September 10, 2026

September 2026 Patch Tuesday: What Boston Businesses Need to Patch Now

Microsoft’s September 2026 Patch Tuesday fixed close to 970 vulnerabilities, the largest single release of the year, and two of them were already being exploited before the fix shipped. If your business runs Windows machines that haven’t updated since early September, treat this month’s patch as urgent rather than routine.

  • Microsoft patched roughly 966 to 974 vulnerabilities on September 8, 2026, depending on how different research teams count related CVEs, with 113 rated Critical.
  • Two flaws, CVE-2026-85880 and CVE-2026-81963, were actively exploited as zero-days before patches were available.
  • Both let an attacker who already has a foothold on a machine jump to full SYSTEM privileges, which is the step that turns a minor infection into a total takeover.
  • CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 8 and gave federal agencies until September 22 to fix them.
  • This release beat July 2026’s previous record of 621 CVEs by more than half.

What actually got exploited this month?

Two vulnerabilities in this batch matter more than the raw count. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call system, the internal channel Windows processes use to talk to each other. An attacker who has already run code inside a low-privilege sandbox, such as a browser tab or a malicious document viewer, can use this bug to break out of that sandbox and gain SYSTEM-level control without any further clicks from the user.

The second, CVE-2026-81963, sits in the Windows Update Stack itself, the component that’s supposed to keep your machine safe. It’s a link-following flaw that lets a local attacker redirect a file operation to gain elevated privileges. Microsoft credited a researcher at Airbus Helicopters and its own Threat Intelligence Center with finding it after it was already being used against real targets.

Why does a local privilege bug matter if attackers still need a foothold?

Neither of these bugs is the way attackers get in the door. Phishing emails, exposed remote desktop ports, and stolen credentials still do that job. What these two bugs do is remove the last obstacle once an attacker already has a small opening, turning a single compromised browser tab or a low-privilege malware dropper into full control of the machine, including the ability to disable security tools, read every file, and move to other computers on the network. That’s exactly the chain used in most of the ransomware incidents that hit small businesses in the region over the past year.

What should a small business patch first?

Start with anything that touches the internet directly or handles email and web browsing for staff: workstations, laptops, and any server running Exchange, SharePoint, or SQL Server on premises. Those products were all named in this month’s release alongside the core Windows fixes. If you’re still deciding how to modernize an aging server room, our recent look at Windows 10 end of support and extended security updates covers the tradeoffs of patching versus replacing hardware that’s past its prime.

How does this compare to prior months?

We’ve flagged a records-scale release before. August 2026’s Patch Tuesday was itself a heavy month, and July set the previous record at 621 CVEs. September blew past both. The trend line points one direction: attackers are finding and weaponizing flaws faster than most small businesses can keep up with manually, which is the whole argument for automated patch management rather than someone checking Windows Update once a quarter.

Frequently asked questions

What is Patch Tuesday?
Patch Tuesday is the second Tuesday of every month, when Microsoft releases security updates for Windows, Office, and its other products. IT teams use the term to describe their monthly update cycle.

Were the September 2026 zero-days already being used in attacks?
Yes. Microsoft confirmed both CVE-2026-85880 and CVE-2026-81963 were exploited in the wild before the patches shipped on September 8, 2026, and CISA added both to its Known Exploited Vulnerabilities catalog the same day.

Do I need to patch my servers immediately, or can it wait until the weekend?
For any system reachable from the internet, or any machine used for email and web browsing, patch within a few business days. Federal civilian agencies were given until September 22, 2026 to remediate; small businesses face the same attackers and should not wait longer than that.

How do I know if my computers already applied the September update?
On a Windows machine, go to Settings, then Windows Update, and check that the installed update is dated on or after September 8, 2026. A managed IT provider can confirm this across every device on your network at once.

A record-setting patch batch with two zero-days already in use is exactly the kind of month where a missed update on one laptop can turn into a ransomware incident for the whole office. If you’re not certain every device on your network picked up the September fixes, or you want someone else watching for the next zero-day so you don’t have to, Boston Managed IT offers a free 15-minute Microsoft 365 or security review to check where you stand. Call (617) 322-5155 or visit bostonmit.com/contact to set it up.

— Boston Managed IT

About the Author

Your IT Partner Is Just a Click Away. Are you ready to stop thinking about IT?

We handle the infrastructure, helpdesk, and security — Boston businesses rely on us so they never have to think about IT again.