU branch (CU31)KB5122774CVE-2026-67631
SQL Server Management Studio 22 (fix ships as an SSMS 22 release; Microsoft lists no KB number)not establishedresolve via vendor advisory before deployment

Then. Pick the branch you are on — GDR if you have never installed a cumulative update, CU otherwise — and install the matching KB for each version; SQL 2017 and 2019 GDR and CU updates cover Linux as well. Update Management Studio to the SSMS 22 release that carries the SQL Copilot fix, and until then treat Copilot's read-only mode as advisory: connect it with a read-only login if you want read-only behaviour. Then review which principals can reach each instance from a user-facing tier; that inventory sets the real clock for this unit.

The analyst's judgment in this unit

This unit is Act on structure. SQL Server is core infrastructure, and code execution over the network clears the gate. Twenty of the 24 code-execution flaws need a SQL login, so on an estate where no untrusted principal can reach an instance the practical clock would be 14 days. CVE-2026-47297 is why the team does not offer that exit this month. Microsoft's score and description say no authentication is needed; Microsoft's FAQ on the same page says it is. If the score is right, a network-reachable instance is exposed to anyone who can open a connection, and five days is the floor. If the FAQ is right, the 14-day reading holds. The team assumes the score until the vendor resolves it, because the cost of being wrong runs one way. Where web tiers hold SQL logins, five days stands regardless. The SQL Copilot flaw needs a user to paste crafted instructions into the assistant. It is here because Management Studio ships in the same servicing cycle, not because it drives the tier.

5

Skype for Business Server September 2026 cumulative update (KB5123287 Subscription Edition CU1 · KB5123300 2019 CU8 · KB5123301 2015 CU13)

Per-product servicing — see table
ACT · structural
≤5 days

Why now. Skype for Business Server is a collaboration server whose Edge role exists to face the internet, and CVE-2026-66302 is an unauthenticated 9.8: a crafted request writes a file where the attacker chooses and the server runs it. No account, no click. The SANS Internet Storm Center puts it immediately after the two exploited zero-days in its own ordering, alongside MSMQ and RRAS. Ten Skype for Business CVEs ship in this cycle; this one is the reason the unit exists. It is a niche product in 2026, which is exactly why it tends to be the forgotten internet-facing server on an estate that migrated to Teams years ago and never decommissioned the old front end.

ProductPackageCarries (named in this brief)
Skype for Business Server Subscription Edition CU1KB5123287CVE-2026-66302, CVE-2026-69646, CVE-2026-66304
Skype for Business Server 2019 CU8KB5123300CVE-2026-66302, CVE-2026-69646, CVE-2026-66304
Skype for Business Server 2015 CU13KB5123301CVE-2026-66302, CVE-2026-69646, CVE-2026-66304

Then. Install the September cumulative update for your edition. Microsoft's lifecycle pages show Skype for Business Server 2015 and 2019 both left extended support on 14 October 2025, yet Microsoft lists September fixes for both — confirm your support arrangement before relying on either KB. Then check whether an Edge or reverse-proxy publication for Skype for Business still exists at all; the most common finding is that it does and nobody owns it.

The analyst's judgment in this unit

This unit reaches Act because the server is designed to face the internet and the flaw needs no account. If you run no Skype for Business Server, it does not apply. If you run it only on an internal network with no Edge role and no published endpoints, it drops to Prioritise and a 14-day clock. The Exvora AI team ranks it below SQL Server only on how many estates each touches, not on severity; on an estate that still publishes Skype for Business, swap it up to rank 2.

6

Dynamics 365 Customer Engagement (on-premises) 9.1 — Service Update 1.48 (KB5123731)

Per-product servicing — see table
ACT · structural
≤5 days

Why now. An on-premises CRM is a published application by design — the frozen list names it as exposed technology — and this release publishes two authenticated code-execution flaws for Dynamics 365 Customer Engagement 9.1, one of them a Critical deserialization bug whose fix Microsoft traces back to July's Service Update 1.46. A CRM login is not a hard thing for an attacker to hold; it is the account class phishing campaigns are built to collect. No exploitation signal, so this is a five-day structural item on any deployment reachable from outside.

