Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

September 2026 Microsoft Patch Tuesday security alert - 973 vulnerabilities fixed including two zero-days

September Patch Tuesday: 973 Fixes and Two Zero-Days Already Exploited

Microsoft dropped its September 2026 Patch Tuesday overnight, and it’s a big one — 973 vulnerabilities across Windows, Office, Exchange, SharePoint, SQL Server and Azure. Two of those flaws are already being exploited in the wild.

The actively exploited pair are both elevation-of-privilege bugs. CVE-2026-85880 targets Windows Advanced Local Procedure Call (ALPC), and CVE-2026-81963 abuses a link-following weakness in the Windows Update Stack. Neither is rated Critical — both sit at Important — which is exactly the kind of thing that causes them to slip through a patch cycle if your team only triages by severity rating. Attackers don’t care about your triage labels; they care about what works.

That’s worth pausing on, because it’s a pattern we see repeatedly across our Australian client base. Businesses that patch only Critical-rated CVEs within the first week end up leaving actively exploited Important-rated flaws open for weeks. In a managed environment we treat any “exploitation detected” flag as a Critical-equivalent, regardless of Microsoft’s rating. If you’re not doing the same, these two will sit unpatched while someone uses them for lateral movement.

What else matters in this release

Beyond the two zero-days, there are Critical remote-code-execution fixes in Excel (CVE-2026-81959, CVE-2026-81953) and Word (CVE-2026-81952). If your staff open Office documents from external sources — and they do — these need attention. Windows Print Spooler, Remote Desktop Client and Message Queuing also picked up Important-rated RCE fixes.

Exchange Server gets nine patches. If you’re still running on-prem Exchange (and after the 22,000-server exposure story we covered last week, plenty of Australian businesses are), don’t let this batch sit in the queue.

What to do right now

1. Prioritise the two exploited flaws. CVE-2026-85880 and CVE-2026-81963 should go out this week, not next cycle.

2. Patch Office separately. Windows cumulative updates don’t cover Office. Check your update channel and confirm Excel and Word fixes are deploying.

3. Review known issues before pushing to production. Microsoft flags issues with Exchange, SQL Server and Windows Server in this release. Test before you approve a broad rollout.

How All IT Services can help

We manage patching for businesses across Sydney, the Central West, Brisbane and Melbourne. Our clients had both zero-day patches triaged and scheduled within hours of release — not waiting for next month’s maintenance window. If your current patch process relies on someone remembering to check, talk to us about managed IT or get in touch.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →