September 2026 Windows Security Updates: What Business Leaders Should Know
Published on September 11, 2026
Microsoft’s September Windows security updates address two vulnerabilities already being exploited. The bigger lesson for business leaders is whether patching is being prioritized, verified, and measured correctly.
Microsoft’s September 2026 Windows security updates deserve more attention than a routine Patch Tuesday.
The September 8 release addresses two Windows vulnerabilities that were already being exploited in real attacks. At the same time, researchers identified a significant group of additional Windows vulnerabilities capable of remote code execution, including some that may require neither authentication nor user interaction.
For business leaders, the important question is not how many vulnerabilities Microsoft fixed this month. It is whether the systems that matter to your business are actually receiving the right updates quickly, successfully, and with enough validation to prove the risk has been reduced.
What changed in the September Windows updates?
Microsoft released its September security updates on September 8, 2026. The broader Microsoft release addresses hundreds of vulnerabilities across Windows, Office, Exchange, SQL Server, SharePoint, Azure, and other products.
Windows represents a substantial portion of the release, but two vulnerabilities deserve immediate attention because Microsoft and the U.S. Cybersecurity and Infrastructure Security Agency, or CISA, have confirmed that they have been exploited.
- CVE-2026-81963 affects the Windows Update Stack and can allow an attacker who already has some level of local access to elevate privileges to SYSTEM.
- CVE-2026-85880 affects Windows Advanced Local Procedure Call, or ALPC, and can also allow a local attacker to elevate privileges to SYSTEM.
SYSTEM is one of the highest privilege levels available in Windows. These vulnerabilities are therefore particularly useful to an attacker who has already obtained an initial foothold through another vulnerability, malicious attachment, compromised account, or other technique.
That distinction matters. Neither vulnerability should automatically be interpreted as an attacker being able to compromise every Windows computer directly from the internet. Their value to an attacker is that they can help turn limited access into much greater control of an affected system.
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 8 based on evidence of active exploitation. That moves them from theoretical security concerns to vulnerabilities organizations should treat as remediation priorities.
The headline vulnerability count is not the most useful metric
This month’s Microsoft release is unusually large. Different security organizations have reported slightly different totals because they use different methods for counting newly released, previously disclosed, republished, and third-party vulnerabilities.
For a business, that accounting distinction is far less important than understanding which vulnerabilities affect systems you actually operate.
Security researchers reviewing the September release identified roughly 20 vulnerabilities with characteristics that could make them particularly serious: remote code execution without authentication or user interaction. Affected technologies include Windows components associated with DNS, DHCP, Active Directory Domain Services, Remote Desktop Services, Netlogon, SMB, failover clustering, and other infrastructure.
These vulnerabilities are not all known to be under active attack. That distinction is important. They do, however, reinforce why server patching and workstation patching cannot be treated as identical exercises.
A vulnerability affecting a lightly used workstation presents a different business risk from one affecting a domain controller, Remote Desktop server, DNS server, or other system that provides foundational services to the organization.
What businesses should be asking their IT teams
A mature patch-management conversation should go beyond asking whether “Windows updates are automatic.”
Leadership should be able to get clear answers to questions such as:
- Have the September Windows security updates been tested and approved for deployment?
- Are the two actively exploited Windows vulnerabilities patched across affected systems?
- Which computers or servers failed to install the update?
- Which devices are waiting for a restart before the update is actually complete?
- Are domain controllers, Remote Desktop systems, DNS, DHCP, file servers, and other critical infrastructure being prioritized according to their exposure?
- Are any Windows computers running versions that are no longer normally supported?
- If Windows 10 remains in the environment, are those systems properly enrolled in Extended Security Updates?
- Can the IT team or provider produce evidence of the installed build or update rather than simply reporting that a patch job ran?
That last question is particularly important.
Patch deployment and patch compliance are not the same thing.
A management platform can issue an installation command successfully while an endpoint later fails installation, remains offline, requires a reboot, lacks disk space, has a damaged update component, or otherwise remains vulnerable.
Good patch management measures the final state of the device.
Windows 10 deserves special attention
Windows 10 reached the end of normal support on October 14, 2025. Organizations that still require Windows 10 can use Microsoft’s Extended Security Updates program on eligible systems, but those devices must be properly licensed and enrolled to continue receiving applicable critical and important security updates.
Microsoft released an updated Windows 10 ESU Licensing Preparation Package, KB5126256, in September 2026. Installing that preparation package alone does not enroll a computer in ESU. Organizations should therefore verify actual ESU enrollment rather than assuming that seeing the package installed means the system is protected.
This creates an important inventory question for organizations still operating Windows 10: Are those computers intentionally remaining on Windows 10 under ESU, or have they simply been left behind?
Those are two very different risk positions.
September's updates also contain useful reliability fixes
The September Windows 11 updates are not solely security patches.
For Windows 11 versions 24H2 and 25H2, Microsoft’s KB5124008 also resolves several issues associated with earlier updates, including problems that could cause Microsoft Teams and the new Outlook to fail or close unexpectedly on certain ARM-based computers. Microsoft also reports fixes for some desktop background and mouse-personalization problems introduced by previous updates.
Windows 11 version 23H2 receives KB5122880, while other supported Windows branches have their corresponding September cumulative updates.
This is another reason organizations should avoid treating patching as a binary choice between “install immediately everywhere” and “wait several weeks.” A better approach is controlled deployment: test on representative systems, monitor the first deployment group, then expand rapidly when no blocking issue appears.
What a competent patching process should look like
For most organizations, the September release should trigger a few straightforward actions.
- Confirm asset inventory. Know which Windows versions are actually running across workstations and servers.
- Identify exposure. Prioritize systems affected by actively exploited vulnerabilities and systems providing critical network or identity services.
- Deploy through controlled groups. Use a small representative pilot population before broad deployment where business continuity requires testing.
- Accelerate high-risk remediation. Actively exploited vulnerabilities should not sit in a routine multiweek patch queue simply because the normal maintenance schedule says so.
- Verify the result. Measure installed updates, expected operating-system builds, reboot status, failures, and remaining vulnerable devices.
- Investigate exceptions. Every unpatched system should eventually have a reason, an owner, and a remediation plan.
The objective is not reckless speed. The objective is reducing the time between a meaningful security risk becoming known and the organization being able to demonstrate that the affected exposure has been addressed.
A patch-compliance percentage can hide the machines that matter most
An organization might report 98 percent patch compliance and still have significant exposure if the remaining 2 percent includes a domain controller, externally accessible server, executive laptop, or system containing sensitive information.
That is why patch management should increasingly be viewed as a risk-management process rather than a software-maintenance task.
Executives do not need to study hundreds of CVEs each month. They should expect their IT team or technology provider to separate the noise from the issues that materially affect the organization, deploy updates safely, identify exceptions, and provide evidence that remediation succeeded.
The September 2026 Windows updates provide a useful test of that process. With vulnerabilities already being exploited and several potentially serious remote-code-execution issues included in the release, this is a good month to ask not simply, “Are we patching?” but “Can we prove the systems that matter are patched?”
If that answer is unclear, review the current Windows patch status with your IT team or technology provider and ask specifically for outstanding security updates, failed installations, pending restarts, unsupported operating systems, Windows 10 ESU status, and exceptions affecting critical infrastructure.
