Today’s Patch Tuesday Alert addresses Microsoft’s September 2026 Security Updates. The FIRE team is actively working on coverage for these vulnerabilities and expect to ship that coverage as soon as it is completed.
In-the-Wild & Disclosed CVEs
According to Microsoft, an authenticated attacker with the ability to execute code in a low-privilege AppContainer could exploit a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) to elevate to SYSTEM level privileges. AppContainers provide an isolated execution environment (sandbox). This vulnerability allows the attacker to escape that sandbox. Microsoft has reported this vulnerability as Exploitation Detected.
An authenticated attacker could take advantage of a flaw in Windows Update Stack, where a link to a file (shortcut) may be accessed inappropriately, leading to privilege elevation to SYSTEM. Microsoft has reported this vulnerability as Exploitation Detected.
CVE Breakdown by Tag
While historical Microsoft Security Bulletin groupings are gone, Microsoft vulnerabilities are tagged with an identifier. This list provides a breakdown of the CVEs on a per tag basis. Vulnerabilities are also color coded to aid with identifying key issues.
- Traditional Software
- Mobile Software
- Cloud or Cloud Adjacent
- Vulnerabilities that are being exploited or that have been disclosed will be highlighted
| Tag | CVE Count | CVEs |
| SQL Server | 61 | CVE-2026-47297, CVE-2026-65669, CVE-2026-66814, CVE-2026-66816, CVE-2026-66818, CVE-2026-66819, CVE-2026-66820, CVE-2026-67368, CVE-2026-67369, CVE-2026-67370, CVE-2026-67373, CVE-2026-67376, CVE-2026-67378, CVE-2026-67379, CVE-2026-67380, CVE-2026-67381, CVE-2026-67383, CVE-2026-67384, CVE-2026-67385, CVE-2026-67386, CVE-2026-67388, CVE-2026-67389, CVE-2026-67390, CVE-2026-67393, CVE-2026-67624, CVE-2026-67629, CVE-2026-67630, CVE-2026-67631, CVE-2026-67633, CVE-2026-67636, CVE-2026-67638, CVE-2026-67639, CVE-2026-67641, CVE-2026-67642, CVE-2026-67643, CVE-2026-67645, CVE-2026-67648, CVE-2026-68775, CVE-2026-68776, CVE-2026-68777, CVE-2026-68778, CVE-2026-68779, CVE-2026-68780, CVE-2026-68781, CVE-2026-68784, CVE-2026-68785, CVE-2026-68786, CVE-2026-68787, CVE-2026-69562, CVE-2026-73028, CVE-2026-73029, CVE-2026-77480, CVE-2026-77481, CVE-2026-77482, CVE-2026-77483, CVE-2026-77484, CVE-2026-77485, CVE-2026-77486, CVE-2026-77487, CVE-2026-77488, CVE-2026-78456 |
| Windows Ancillary Function Driver for WinSock | 2 | CVE-2026-50349, CVE-2026-70342 |
| Microsoft Exchange Server | 9 | CVE-2026-55007, CVE-2026-69355, CVE-2026-69356, CVE-2026-69361, CVE-2026-69375, CVE-2026-69378, CVE-2026-69380, CVE-2026-69382, CVE-2026-69641 |
| Windows VHD miniport driver | 1 | CVE-2026-56172 |
| Windows Server | 1 | CVE-2026-56177 |
| Microsoft Trace Data Helper | 1 | CVE-2026-56198 |
| Windows RDP Client | 1 | CVE-2026-57098 |
| ASP.NET Core | 2 | CVE-2026-57099, CVE-2026-69304 |
| Microsoft Windows Codecs Library | 4 | CVE-2026-58599, CVE-2026-58600, CVE-2026-81352, CVE-2026-81353 |
| XBox Gaming Services | 1 | CVE-2026-58611 |
| .NET | 3 | CVE-2026-58649, CVE-2026-69805, CVE-2026-69806 |
| Windows Installer | 5 | CVE-2026-62694, CVE-2026-69441, CVE-2026-71339, CVE-2026-72929, CVE-2026-77894 |
| Windows Push Notifications | 3 | CVE-2026-62697, CVE-2026-69280, CVE-2026-69300 |
| Microsoft Windows Media Foundation | 6 | CVE-2026-62706, CVE-2026-62744, CVE-2026-69386, CVE-2026-69408, CVE-2026-69511, CVE-2026-69601 |
| Windows Netlogon | 2 | CVE-2026-62759, CVE-2026-72982 |
| Active Directory Domain Services | 6 | CVE-2026-62762, CVE-2026-62813, CVE-2026-69359, CVE-2026-69524, CVE-2026-69546, CVE-2026-69809 |
| Windows PowerShell | 2 | CVE-2026-62801, CVE-2026-69807 |
| Microsoft Office Word | 38 | CVE-2026-62804, CVE-2026-68843, CVE-2026-69360, CVE-2026-69556, CVE-2026-69671, CVE-2026-69686, CVE-2026-69719, CVE-2026-69722, CVE-2026-69734, CVE-2026-69759, CVE-2026-69764, CVE-2026-72972, CVE-2026-72973, CVE-2026-72976, CVE-2026-77504, CVE-2026-77901, CVE-2026-77911, CVE-2026-78502, CVE-2026-78503, CVE-2026-78504, CVE-2026-78506, CVE-2026-78507, CVE-2026-78510, CVE-2026-78511, CVE-2026-78512, CVE-2026-78514, CVE-2026-78517, CVE-2026-78521, CVE-2026-78522, CVE-2026-78526, CVE-2026-80079, CVE-2026-80080, CVE-2026-80085, CVE-2026-80088, CVE-2026-80090, CVE-2026-81952, CVE-2026-83949, CVE-2026-83951 |
| Active Directory Certificate Services (AD CS) | 4 | CVE-2026-62810, CVE-2026-69395, CVE-2026-69624, CVE-2026-69821 |
| Azure Arc | 1 | CVE-2026-62895 |
| Microsoft Discovery Studio | 1 | CVE-2026-62906 |
| Microsoft Entra ID | 1 | CVE-2026-62916 |
| Skype for Business | 10 | CVE-2026-63523, CVE-2026-66302, CVE-2026-66303, CVE-2026-66304, CVE-2026-66305, CVE-2026-66306, CVE-2026-66307, CVE-2026-66308, CVE-2026-69642, CVE-2026-69646 |
| Microsoft Office | 15 | CVE-2026-64918, CVE-2026-69285, CVE-2026-69442, CVE-2026-69626, CVE-2026-69632, CVE-2026-69739, CVE-2026-77898, CVE-2026-78505, CVE-2026-78524, CVE-2026-80076, CVE-2026-80078, CVE-2026-80082, CVE-2026-80087, CVE-2026-80089, CVE-2026-80091 |
| Microsoft Dynamics 365 | 2 | CVE-2026-65772, CVE-2026-77908 |
| Microsoft Teams for Android | 2 | CVE-2026-65812, CVE-2026-69559 |
| Power Automate | 2 | CVE-2026-65818, CVE-2026-77897 |
| Windows Connected User Experiences and Telemetry | 5 | CVE-2026-68824, CVE-2026-68847, CVE-2026-69267, CVE-2026-69470, CVE-2026-69625 |
| Windows Bind Filter Driver | 1 | CVE-2026-68825 |
| Windows GDI+ | 2 | CVE-2026-68827, CVE-2026-69288 |
| Remote Desktop Client | 9 | CVE-2026-68828, CVE-2026-69317, CVE-2026-69358, CVE-2026-69485, CVE-2026-77896, CVE-2026-78463, CVE-2026-80074, CVE-2026-80077, CVE-2026-83998 |
| Windows Universal Plug and Play (UPnP) Device Host | 2 | CVE-2026-68830, CVE-2026-69351 |
| Windows Defender Firewall Service | 2 | CVE-2026-68831, CVE-2026-70568 |
| Windows NTFS | 29 | CVE-2026-68832, CVE-2026-68833, CVE-2026-68834, CVE-2026-68838, CVE-2026-68841, CVE-2026-68851, CVE-2026-68875, CVE-2026-69265, CVE-2026-69312, CVE-2026-69332, CVE-2026-69340, CVE-2026-69379, CVE-2026-69425, CVE-2026-69461, CVE-2026-69463, CVE-2026-69479, CVE-2026-69504, CVE-2026-69505, CVE-2026-69532, CVE-2026-69566, CVE-2026-69567, CVE-2026-69591, CVE-2026-69638, CVE-2026-69709, CVE-2026-69875, CVE-2026-71329, CVE-2026-72935, CVE-2026-77503, CVE-2026-83995 |