ProductPackageCarries (named in this brief)
Dynamics 365 Customer Engagement (on-premises) 9.1 — Service Update 1.48KB5123731CVE-2026-77908
Dynamics 365 (on-premises) 9.1 — Service Update 1.46 (July 2026, build 9.1.0046.0006), which the September CVRF records as the release-note fix for CVE-2026-65772; any deployment at 1.46 or later already has itKB5095498CVE-2026-65772

Then. Install Service Update 1.48 (KB5123731) on the on-premises deployment. The CVE-2026-65772 fix is older than this cycle: the CVRF's fixed build for it is 9.1.0046.0006, which is Service Update 1.46 from July 2026, so a deployment at 1.46 or later already has it and 1.48 carries it forward. Dynamics 365 online tenants are Microsoft's to patch and need nothing from you.

The analyst's judgment in this unit

This unit is Act because a published CRM is exposed technology and code execution clears the gate. Both flaws need an authenticated user. A deployment reachable only from an internal network drops to Prioritise. If you run Dynamics 365 online rather than on-premises, this unit does not apply.

7

Microsoft Office September 2026 security updates (Microsoft 365 Apps, Office LTSC 2024 / 2021 and Office 2019 via Click-to-Run; Office 2016: KB5002923 Word · KB5002914 Excel · KB5002919 Outlook · KB5002920 PowerPoint · KB5002912 Access · KB5002916 · KB5002904 · KB5002913 · KB5002898 Office)

Per-product servicing — see table
PRIORITISE
≤14 days

Why now. 108 CVEs ship for Office this month by Microsoft's own product tags, 20 of them Critical — 22 if the two Windows Graphics Component flaws that also list Office products are counted, which is CrowdStrike's figure — and two of them change what 'client-side' means. CVE-2026-78509 executes when Outlook draws a crafted message in the Reading Pane: Microsoft's own words are that the recipient does not open the message and does not click anything in it. CVE-2026-78510 executes when the Windows Explorer preview pane renders a crafted RTF file, and Microsoft states in that advisory that the Preview Pane is an attack vector. Both score 9.8, both come from the same researcher, Haifei Li of EXPMON, and neither has an exploitation signal. CrowdStrike counts 22 Critical Office patches this month and 12 of them exploitable through a preview or reading pane. The rest of the unit is the familiar Office shape — 38 Word and 32 Excel fixes, Critical 8.8s that need a user to open a file — and would sit on the normal cycle. The two zero-click flaws are why it does not.

ProductPackageCarries (named in this brief)
Microsoft 365 Apps for Enterprise, Office LTSC 2024, Office LTSC 2021 and Office 2019 (Click-to-Run; the fix is a build delivered by update channel, and Microsoft publishes no KB number)not establishedresolve via vendor advisory before deployment
Word 2016 (MSI)KB5002923CVE-2026-78509
Office 2016 (MSI) — shared Office component updateKB5002916CVE-2026-78510, CVE-2026-69285
Excel 2016 (MSI)KB5002914—
Outlook 2016 (MSI) — note: this update does NOT carry the Reading Pane fix. For Office 2016, CVE-2026-78509 ships in the Word update KB5002923KB5002919CVE-2026-69629, CVE-2026-78519, CVE-2026-80073
PowerPoint 2016 (MSI)KB5002920—
Access 2016 (MSI)KB5002912—
Office 2016 (MSI) — further shared component updatesKB5002904—
Microsoft 365 for Mac, Office LTSC for Mac 2021 and 2024 — Microsoft states the fix for CVE-2026-78509 and CVE-2026-78510 is not immediately available and will follow as a revision to the advisorynot establishedresolve via vendor advisory before deployment

Also inside: Microsoft's advisory for CVE-2026-78509 contradicts itself: one answer says viewing the message in the Outlook Reading Pane triggers the flaw without opening or clicking, the next says the Preview Pane is not an attack vector. The Exvora AI team reads the first as Outlook's Reading Pane and the second as the Windows Explorer Preview Pane — two different panes — and treats the Outlook one as the operative statement, because it is the specific one. Microsoft 365 Apps updates do not arrive through Windows Update; they arrive as new builds from the Office content network on each update channel's schedule, and the installer cannot apply one while an Office program is open. For Office 2016 the MSI packages are per application — the Outlook Reading Pane fix is in the Word 2016 update, KB5002923, because Word is Outlook's rendering engine. One more RTF-preview flaw does not live in this unit at all: CVE-2026-77493, a 9.8 in the Windows Graphics Component with the same 'opens the file or it is rendered in the preview pane' description, ships in the Windows update. Patching Office alone leaves it open; that is one more reason the Windows update is rank 1.

