September 2026 Patch Tuesday: What Boston Businesses Need to Patch Now

IT technician applying security patches to a business server in an office setting

Microsoft’s September 2026 Patch Tuesday fixed close to 970 vulnerabilities, the largest single release of the year, and two of them were already being exploited before the fix shipped. If your business runs Windows machines that haven’t updated since early September, treat this month’s patch as urgent rather than routine.

  • Microsoft patched roughly 966 to 974 vulnerabilities on September 8, 2026, depending on how different research teams count related CVEs, with 113 rated Critical.
  • Two flaws, CVE-2026-85880 and CVE-2026-81963, were actively exploited as zero-days before patches were available.
  • Both let an attacker who already has a foothold on a machine jump to full SYSTEM privileges, which is the step that turns a minor infection into a total takeover.
  • CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 8 and gave federal agencies until September 22 to fix them.
  • This release beat July 2026’s previous record of 621 CVEs by more than half.

What actually got exploited this month?

Two vulnerabilities in this batch matter more than the raw count. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call system, the internal channel Windows processes use to talk to each other. An attacker who has already run code inside a low-privilege sandbox, such as a browser tab or a malicious document viewer, can use this bug to break out of that sandbox and gain SYSTEM-level control without any further clicks from the user.

The second, CVE-2026-81963, sits in the Windows Update Stack itself, the component that’s supposed to keep your machine safe. It’s a link-following flaw that lets a local attacker redirect a file operation to gain elevated privileges. Microsoft credited a researcher at Airbus Helicopters and its own Threat Intelligence Center with finding it after it was already being used against real targets.

Why does a local privilege bug matter if attackers still need a foothold?

Neither of these bugs is the way attackers get in the door. Phishing emails, exposed remote desktop ports, and stolen credentials still do that job. What these two bugs do is remove the last obstacle once an attacker already has a small opening, turning a single compromised browser tab or a low-privilege malware dropper into full control of the machine, including the ability to disable security tools, read every file, and move to other computers on the network. That’s exactly the chain used in most of the ransomware incidents that hit small businesses in the region over the past year.

What should a small business patch first?

Start with anything that touches the internet directly or handles email and web browsing for staff: workstations, laptops, and any server running Exchange, SharePoint, or SQL Server on premises. Those products were all named in this month’s release alongside the core Windows fixes. If you’re still deciding how to modernize an aging server room, our recent look at Windows 10 end of support and extended security updates covers the tradeoffs of patching versus replacing hardware that’s past its prime.

How does this compare to prior months?

We’ve flagged a records-scale release before. August 2026’s Patch Tuesday was itself a heavy month, and July set the previous record at 621 CVEs. September blew past both. The trend line points one direction: attackers are finding and weaponizing flaws faster than most small businesses can keep up with manually, which is the whole argument for automated patch management rather than someone checking Windows Update once a quarter.

Frequently asked questions

What is Patch Tuesday?
Patch Tuesday is the second Tuesday of every month, when Microsoft releases security updates for Windows, Office, and its other products. IT teams use the term to describe their monthly update cycle.

Were the September 2026 zero-days already being used in attacks?
Yes. Microsoft confirmed both CVE-2026-85880 and CVE-2026-81963 were exploited in the wild before the patches shipped on September 8, 2026, and CISA added both to its Known Exploited Vulnerabilities catalog the same day.

Do I need to patch my servers immediately, or can it wait until the weekend?
For any system reachable from the internet, or any machine used for email and web browsing, patch within a few business days. Federal civilian agencies were given until September 22, 2026 to remediate; small businesses face the same attackers and should not wait longer than that.

How do I know if my computers already applied the September update?
On a Windows machine, go to Settings, then Windows Update, and check that the installed update is dated on or after September 8, 2026. A managed IT provider can confirm this across every device on your network at once.

A record-setting patch batch with two zero-days already in use is exactly the kind of month where a missed update on one laptop can turn into a ransomware incident for the whole office. If you’re not certain every device on your network picked up the September fixes, or you want someone else watching for the next zero-day so you don’t have to, Boston Managed IT offers a free 15-minute Microsoft 365 or security review to check where you stand. Call (617) 322-5155 or visit bostonmit.com/contact to set it up.

— Boston Managed IT

Picture of Nicholas Salem

Nicholas Salem

As the CEO of BMIT, a leading managed IT services company, Nick Salem is responsible for providing strategic leadership and direction to the organization. With over 15 years of experience in the IT industry, Nick has a strong track record of driving business growth and improving operational efficiency through the use of technology. https://nicholassalem.com

Free assessment

Not sure where you stand?

Thirty minutes with a senior engineer on your security, backups, and Microsoft 365. Findings in writing.

Keep reading

IT technician checking server hardware in a data center, representing Windows Server 2022 reaching end of mainstream support

Windows Server 2022 End of Mainstream Support: What It Means for Boston Businesses

Windows Server 2022 reaches end of mainstream support on October 13,...

Business owner reviewing a data breach notification checklist on a laptop in an office

Massachusetts Data Breach Notification Law: What Boston Businesses Must Do When It Happens

Massachusetts Chapter 93H, the state’s data breach notification law, requires any...

IT technician checking a network security appliance in a server rack

SonicWall SMA1000 Vulnerability: What Boston Businesses Need to Know

SonicWall confirmed on September 1, 2026 that two vulnerabilities in its...

Free technical assessment

Thirty minutes with a senior engineer.

  • Security posture, backups, and Microsoft 365, reviewed live
  • The three fixes that matter most, ranked, with rough effort
  • Findings in writing, and an honest answer on whether you need us

Book your assessment

Next, you pick a time on our calendar. No sales deck.

Prefer the phone? (617) 322-5155