Security Digest: September 9, 2026 - 108 Critical Vulnerabilities

Microsoft’s September 9 security wave is urgent: today’s disclosures include multiple network-reachable remote code execution flaws in Windows core services, Office, DHCP, DNS, Hyper-V, and RRAS, plus privilege-escalation issues in Entra ID, Exchange, SQL Server, and Windows components. If you run Microsoft infrastructure, patch first on exposed servers and user-facing endpoints, then verify mitigations for Office, Exchange, and identity platforms.

· 18 min read

Executive Summary

Microsoft’s September 9 security wave is urgent: today’s disclosures include multiple network-reachable remote code execution flaws in Windows core services, Office, DHCP, DNS, Hyper-V, and RRAS, plus privilege-escalation issues in Entra ID, Exchange, SQL Server, and Windows components. If you run Microsoft infrastructure, patch first on exposed servers and user-facing endpoints, then verify mitigations for Office, Exchange, and identity platforms.

Do not delay: several bugs allow unauthenticated or low-privilege attackers to take control over the network, and the mix of buffer overflows, use-after-free, and auth bypass issues means exploitation risk is high once patches are public.

Critical Vulnerabilities

  • CVE-2026-83941: Entra ID privilege escalation
    • Impact: An authorized attacker can elevate privileges over the network.
    • Affected Systems: Entra ID tenants and connected identity workflows.
    • Immediate Action: Review privileged role assignments now and apply Microsoft’s fix as soon as it is available.
    • Mitigation: Tighten conditional access, reduce standing admin access, and audit recent role changes.
  • CVE-2026-69845: Windows DHCP Server code execution
    • Impact: Unauthenticated remote code execution.
    • Affected Systems: Windows DHCP Server.
    • Immediate Action: Patch DHCP servers first, especially internet- or branch-facing systems.
    • Mitigation: Restrict DHCP exposure to trusted networks until patched.
  • CVE-2026-78510: Microsoft Word code execution
    • Impact: Malicious documents can trigger remote code execution.
    • Affected Systems: Microsoft 365 Apps, Office 2016/2019/2021.
    • Immediate Action: Update Office on all endpoints immediately.
    • Mitigation: Block unknown attachments and keep Protected View enabled.
  • CVE-2026-72983: Windows ICS code execution
    • Impact: Remote code execution over the network.
    • Affected Systems: Windows Internet Connection Sharing.
    • Immediate Action: Patch affected Windows systems and disable ICS where not required.
    • Mitigation: Remove unnecessary sharing features from exposed systems.
  • CVE-2026-78509: Microsoft Outlook code execution
    • Impact: Malicious content can lead to remote code execution.
    • Affected Systems: Outlook and Microsoft 365 mail clients.
    • Immediate Action: Update Outlook clients now.
    • Mitigation: Treat unexpected messages and previews as high risk until patched.
  • CVE-2026-77493: Microsoft Graphics Component double free
    • Impact: Remote code execution.
    • Affected Systems: Windows graphics stack and apps using it.
    • Immediate Action: Apply Windows updates across desktops and servers.
    • Mitigation: Limit exposure to untrusted images and documents.
  • CVE-2026-69595: Windows Services for NFS ONCRPC XDR Driver
    • Impact: Remote code execution.
    • Affected Systems: Windows NFS components.
    • Immediate Action: Patch servers using NFS services immediately.
    • Mitigation: Disable NFS services if not needed.
  • CVE-2026-69715: Windows DirectShow code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows multimedia components.
    • Immediate Action: Update all Windows endpoints.
    • Mitigation: Avoid opening untrusted media files.
  • CVE-2026-69491: Windows DirectMusic buffer overflow
    • Impact: Remote code execution.
    • Affected Systems: Windows media stack.
    • Immediate Action: Patch Windows systems now.
    • Mitigation: Restrict untrusted media execution paths.
  • CVE-2026-78445: Windows Services for NFS ONCRPC XDR Driver
    • Impact: Remote code execution.
    • Affected Systems: Windows NFS components.
    • Immediate Action: Prioritize servers with NFS enabled.
    • Mitigation: Disable NFS exposure where possible.
  • CVE-2026-72982: Windows Netlogon stack overflow
    • Impact: Remote code execution over the network.
    • Affected Systems: Domain-connected Windows systems.
    • Immediate Action: Patch domain controllers and critical servers first.
    • Mitigation: Monitor for abnormal authentication traffic.
  • CVE-2026-72979: Windows DHCP Server code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows DHCP Server.
    • Immediate Action: Update DHCP servers immediately.
    • Mitigation: Segregate DHCP service from untrusted networks.
  • CVE-2026-69824: Microsoft Standard XPS code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows XPS components.
    • Immediate Action: Apply Windows patches to endpoints and servers.
    • Mitigation: Limit XPS document handling from untrusted sources.
  • CVE-2026-70296: Windows Imaging Component code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows imaging stack.
    • Immediate Action: Patch all Windows devices.
    • Mitigation: Avoid untrusted image files until updated.
  • CVE-2026-73010: Windows Failover Cluster code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows Failover Clustering.
    • Immediate Action: Update clustered servers first.
    • Mitigation: Restrict cluster management access.
  • CVE-2026-73009: Windows SSTP code execution
    • Impact: Remote code execution.
    • Affected Systems: Secure Socket Tunneling Protocol.
    • Immediate Action: Patch VPN-facing Windows systems now.