Then. Push the September build on every Click-to-Run channel and install the Office 2016 MSI updates, Word and the shared Office update first. Office for the Mac has no fix yet: Microsoft states the updates for Office LTSC for Mac 2021 and 2024 will follow as a revision to the advisory, and the CVRF lists no remediation for Microsoft 365 for Mac either. Until it lands, Mac fleets are in the mitigate-and-monitor lane for both 9.8s: turn off the Outlook Reading Pane or read mail in Outlook on the web, and disable file preview and block RTF at the mail gateway. Protected View does not help here, because the Word flaw fires on preview rather than on open. That is the abstraction leak the model warns about — a fix exists for the CVE but not for every product that carries it.

The analyst's judgment in this unit

The tree files Office as Track: it is neither exposed technology nor core infrastructure, and nothing in it is exploited. The Exvora AI team has moved it up one tier, to Prioritise, and this is the judgment to accept or reject. The reason is narrow. The Track verdict rests on the idea that a client-side flaw needs a user to do something. For the Outlook flaw, Microsoft says the user does nothing. For the Word flaw, Microsoft says previewing is enough. That is the same shape as a network flaw on a listed server: reachable by anyone who can send you mail. A reader who treats mail-borne zero-click code execution as exposed technology would make this a five-day Act unit, and the team thinks that reading is defensible. The model's frozen list does not yet say so, and the team will take that to the model's next revision rather than quietly widen the list here. Reject the judgment and this unit returns to the normal cycle, with the Mac gap still open.

The cut — why the top unit cannot slip

Confidence: moderate — analytic judgement, not vendor-attested

The Windows client and server September 2026 security update (client: KB5124008 · KB5122880 · KB5124012 · KB5122878; server: KB5122871 · KB5122882 · KB5122876 · KB5123099 · KB5123065 · KB5123066) is the cut: it removes both exploited escalation links — CVE-2026-81963 on the Windows 11 and Server 2025 line, CVE-2026-85880 on the Windows 10 and Server 2012 through 2022 line — and it is assessed to cut all three chain classes this month: network entry on a Windows server role followed by escalation to SYSTEM; mail or document entry (the Outlook Reading Pane, Word RTF and Exchange indexing flaws) followed by the ALPC sandbox escape; and an authenticated application foothold (SharePoint, Exchange, SQL Server, Dynamics, Skype for Business) followed by escalation on the host beneath it. It cannot slip.

Basis. Stage 2 composition pass. Both exploited flaws are escalation links to SYSTEM, and the vendor's own product lists show they cover every supported Windows build between them, so every entry link this month lands on a host where one of the two co-locates. ZDI's reading of CVE-2026-85880 — that this class of bug hides within documents, PDFs and other attachments — is the third-party observation that ties the sandbox escape to the document-borne entries. No advisory attests any chain; it is inferred from architecture and from the reported shape of the flaws.

What would lower this. On a well-tiered estate where user-level footholds cannot reach the hosts running exposed entry services, the escalation and entry links do not co-locate on the same asset and the cut's leverage drops to the escalation fix alone. An estate that already blocks RTF and disables the Reading Pane removes the document-entry chain before the patch does. And an attacker who already reached SYSTEM before the fix keeps what they took; the cut is prevention, not remediation.

Confidence: moderate — analytic judgement, not vendor-attested

The Office update is Prioritise, not Track: the Exvora AI team has escalated it one tier because CVE-2026-78509 (Outlook Reading Pane) and CVE-2026-78510 (Word RTF preview) execute with no user action, which removes the premise the tree's Track verdict rests on.

Basis. The tree files Office as Track because it is neither exposed technology nor core infrastructure and nothing in it is exploited. That verdict assumes a client-side flaw needs a user to act. Microsoft's own advisories say the Outlook flaw fires on rendering in the Reading Pane with no open and no click, and that the Preview Pane is an attack vector for the Word flaw. A flaw reachable by anyone who can send mail to the user is, in reach, the same shape as a network flaw on a listed exposed server. The escalation is one tier, the same magnitude the model already grants a public proof-of-concept, and it is labelled here rather than applied silently.

What would lower this. An estate that disables the Outlook Reading Pane, blocks RTF at the mail gateway, or reads mail only in Outlook on the web has removed the zero-click path and can leave Office on the normal cycle. Conversely, any exploitation evidence for either flaw would make this an Act unit on the evidence lane, not a judgement at all. The frozen list is deliberately not widened in this brief; if the model's next revision admits mail-borne zero-click execution as exposed technology, this stops being a soft call.

Confidence: moderate-high — analytic judgement, not vendor-attested

The severity inversion this month is structural, not incidental: both exploited flaws score 7.8 and are rated Important, while none of the 113 Critical flaws — including the 31 unauthenticated 9.8s in the Windows update — has an exploitation signal, and the record volume reflects discovery rather than attacks.

Basis. Direct comparison of vendor-attested exploitation status (Microsoft's 'Exploitation Detected' and the KEV listings for CVE-2026-81963 and CVE-2026-85880) against Microsoft's own severity ratings and scores. Two independent readers make the discovery point in their own words: Tenable's Satnam Narang, in a statement carried by Krebs on Security and SecurityWeek, says AI-assisted vulnerability discovery is creating larger haystacks but is not finding more needles, and ZDI notes on its own blog that it has not seen a correlating spike in active exploits. Seven of nine 2026 cycles now show the exploited flaw out-scored by an unexploited one.

What would lower this. The corpus is nine months of one vendor. If any of the 20 flaws ZDI classes as wormable is exploited within weeks, the inversion collapses for September specifically — a 9.8 would then be both highest-scored and exploited — though the deployment answer, ship the Windows update first, does not change. A run of Critical-rated flaws entering KEV from this release would also mean the volume was finding needles after all.

Confidence: moderate — analytic judgement, not vendor-attested

SharePoint, Exchange, SQL Server, Skype for Business and Dynamics reach Act structurally — on exposure or core-infrastructure status plus a gate-passing impact — with no exploitation evidence behind any of this month's specific CVEs. That is the set of calls in this brief the evidence does not back.

Basis. SharePoint, Exchange, Skype for Business and an on-premises CRM are frozen-list exposed technologies; SQL Server is frozen-list core infrastructure. Each carries a network-vector code-execution flaw (or, for Exchange, additionally a session-script flaw on the mail edge) that clears the impact gate. The structural verdict is designed to fire before exploitation evidence exists — that is its purpose — but it is a forecast about reachability, not an attested fact about attacks. SharePoint's 2026 exploitation record and Exchange's unauthenticated mail-processing flaw are the two strongest reasons to trust the forecast this month.

What would lower this. A server behind an authenticating reverse proxy, or one reachable only from an internal network, is a different exposure than one on the public internet, and the tree cannot tell them apart. Where the exposed surface is not actually reachable from an untrusted network, each of these units drops to Prioritise and the 5-day clock becomes 14. Most code-execution flaws in these five units require an authenticated account, which narrows who can use them. The exceptions are Exchange's CVE-2026-55007, Skype for Business's CVE-2026-66302, and SQL Server's CVE-2026-47297, whose score says no authentication is needed while its FAQ says the opposite.

The pattern — nine Patch Tuesdays, one direction

974Microsoft CVEs in the September release note973 Microsoft-CNA entries in the CVRF document
113rated Critical by Microsoftnone with an exploitation signal
2exploited zero-daysboth 7.8 · both Important · one per Windows generation
6 · 1 · 2ACT · Prioritise · Track on this month's worklistplus 2 mitigate & monitor — the Mac Office fixes that do not exist yet
2,672Microsoft CVEs across 2026's nine Patch Tuesdays1,130 in all of 2025, per Tenable via The Register

Microsoft-issued CVEs per Patch Tuesday, 2026 — counted from Microsoft's Security Update Guide (Microsoft as CNA, released on the Patch Tuesday date)

Jan
112
Feb
54
Mar
78
Apr
163
May
118
Jun
201
Jul
571
Aug
402
Sep
973

CVEs Microsoft rated Critical per Patch Tuesday, 2026 — same source, same method

Jan
8
Feb
2
Mar
3
Apr
8
May
16
Jun
32
Jul
57
Aug
44
Sep
113

September's worklist by verdict — nine units on the clock; the two Mac Office flaws have no fix yet

Act
6
Prioritise
1
Track
2
Mitigate & monitor
2

The worklist, unit by unit — what each verdict is and what closes it

VerdictUnitThe fix
ActWindows client and server — September update (cumulative on Windows 10/11 and Server 2016–2025; Monthly Rollup on Server 2012/R2)Install the update for your build and reboot — Windows 10 and Server 2012/R2 receive theirs only under ESU — domain controllers first, then hosts exposing RDP, RRAS, MSMQ, NFS or clustering. Then compromise assessment: both zero-days were exploited before this fix existed.
ActSharePoint Server Subscription Edition (KB5002908)Its own servicing path, not the Windows update: install KB5002908 and run the Configuration Wizard. SharePoint 2016 and 2019 are out of support and receive nothing — migrate.
ActExchange Server (KB5121608 · KB5121609 · KB5121610 · KB5121611)Install the September security update for your CU; Exchange 2016 and 2019 patch only under ESU — an arrangement Rapid7 records as itself ending in October 2026.
ActSQL Server and SSMS 22 (GDR or CU per version)Install the matching GDR or CU for each version; update Management Studio for the SQL Copilot fix and run Copilot with a read-only login until then.
ActSkype for Business Server (September CU)Install the cumulative update for your edition; confirm your support arrangement and whether an Edge publication still exists at all.
ActDynamics 365 CE on-premises (Service Update 1.48, KB5123731)Install Service Update 1.48; a deployment at 1.46 already has the CVE-2026-65772 fix, but CVE-2026-77908 needs 1.48.
PrioritiseOffice (Click-to-Run channels and Office 2016 MSI)Push the September build on every channel, Word and the shared Office update first. Mac has no fix — see the mitigate & monitor rows.
TrackCloud services (Azure AI Language, Entra ID, Copilot Studio and others)Nothing to deploy — Microsoft states each is already fully mitigated and publishes for transparency.
Track.NET, Visual Studio and VS Code (KB5126104 · KB5126105 · KB5126106)Normal cycle; every flaw needs a user to open a crafted project, workspace or file.
Mitigate & monitorCVE-2026-78509 — Outlook on Mac, no fix at publicationRead mail in Outlook on the web or turn off the Reading Pane until the Mac update ships as an advisory revision.
Mitigate & monitorCVE-2026-78510 — Word on Mac, no fix at publicationDo not preview or open RTF from untrusted senders until the Mac update ships.

Every bar in the two monthly charts is the same measurement: the Exvora AI team counted the CVEs Microsoft itself issued on each Patch Tuesday from Microsoft's own Security Update Guide data, so the months are comparable in a way the press counts — which differ by methodology every month — are not. September's 973 is 2.4 times August and 1.7 times July, the previous record. Exploited zero-days over the same nine months: 1, 6, 0, 2, 0, 0, 3, 1, 2. The haystack tripled; the needles did not.

Source: https://msrc.microsoft.com/update-guide

What is not urgent — and why

1

Cloud services Microsoft has already fixed — no customer action (Azure AI Language, Azure AD B2C, Entra ID, Copilot Studio, Power Automate, Fabric, Cosmos DB, Discovery Studio, HDInsight)

No deployable action — see disposition
TRACK
fixed by Microsoft · no action

Disposition. Microsoft states for each of these CVEs that the vulnerability 'has already been fully mitigated by Microsoft. There is no action for users of this service to take'; they are published for transparency under Microsoft's cloud-service CVE policy. There is nothing to deploy, so the tree does not run.

Why now. Nothing here needs deploying, and that is the point of recording it. The two CVSS-10.0 entries in this release — Azure AI Language and Azure AD B2C — and the 9.9 in Entra ID are cloud services Microsoft fixed on its own side before publishing; the CVE exists for transparency. A severity-sorted queue would put them at the top and then discover there is nothing to do. The identity ones deserve a second look for a different reason: a Microsoft-side authorization flaw in Entra ID or B2C is a tenant-exposure event even after it is fixed, and the advisory does not say whether it was ever exercised. Ask your Microsoft account team; the patch queue cannot answer it.

Then. No deployment. Check Entra sign-in and audit logs for the window before 8 September if your tenant relies on B2C or on the Entra features the two advisories describe.