| Windows Print Spooler Components | 12 | CVE-2026-68835, CVE-2026-68848, CVE-2026-69309, CVE-2026-69344, CVE-2026-69346, CVE-2026-69364, CVE-2026-69552, CVE-2026-69569, CVE-2026-69838, CVE-2026-69921, CVE-2026-70564, CVE-2026-85877 |
| Windows File History Service | 3 | CVE-2026-68837, CVE-2026-71340, CVE-2026-72947 |
| Windows USB Mass Storage Class Driver | 3 | CVE-2026-68839, CVE-2026-69490, CVE-2026-69527 |
| Windows USB Driver | 5 | CVE-2026-68840, CVE-2026-69295, CVE-2026-69457, CVE-2026-69503, CVE-2026-72953 |
| Windows MIDI Service Module | 6 | CVE-2026-68842, CVE-2026-69339, CVE-2026-69440, CVE-2026-69508, CVE-2026-69720, CVE-2026-78464 |
| Windows Storage Spaces Controller | 5 | CVE-2026-68844, CVE-2026-68877, CVE-2026-69290, CVE-2026-69568, CVE-2026-69575 |
| Windows Program Compatibility Assistant Service | 6 | CVE-2026-68845, CVE-2026-68873, CVE-2026-68874, CVE-2026-68876, CVE-2026-69534, CVE-2026-69563 |
| Windows Kernel | 11 | CVE-2026-68846, CVE-2026-68884, CVE-2026-69366, CVE-2026-69406, CVE-2026-69466, CVE-2026-69473, CVE-2026-69578, CVE-2026-69669, CVE-2026-69723, CVE-2026-83942, CVE-2026-85360 |
| Windows Bluetooth Port Driver | 2 | CVE-2026-68849, CVE-2026-69817 |
| Microsoft Account | 2 | CVE-2026-68850, CVE-2026-68852 |
| Windows Fast FAT Driver | 2 | CVE-2026-68878, CVE-2026-69347 |
| Windows Win32K | 23 | CVE-2026-68880, CVE-2026-69274, CVE-2026-69301, CVE-2026-69333, CVE-2026-69335, CVE-2026-69348, CVE-2026-69410, CVE-2026-69498, CVE-2026-69609, CVE-2026-69610, CVE-2026-69630, CVE-2026-69652, CVE-2026-69689, CVE-2026-69706, CVE-2026-69762, CVE-2026-69779, CVE-2026-69792, CVE-2026-69808, CVE-2026-69818, CVE-2026-69832, CVE-2026-69844, CVE-2026-69853, CVE-2026-70283 |
| Microsoft Standard XPS | 18 | CVE-2026-68881, CVE-2026-68885, CVE-2026-68888, CVE-2026-68889, CVE-2026-68890, CVE-2026-68891, CVE-2026-68892, CVE-2026-68897, CVE-2026-69269, CVE-2026-69271, CVE-2026-69272, CVE-2026-69308, CVE-2026-69313, CVE-2026-69336, CVE-2026-69345, CVE-2026-69367, CVE-2026-69376, CVE-2026-69824 |
| Windows Network Connection Broker | 2 | CVE-2026-68886, CVE-2026-72967 |
| Windows Message Queuing Queue Manager | 2 | CVE-2026-68887, CVE-2026-72932 |
| Windows Remote Desktop Licensing Service | 2 | CVE-2026-68893, CVE-2026-69627 |
| Windows Error Reporting | 12 | CVE-2026-68894, CVE-2026-69362, CVE-2026-69433, CVE-2026-69436, CVE-2026-69450, CVE-2026-69462, CVE-2026-69482, CVE-2026-69513, CVE-2026-69612, CVE-2026-69684, CVE-2026-69896, CVE-2026-83996 |
| Internet Storage Name Service | 1 | CVE-2026-68895 |
| Microsoft Windows Search Component | 11 | CVE-2026-68896, CVE-2026-69305, CVE-2026-69322, CVE-2026-69453, CVE-2026-69507, CVE-2026-69554, CVE-2026-69585, CVE-2026-69600, CVE-2026-69608, CVE-2026-69911, CVE-2026-70145 |
| Windows iSCSI | 4 | CVE-2026-68898, CVE-2026-69598, CVE-2026-69628, CVE-2026-73025 |
| Windows DHCP Server | 36 | CVE-2026-69266, CVE-2026-69297, CVE-2026-69342, CVE-2026-69405, CVE-2026-69412, CVE-2026-69415, CVE-2026-69416, CVE-2026-69497, CVE-2026-69510, CVE-2026-69547, CVE-2026-69620, CVE-2026-69637, CVE-2026-69679, CVE-2026-69803, CVE-2026-69845, CVE-2026-69847, CVE-2026-69876, CVE-2026-69878, CVE-2026-69929, CVE-2026-69930, CVE-2026-70065, CVE-2026-70124, CVE-2026-72979, CVE-2026-77494, CVE-2026-77498, CVE-2026-77499, CVE-2026-77501, CVE-2026-77502, CVE-2026-77886, CVE-2026-77887, CVE-2026-77888, CVE-2026-77889, CVE-2026-77890, CVE-2026-77891, CVE-2026-77893, CVE-2026-77895 |
| Microsoft Office SharePoint | 16 | CVE-2026-69268, CVE-2026-69273, CVE-2026-69282, CVE-2026-69402, CVE-2026-69409, CVE-2026-69417, CVE-2026-69464, CVE-2026-69465, CVE-2026-69615, CVE-2026-69636, CVE-2026-69683, CVE-2026-69690, CVE-2026-69716, CVE-2026-69724, CVE-2026-69804, CVE-2026-69904 |
| Windows USB Audio Class driver (usbaudio.sys) | 9 | CVE-2026-69270, CVE-2026-69286, CVE-2026-69307, CVE-2026-69413, CVE-2026-69469, CVE-2026-69571, CVE-2026-69687, CVE-2026-69707, CVE-2026-69859 |
| Kernel Streaming WOW Thunk Service Driver | 2 | CVE-2026-69275, CVE-2026-69900 |
| Microsoft UxTheme Library (uxtheme.dll) | 1 | CVE-2026-69276 |
| Microsoft Local Security Authority Server (lsasrv) | 3 | CVE-2026-69277, CVE-2026-69365, CVE-2026-69594 |
| Windows Cloud Files Mini Filter Driver | 3 | CVE-2026-69279, CVE-2026-80093, CVE-2026-83991 |
| Windows License Manager | 2 | CVE-2026-69281, CVE-2026-69315 |
| Windows CD-ROM Driver | 4 | CVE-2026-69283, CVE-2026-69561, CVE-2026-78454, CVE-2026-78508 |
| Windows DCOM Server | 1 | CVE-2026-69284 |
| Windows Remote Desktop Services | 9 | CVE-2026-69287, CVE-2026-69475, CVE-2026-69514, CVE-2026-69525, CVE-2026-69536, CVE-2026-69539, CVE-2026-69599, CVE-2026-69616, CVE-2026-80096 |
| Windows Setup Files Cleanup | 1 | CVE-2026-69289 |
| Windows Volume Manager Extension Driver | 5 | CVE-2026-69291, CVE-2026-69334, CVE-2026-69468, CVE-2026-69582, CVE-2026-77904 |
| Remote Desktop Gateway Service | 2 | CVE-2026-69292, CVE-2026-69338 |
| Windows Biometric Service | 64 | CVE-2026-69293, CVE-2026-69298, CVE-2026-69323, CVE-2026-69352, CVE-2026-69476, CVE-2026-69489, CVE-2026-69580, CVE-2026-69583, CVE-2026-69589, CVE-2026-69593, CVE-2026-69727, CVE-2026-69738, CVE-2026-69773, CVE-2026-69787, CVE-2026-69826, CVE-2026-70572, CVE-2026-70573, CVE-2026-70581, CVE-2026-72941, CVE-2026-72988, CVE-2026-72990, CVE-2026-72991, CVE-2026-72992, CVE-2026-72993, CVE-2026-72994, CVE-2026-72995, CVE-2026-72996, CVE-2026-72997, CVE-2026-73000, CVE-2026-73001, CVE-2026-73002, CVE-2026-73007, CVE-2026-73008, CVE-2026-73011, CVE-2026-73015, CVE-2026-73020, CVE-2026-73021, CVE-2026-73026, CVE-2026-77489, CVE-2026-78447, CVE-2026-78448, CVE-2026-83954, CVE-2026-83955, CVE-2026-83967, CVE-2026-83968, CVE-2026-83969, CVE-2026-83970, CVE-2026-83971, CVE-2026-83972, CVE-2026-83973, CVE-2026-83974, CVE-2026-83975, CVE-2026-83976, CVE-2026-83977, CVE-2026-83978, CVE-2026-83979, CVE-2026-83980, CVE-2026-83981, CVE-2026-83982, CVE-2026-83983, CVE-2026-83985, CVE-2026-83986, CVE-2026-83987, CVE-2026-83988 |
| Microsoft COM for Windows | 2 | CVE-2026-69294, CVE-2026-69299 |
| Windows Device Association Service | 11 | CVE-2026-69296, CVE-2026-69478, CVE-2026-69488, CVE-2026-69574, CVE-2026-69581, CVE-2026-69711, CVE-2026-69714, CVE-2026-69791, CVE-2026-69866, CVE-2026-77500, CVE-2026-83940 |
| Push Message Routing Service | 1 | CVE-2026-69303 |
| Windows DNS | 14 | CVE-2026-69310, CVE-2026-69369, CVE-2026-69551, CVE-2026-69631, CVE-2026-69672, CVE-2026-69680, CVE-2026-69730, CVE-2026-69813, CVE-2026-69858, CVE-2026-70091, CVE-2026-72928, CVE-2026-72948, CVE-2026-72987, CVE-2026-78523 |
| Windows Audio Service | 8 | CVE-2026-69311, CVE-2026-69394, CVE-2026-69447, CVE-2026-69540, CVE-2026-69604, CVE-2026-69692, CVE-2026-69801, CVE-2026-70562 |
| Windows Device Association Broker service | 2 | CVE-2026-69314, CVE-2026-69693 |
| Windows Overlay Filter | 7 | CVE-2026-69316, CVE-2026-69343, CVE-2026-69350, CVE-2026-69368, CVE-2026-69371, CVE-2026-69373, CVE-2026-69474 |
| Windows Imaging Component | 8 | CVE-2026-69318, CVE-2026-69499, CVE-2026-69860, CVE-2026-70296, CVE-2026-73013, CVE-2026-73023, CVE-2026-77495, CVE-2026-83992 |
| Windows USB Video Driver | 5 | CVE-2026-69319, CVE-2026-69422, CVE-2026-69423, CVE-2026-69584, CVE-2026-72962 |
| Windows Power Dependency Coordinator | 2 | CVE-2026-69321, CVE-2026-69459 |
| Windows Performance Monitor | 1 | CVE-2026-69324 |
| Microsoft JScript | 2 | CVE-2026-69325, CVE-2026-69438 |
| Windows Storage | 2 | CVE-2026-69328, CVE-2026-78516 |
| BranchCache | 1 | CVE-2026-69329 |
| Windows Remote Access Connection Manager | 7 | CVE-2026-69331, CVE-2026-69455, CVE-2026-71333, CVE-2026-71342, CVE-2026-71343, CVE-2026-71352, CVE-2026-72966 |
| Windows Registry | 1 | CVE-2026-69337 |
| Windows Image Acquisition | 4 | CVE-2026-69341, CVE-2026-69483, CVE-2026-69500, CVE-2026-69613 |
| Windows Management Instrumentation | 4 | CVE-2026-69349, CVE-2026-69451, CVE-2026-70582, CVE-2026-77905 |
| Windows Text Shaping | 2 | CVE-2026-69353, CVE-2026-69786 |
| Windows NDIS | 2 | CVE-2026-69357, CVE-2026-69396 |
| Windows Network File System | 2 | CVE-2026-69372, CVE-2026-69772 |
| Windows SMB Server | 2 | CVE-2026-69374, CVE-2026-69403 |
| Windows Modern Device Management (MDM) | 6 | CVE-2026-69377, CVE-2026-69460, CVE-2026-69674, CVE-2026-70577, CVE-2026-73003, CVE-2026-73022 |
| Windows Storage Port Driver | 1 | CVE-2026-69381 |
| Windows Shell | 6 | CVE-2026-69383, CVE-2026-69392, CVE-2026-69528, CVE-2026-69606, CVE-2026-69829, CVE-2026-70563 |
| Virtual Hard Disk (VHD) Miniport Driver | 7 | CVE-2026-69384, CVE-2026-69541, CVE-2026-69549, CVE-2026-69611, CVE-2026-69681, CVE-2026-70574, CVE-2026-81355 |
| Windows TCP/IP | 6 | CVE-2026-69385, CVE-2026-69404, CVE-2026-69588, CVE-2026-69757, CVE-2026-69761, CVE-2026-69793 |
| Windows Bluetooth Service | 4 | CVE-2026-69388, CVE-2026-69398, CVE-2026-69448, CVE-2026-69889 |
| Windows Storage Management Provider | 2 | CVE-2026-69389, CVE-2026-71337 |
| Windows Spaceport.sys | 17 | CVE-2026-69390, CVE-2026-69393, CVE-2026-69512, CVE-2026-69535, CVE-2026-69538, CVE-2026-69643, CVE-2026-69691, CVE-2026-69741, CVE-2026-69770, CVE-2026-69895, CVE-2026-70569, CVE-2026-71345, CVE-2026-71348, CVE-2026-71349, CVE-2026-71350, CVE-2026-72942, CVE-2026-72952 |
| Windows Broker Infrastructure Service | 1 | CVE-2026-69391 |
| OpenSSH for Windows | 1 | CVE-2026-69397 |
| Audio Video Control Transport Protocol | 1 | CVE-2026-69401 |
| Volume Manager Driver | 3 | CVE-2026-69407, CVE-2026-69418, CVE-2026-69432 |
| Windows VOLSNAP.SYS | 3 | CVE-2026-69420, CVE-2026-69426, CVE-2026-69427 |
| Windows Kernel Mode Driver | 1 | CVE-2026-69421 |
| Windows Distributed File System (DFS) | 2 | CVE-2026-69424, CVE-2026-78446 |