    • Mitigation: Reduce SSTP exposure where possible.
  • CVE-2026-69910: Windows Hyper-V stack overflow
    • Impact: Remote code execution.
    • Affected Systems: Hyper-V hosts.
    • Immediate Action: Patch virtualization hosts urgently.
    • Mitigation: Limit admin access to hypervisors.
  • CVE-2026-73025: Windows iSCSI weak authentication
    • Impact: Security feature bypass.
    • Affected Systems: Windows iSCSI deployments.
    • Immediate Action: Review iSCSI exposure and patch immediately.
    • Mitigation: Enforce network segmentation and access controls.
  • CVE-2026-69819: RPC Runtime code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows RPC services.
    • Immediate Action: Patch all exposed Windows systems.
    • Mitigation: Restrict RPC exposure across network boundaries.
  • CVE-2026-69769: Windows HTTP Print Provider code execution
    • Impact: Remote code execution.
    • Affected Systems: Print infrastructure.
    • Immediate Action: Patch print servers and endpoints.
    • Mitigation: Disable unnecessary print services.
  • CVE-2026-69590: Windows RRAS code execution
    • Impact: Remote code execution and unauthorized access.
    • Affected Systems: Routing and Remote Access Service.
    • Immediate Action: Patch RRAS servers immediately.
    • Mitigation: Limit remote access paths until fixed.
  • CVE-2026-69525: Windows Remote Desktop Services code execution
    • Impact: Remote code execution.
    • Affected Systems: RDS deployments.
    • Immediate Action: Patch remote desktop servers now.
    • Mitigation: Restrict RDP exposure and require MFA.
  • CVE-2026-69408: Windows Media Foundation code execution
    • Impact: Remote code execution.
    • Affected Systems: Media-capable Windows systems.
    • Immediate Action: Update Windows endpoints immediately.
    • Mitigation: Avoid untrusted media content.
  • CVE-2026-69829: Windows Shell code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows shell components.
    • Immediate Action: Patch desktops and file servers now.
    • Mitigation: Limit interaction with untrusted files and archives.
  • CVE-2026-69276: UxTheme Library code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows theme handling.
    • Immediate Action: Apply the latest Windows cumulative update.
    • Mitigation: Restrict untrusted theme packages.
  • CVE-2026-69431: Telnet Client buffer overflow
    • Impact: Remote code execution.
    • Affected Systems: Systems with Telnet Client enabled.
    • Immediate Action: Remove Telnet Client where possible and patch.
    • Mitigation: Use secure remote administration tools only.
  • CVE-2026-69496: Windows Compressed Folder code execution
    • Impact: Remote code execution via archive handling.
    • Affected Systems: Windows archive utilities.
    • Immediate Action: Patch Windows and warn users about unknown ZIP files.
    • Mitigation: Block suspicious archives at the gateway.
  • CVE-2026-69493: Windows Event Logging Service code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows logging services.
    • Immediate Action: Patch servers and endpoints now.
    • Mitigation: Watch for event log tampering.
  • CVE-2026-69579: Windows Message Queuing code execution
    • Impact: Remote code execution.
    • Affected Systems: MSMQ-enabled systems.
    • Immediate Action: Patch or disable MSMQ if unused.
    • Mitigation: Reduce network exposure of message queues.
  • CVE-2026-69586: Microsoft Windows PDF code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows PDF handling.
    • Immediate Action: Update Windows and PDF-handling apps.
    • Mitigation: Treat unsolicited PDFs as hostile.
  • CVE-2026-69463: Windows NTFS code execution
    • Impact: Remote code execution.
    • Affected Systems: NTFS file systems.
    • Immediate Action: Prioritize servers and file shares.
    • Mitigation: Restrict access to untrusted removable media.
  • CVE-2026-69768: Windows RNDIS code execution
    • Impact: Remote code execution.
    • Affected Systems: Windows networking stack.
    • Immediate Action: Patch all Windows hosts.
    • Mitigation: Limit USB/network bridging devices.
  • CVE-2026-69730: Windows DNS code execution
    • Impact: Remote code execution.
    • Affected Systems: DNS servers.
    • Immediate Action: Patch DNS infrastructure immediately.
    • Mitigation: Restrict recursive and management access.
  • CVE-2026-81376: Visual Studio Code security bypass
    • Impact: Security feature bypass.
    • Affected Systems: VS Code installations.
    • Immediate Action: Update VS Code across developer fleets.
    • Mitigation: Review extensions and remote workspace access.
  • CVE-2026-65669: SQL Server privilege escalation
    • Impact: Authorized attacker can elevate privileges.
    • Affected Systems: SQL Server.
    • Immediate Action: Patch database servers and review privileged logins.
    • Mitigation: Remove excess SQL roles and monitor admin activity.
  • CVE-2026-69356: Exchange Server XSS/spoofing
    • Impact: Spoofing and phishing-style abuse.
    • Affected Systems: Microsoft Exchange Server.
    • Immediate Action: Patch Exchange immediately.
    • Mitigation: Harden mail hygiene and user awareness.
  • CVE-2026-69641: Exchange Server privilege escalation
    • Impact: Authorized attacker can elevate privileges.
    • Affected Systems: Microsoft Exchange Server.
    • Immediate Action: Patch Exchange and audit admin roles.
    • Mitigation: Minimize Exchange administrative access.
  • CVE-2026-69854: Spring Cloud Azure auth bypass
    • Impact: Unauthorized privilege escalation.
    • Affected Systems: Spring Cloud Azure deployments.
    • Immediate Action: Update application dependencies now.
    • Mitigation: Validate auth flows and rotate exposed credentials.