2

.NET, Visual Studio and Visual Studio Code September 2026 updates (.NET 8.0 KB5126104 · .NET 9.0 KB5126105 · .NET 10.0 KB5126106; .NET Framework per-OS cumulative updates)

Per-product servicing — see table
TRACK
normal cycle

Why now. Developer tooling is neither exposed technology nor core infrastructure, and every flaw here needs a developer to open something — a workspace, a project, a file — so the tree files the unit on the normal cycle. The 9.6 is worth knowing about anyway: CVE-2026-81376 lets a crafted VS Code workspace bypass Workspace Trust, the one control that stands between cloning an untrusted repository and running its code. That is the entry shape of every developer-targeting supply-chain campaign of the last three years, and a developer workstation is the pivot that holds signing keys, cloud tokens and pipeline credentials. Normal cycle, but a short one.

ProductPackageCarries (named in this brief)
.NET 8.0 (Windows, Linux, macOS) and ASP.NET Core 8.0KB5126104CVE-2026-69522, CVE-2026-69439
.NET 9.0 (Windows, Linux, macOS) and ASP.NET Core 9.0KB5126105CVE-2026-69522, CVE-2026-69439
.NET 10.0 (Windows, Linux, macOS) and ASP.NET Core 10.0KB5126106CVE-2026-69522, CVE-2026-69439
.NET 11.0 and ASP.NET Core 11.0 — Microsoft lists the fix with no KB numbernot establishedresolve via vendor advisory before deployment
.NET Framework 3.5 and 4.8.1 on Windows 11 24H2 / 25H2 and Windows Server 2025 (other builds carry their own September .NET Framework KB)KB5126052CVE-2026-69522
Visual Studio 2022 and Visual Studio Code — fixes ship as product releases with no KB numbernot establishedresolve via vendor advisory before deployment

Then. Update VS Code and Visual Studio through their own channels, and the .NET runtimes per version; the .NET Framework fix ships as a per-OS cumulative update alongside the Windows update. Ten VS Code fixes ship this month in total, eight of them security feature bypasses, and four of those name Workspace Trust specifically.

The analyst's judgment in this unit

Track is the tree's verdict and the Exvora AI team agrees with it. The one reason to move faster is not severity but who the target is. If your developers routinely open repositories they did not write, treat the VS Code fix as a 14-day item.