| Windows LDAP - Lightweight Directory Access Protocol | 1 | CVE-2026-69428 |
| Windows IKE Extension | 3 | CVE-2026-69429, CVE-2026-69587, CVE-2026-69881 |
| Windows Embedded Mode Service | 1 | CVE-2026-69430 |
| Telnet Client | 1 | CVE-2026-69431 |
| Windows URL Moniker | 2 | CVE-2026-69434, CVE-2026-73019 |
| .NET and Visual Studio | 1 | CVE-2026-69439 |
| Windows Device Health Attestation (DHA) | 1 | CVE-2026-69443 |
| Microsoft Windows Speech | 3 | CVE-2026-69444, CVE-2026-69456, CVE-2026-69531 |
| Windows Compressed Folder | 3 | CVE-2026-69445, CVE-2026-69496, CVE-2026-70019 |
| Windows BitLocker | 2 | CVE-2026-69449, CVE-2026-69458 |
| Microsoft Graphics Component | 8 | CVE-2026-69467, CVE-2026-73006, CVE-2026-73016, CVE-2026-77493, CVE-2026-78439, CVE-2026-81955, CVE-2026-83990, CVE-2026-84000 |
| Windows Devices Human Interface | 1 | CVE-2026-69472 |
| Microsoft Office Access | 4 | CVE-2026-69477, CVE-2026-69529, CVE-2026-69614, CVE-2026-69778 |
| Windows Partition Management Driver | 3 | CVE-2026-69480, CVE-2026-69492, CVE-2026-71341 |
| Windows Enterprise App Management | 2 | CVE-2026-69481, CVE-2026-69907 |
| Windows Microsoft DirectMusic | 1 | CVE-2026-69491 |
| Windows Event Logging Service | 3 | CVE-2026-69493, CVE-2026-69494, CVE-2026-69495 |
| Windows Secure Kernel Mode | 4 | CVE-2026-69501, CVE-2026-69846, CVE-2026-69906, CVE-2026-83939 |
| Role: Windows Fax Service | 3 | CVE-2026-69509, CVE-2026-69621, CVE-2026-72944 |
| Connected Devices Platform Service (Cdpsvc) | 1 | CVE-2026-69516 |
| Windows Wireless Networking | 1 | CVE-2026-69517 |
| Windows Remote Desktop | 1 | CVE-2026-69518 |
| Visual Studio | 4 | CVE-2026-69522, CVE-2026-71328, CVE-2026-77906, CVE-2026-77907 |
| Reliable Multicast Transport Driver (RMCAST) | 3 | CVE-2026-69530, CVE-2026-78449, CVE-2026-78450 |
| Windows Camera Frame Server Monitor | 1 | CVE-2026-69542 |
| Windows SMB Client | 4 | CVE-2026-69544, CVE-2026-69572, CVE-2026-69618, CVE-2026-72936 |
| Windows RNDIS | 2 | CVE-2026-69548, CVE-2026-69768 |
| Windows Hyper-V | 5 | CVE-2026-69553, CVE-2026-69603, CVE-2026-69910, CVE-2026-72961, CVE-2026-80083 |
| Windows Work Folder Service | 2 | CVE-2026-69560, CVE-2026-71336 |
| Windows Online Certificate Status Protocol (OCSP) | 1 | CVE-2026-69564 |
| Windows Universal Disk Format File System Driver (UDFS) | 3 | CVE-2026-69573, CVE-2026-69592, CVE-2026-69758 |
| Graphic Fonts | 3 | CVE-2026-69576, CVE-2026-72986, CVE-2026-73018 |
| Windows Message Queuing | 3 | CVE-2026-69579, CVE-2026-69645, CVE-2026-83997 |
| Microsoft Windows PDF | 1 | CVE-2026-69586 |
| Windows Routing and Remote Access Service (RRAS) | 8 | CVE-2026-69590, CVE-2026-69852, CVE-2026-70570, CVE-2026-71351, CVE-2026-71353, CVE-2026-72939, CVE-2026-72950, CVE-2026-72959 |
| Windows Services for NFS ONCRPC XDR Driver | 6 | CVE-2026-69595, CVE-2026-70585, CVE-2026-71330, CVE-2026-73024, CVE-2026-78445, CVE-2026-83989 |
| Windows HTTP.sys | 1 | CVE-2026-69597 |
| Windows PrintWorkflowUserSvc | 1 | CVE-2026-69602 |
| Microsoft Install Service | 1 | CVE-2026-69605 |
| Windows Deployment Services | 4 | CVE-2026-69607, CVE-2026-72943, CVE-2026-72954, CVE-2026-72957 |
| Windows Resilient File System (ReFS) | 2 | CVE-2026-69617, CVE-2026-83952 |
| Windows exFAT File System | 1 | CVE-2026-69619 |
| Windows HTTP Print Provider | 2 | CVE-2026-69623, CVE-2026-69769 |
| Microsoft Office Outlook | 7 | CVE-2026-69629, CVE-2026-78509, CVE-2026-78519, CVE-2026-78520, CVE-2026-78525, CVE-2026-80073, CVE-2026-80084 |
| Windows Notification | 1 | CVE-2026-69648 |
| Windows Raw Image Extension | 1 | CVE-2026-69649 |
| Windows Accounts Control | 2 | CVE-2026-69654, CVE-2026-69816 |
| Windows Kerberos | 5 | CVE-2026-69676, CVE-2026-69685, CVE-2026-69744, CVE-2026-69760, CVE-2026-69822 |
| Microsoft Office PowerPoint | 10 | CVE-2026-69678, CVE-2026-69767, CVE-2026-69797, CVE-2026-72938, CVE-2026-72956, CVE-2026-72975, CVE-2026-72977, CVE-2026-78513, CVE-2026-80081, CVE-2026-80086 |
| Windows Host Guardian Service | 1 | CVE-2026-69682 |
| Windows Encrypting File System (EFS) | 3 | CVE-2026-69688, CVE-2026-69794, CVE-2026-69841 |
| Windows IP Address Management (IPAM) Service | 1 | CVE-2026-69694 |
| Windows Web Platform Storage | 1 | CVE-2026-69708 |
| Windows Hello | 9 | CVE-2026-69710, CVE-2026-69725, CVE-2026-69740, CVE-2026-69784, CVE-2026-69799, CVE-2026-69820, CVE-2026-69864, CVE-2026-72980, CVE-2026-81354 |
| Windows Key Distribution Center | 2 | CVE-2026-69712, CVE-2026-84001 |
| Windows Secure Boot | 1 | CVE-2026-69713 |
| Windows Direct Show | 1 | CVE-2026-69715 |
| Windows Group Policy | 1 | CVE-2026-69717 |
| Windows Credential Providers | 3 | CVE-2026-69729, CVE-2026-69790, CVE-2026-69814 |
| HID class driver | 1 | CVE-2026-69731 |
| Windows Link Layer Topology Discovery Protocol | 1 | CVE-2026-69732 |
| Windows Broadcast DVR User Service | 1 | CVE-2026-69735 |
| Microsoft Office Publisher | 2 | CVE-2026-69742, CVE-2026-81385 |
| Windows Container Manager Service | 1 | CVE-2026-69771 |
| Windows DWM Core Library | 1 | CVE-2026-69775 |
| Windows DHCP Client | 2 | CVE-2026-69777, CVE-2026-69781 |
| Role: DNS Server | 4 | CVE-2026-69782, CVE-2026-69827, CVE-2026-69989, CVE-2026-77505 |
| Windows Smart Card | 1 | CVE-2026-69785 |
| RPC Runtime | 1 | CVE-2026-69819 |
| Windows ALPC | 3 | CVE-2026-69834, CVE-2026-69874, CVE-2026-85880 |
| Windows iSCSI Target Service | 1 | CVE-2026-69839 |
| Spring Cloud Azure | 1 | CVE-2026-69854 |
| Azure Cosmos DB | 1 | CVE-2026-69857 |
| Windows Wireless Wide Area Network Service | 1 | CVE-2026-69862 |
| Windows Virtual Trusted Platform Module | 1 | CVE-2026-69890 |
| Windows Media | 1 | CVE-2026-69891 |
| Microsoft Fabric | 1 | CVE-2026-70178 |
| Windows Media Player | 2 | CVE-2026-70203, CVE-2026-72960 |
| Windows Win32 Kernel Subsystem | 2 | CVE-2026-70289, CVE-2026-70290 |
| Visual Studio Code | 10 | CVE-2026-70334, CVE-2026-78461, CVE-2026-78462, CVE-2026-81356, CVE-2026-81357, CVE-2026-81376, CVE-2026-81377, CVE-2026-81378, CVE-2026-81379, CVE-2026-81383 |
| Microsoft WebP Image Extension | 1 | CVE-2026-70351 |
| Azure AI Language | 1 | CVE-2026-70352 |
| Windows AF_UNIX Socket Provider | 1 | CVE-2026-70565 |
| Windows Display Enhancement Service | 1 | CVE-2026-70567 |
| Windows Schannel | 2 | CVE-2026-70575, CVE-2026-72940 |
| Windows Credential Guard | 2 | CVE-2026-70578, CVE-2026-72958 |