Note: The full set of 108 advisories includes additional Windows, Office, Azure, SQL Server, Exchange, and developer-tool weaknesses with similar impact patterns. Treat all affected Microsoft endpoints and servers as high priority until fully patched.

Previously Alerted

What to Do Now

  1. Patch Microsoft servers first: DHCP, DNS, Exchange, RRAS, Hyper-V, RDS, Netlogon, and Failover Clustering.
  2. Patch user endpoints next: Windows desktops, Office, Outlook, VS Code, and PDF/image/media handlers.
  3. Disable or restrict unused services: Telnet, NFS, ICS, MSMQ, iSCSI, and unnecessary remote access features.
  4. Check identity and privilege controls: Entra ID, AD CS, SQL Server, Exchange, and Windows admin roles.
  5. Verify deployment: confirm cumulative updates are installed, reboot where required, and track failed patch jobs.

Verification steps: inventory exposed Windows servers, confirm patch levels on critical systems, and compare against Microsoft’s advisories before the end of the day. Validate that Office and Outlook clients are updated, and that any internet-facing remote access services are behind MFA and segmentation.

Monitoring recommendations: watch for unusual authentication attempts, DNS/DHCP anomalies, new admin accounts, suspicious Office document launches, and unexpected service restarts. Prioritize alerts from domain controllers, mail servers, VPN gateways, and virtualization hosts.

Related Resources

  • Internal blog post: “September 2026 Microsoft Patch Tuesday response plan”
  • Internal blog post: “Hardening Office, Exchange, and Entra ID after critical disclosures”
  • Official vendor advisories: Microsoft Security Update Guide and Microsoft 365 release notes

Keep reading