Method, sources, caveats

Sources

SourceAdmiraltyUsed for
https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-SepA1Vendor CVRF document read 2026-09-09: every CVE, score, vector, severity, exploitability index, acknowledgment, affected product and KB in this brief; per-unit counts; the Jan–Sep trend (Security Update Guide entries for each month counted with the same method: Microsoft as CNA, released on the Patch Tuesday date)
https://msrc.microsoft.com/update-guide/releaseNote/2026-SepA1Vendor release note: '974 Microsoft CVEs', per-product-family breakdown, 25 republished non-Microsoft CVEs
https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilitiesA1KEV read live 2026-09-09 and re-read 2026-09-10 (catalogue 2026.09.10): CVE-2026-81963 and CVE-2026-85880 added 2026-09-08, due 2026-09-22, ransomware use Unknown, unchanged on the second read, and still the only September-release CVEs in the catalogue; adjacent entries CVE-2026-85046, CVE-2026-83548, CVE-2026-83549, CVE-2026-75650, CVE-2026-86218 and the 9 September additions CVE-2026-19490, CVE-2026-20079, CVE-2025-25249 and CVE-2026-87491
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963A1Vendor advisory for the exploited Windows Update Stack flaw
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880A1Vendor advisory for the exploited ALPC flaw: AppContainer sandbox escape to SYSTEM, no user interaction
https://support.microsoft.com/help/5124008A1Windows 11 24H2/25H2 September 2026 update, OS builds 26200.9445 / 26100.9445; end of updates for 24H2 Home and Pro on 13 October 2026
https://support.microsoft.com/help/5122878A1Windows 10 21H2/22H2 (ESU) September 2026 update, OS builds 19045.7725 / 19044.7725
https://support.microsoft.com/help/5122871A1Windows Server 2025 September 2026 update, OS build 26100.33438 (the other Windows KB pages — 5122880, 5124012, 5122882, 5122876, 5123099, 5123065, 5123066 — were confirmed the same way)
https://support.microsoft.com/help/5126256A1Windows 10 ESU Licensing Preparation Package, September 2026
https://support.microsoft.com/help/5095498A1Service Update 1.46 for Dynamics CRM (on-premises) 9.1 — the fixed build the CVRF records for CVE-2026-65772 (KB5123731 is Service Update 1.48, read the same way)
https://learn.microsoft.com/en-us/lifecycle/faq/extended-security-updatesA1ESU end dates: Windows Server 2012/R2 Year 3 ends 13 October 2026; Windows 10 Year 1 ends 13 October 2026
https://learn.microsoft.com/en-us/lifecycle/products/windows-11-home-and-proA1Windows 11 24H2 Home and Pro end date 13 October 2026; Windows 11 Enterprise/Education page gives 23H2 end 10 November 2026; Office LTSC 2021 and Windows Server 2022 mainstream end dates read from their lifecycle pages the same way
https://learn.microsoft.com/en-us/lifecycle/products/sharepoint-server-2019A1SharePoint Server 2019 extended support ended 14 July 2026
https://learn.microsoft.com/en-us/lifecycle/products/exchange-server-2019A1Exchange Server 2019 extended support ended 14 October 2025 (Exchange 2016 and Skype for Business Server 2015/2019 pages read the same way)
https://learn.microsoft.com/en-us/lifecycle/products/skype-for-business-serverA1Skype for Business Server 2019 extended support ended 14 October 2025
https://www.zerodayinitiative.com/blog/2026/9/8/the-september-2026-security-upB2Counts (972 / 114); the 20-item wormable list; DNS 'SigRed's spiritual successor'; Exchange CVE-2026-55007 mail-processing detail; SharePoint CVE-2026-69465; SQL Copilot; ALPC 'hide within documents' reading
https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addressesB2Counts (964 / 104); Update Stack and ALPC zero-day history; DNS and Kerberos 'Exploitation More Likely'; Exchange CVE-2026-69380
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patchB2Counts (966 / 105) and counting methodology; discoverer credits for both zero-days; Windows KB numbers corroborated; 'largest security update ever'
https://www.rapid7.com/blog/post/em-patch-tuesday-september-2026/B2Count (974 + 25 = 999); the Windows Update Stack fix inference; Edge CVE-2026-85046 advisory gap; October 2026 end-of-support list; 'neither Server 2025 nor Windows 11 receives patches' for CVE-2026-85880
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holesB2Count (974 / 113); 'by far its biggest single patch batch ever'; year-to-date context; DNS and Windows Shell call-outs; Tenable's Satnam Narang, in a statement to press also carried by SecurityWeek: 'AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn't finding more needles'
https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/B2Counts (972 / 113); 22 Critical Office patches with 12 via Preview or Reading Pane; Netlogon, DNS-on-DC and DHCP context; ShieldCrash PoC claim
https://isc.sans.edu/diary/September+2026+Microsoft+Patch+Tuesday/33320/B2Counts (973 / 113); prioritisation order; MSMQ TCP 1801 and RRAS mitigations; the conflicting 'not currently in KEV' statement on CVE-2026-85880
https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/B2Counts (973 / 113); 82 of 113 Critical are remote code execution
https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.htmlB2Count (974); Microsoft 'did not disclose any specifics as to who is behind them'; Romain Deperne identified as an Airbus Helicopters researcher; Volexity and Proofpoint credit
https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-inclB2Count (974); per-product breakdown; ALPC history via Tenable
https://www.theregister.com/security/2026/09/09/microsoft-breaks-patch-tuesdayB2Count (974); 'no word yet on who is exploiting this bug'; Tenable's 1,130-CVE 2025 full-year figure; Edge CVE-2026-85046 advisory gap
https://www.automox.com/blog/patch-fix-tuesday-september-2026B2Count (973 / 113 / 58 'Exploitation More Likely'); SQL Copilot 'prompt-injection problem wearing a CVE number'; Office update delivery mechanics; Outlook Reading Pane
https://www.ivanti.com/blog/september-2026-patch-tuesdayB2Count (973 / 119); inter-cycle exploitation since August including the July SharePoint chain exploited within hours of Rapid7's write-up
https://www.action1.com/patch-tuesday/patch-tuesday-september-2026/B2Count (995 / 119, methodology unstated); six 9.8 unauthenticated network RCEs named as first priority