| Windows Mobile Broadband | 1 | CVE-2026-70579 |
| Windows Core Messaging | 2 | CVE-2026-70583, CVE-2026-70584 |
| Windows Paint | 1 | CVE-2026-70586 |
| Windows Remote Desktop Protocol | 1 | CVE-2026-70587 |
| Windows Secure Socket Tunneling Protocol (SSTP) | 4 | CVE-2026-71332, CVE-2026-72930, CVE-2026-72931, CVE-2026-73009 |
| Windows NFS Portmapper | 1 | CVE-2026-71334 |
| Windows Failover Cluster | 4 | CVE-2026-71338, CVE-2026-72989, CVE-2026-73010, CVE-2026-78444 |
| Windows Internet Connection Sharing (ICS) | 3 | CVE-2026-72926, CVE-2026-72964, CVE-2026-72983 |
| Winsock | 1 | CVE-2026-72927 |
| Microsoft WDAC OLE DB provider for SQL | 1 | CVE-2026-72933 |
| Storage Port Driver | 3 | CVE-2026-72937, CVE-2026-72946, CVE-2026-77492 |
| Windows Task Scheduler | 1 | CVE-2026-72945 |
| Windows SMB Server Network Transport Driver (srvnet.sys) | 1 | CVE-2026-72949 |
| Windows Modern Execution Server | 1 | CVE-2026-72963 |
| Windows WebClient Service | 1 | CVE-2026-72965 |
| Microsoft Office Excel | 32 | CVE-2026-72974, CVE-2026-78515, CVE-2026-78518, CVE-2026-81386, CVE-2026-81387, CVE-2026-81388, CVE-2026-81389, CVE-2026-81390, CVE-2026-81391, CVE-2026-81392, CVE-2026-81393, CVE-2026-81394, CVE-2026-81395, CVE-2026-81396, CVE-2026-81397, CVE-2026-81398, CVE-2026-81399, CVE-2026-81400, CVE-2026-81401, CVE-2026-81947, CVE-2026-81948, CVE-2026-81949, CVE-2026-81950, CVE-2026-81951, CVE-2026-81953, CVE-2026-81954, CVE-2026-81956, CVE-2026-81957, CVE-2026-81958, CVE-2026-81959, CVE-2026-81960, CVE-2026-85875 |
| Active Directory Federation Services (AD FS) | 1 | CVE-2026-72978 |
| IP Helper | 1 | CVE-2026-72981 |
| Windows Volume Shadow Copy | 1 | CVE-2026-72985 |
| Windows USB Hub Driver | 1 | CVE-2026-72999 |
| Windows Autopilot | 1 | CVE-2026-73004 |
| Windows Authentication Methods | 1 | CVE-2026-73005 |
| Windows Management Services | 1 | CVE-2026-73012 |
| Data Sharing Service Client | 1 | CVE-2026-73014 |
| Windows Graphics Kernel | 1 | CVE-2026-73017 |
| Windows GDI | 1 | CVE-2026-77491 |
| Windows Boot Manager | 1 | CVE-2026-77892 |
| Windows Security Center | 1 | CVE-2026-77899 |
| Azure CycleCloud | 1 | CVE-2026-77909 |
| Windows OLE DB | 2 | CVE-2026-78441, CVE-2026-78442 |
| Microsoft Windows SCSI Class System File | 3 | CVE-2026-78451, CVE-2026-78452, CVE-2026-78453 |
| Xbox | 1 | CVE-2026-78455 |
| Windows Security Health Service | 1 | CVE-2026-78457 |
| Windows Work Folders | 1 | CVE-2026-80075 |
| Microsoft Authenticator | 1 | CVE-2026-80097 |
| Copilot Studio | 1 | CVE-2026-80098 |
| Azure HDInsights | 1 | CVE-2026-81349 |
| GitHub Copilot and Visual Studio Code | 2 | CVE-2026-81380, CVE-2026-81381 |
| Windows Update Stack | 1 | CVE-2026-81963 |
| Windows Virtualization-Based Security (VBS) Enclave | 2 | CVE-2026-83498, CVE-2026-83501 |
| Microsoft Azure Active Directory B2C | 1 | CVE-2026-83711 |
| Entra ID | 1 | CVE-2026-83941 |
| Microsoft Azure CLI | 1 | CVE-2026-83948 |
| Windows Resilient File System (ReFS) Deduplication Service | 1 | CVE-2026-83999 |
| Microsoft Authentication Library (MSAL) for Node.js | 1 | CVE-2026-84003 |
Other Information
At the time of publication, there were no new advisories included with the September Security Guidance.