September Patch Tuesday: 973 Fixes and Two Zero-Days Already Exploited
Microsoft dropped its September 2026 Patch Tuesday overnight, and it’s a big one — 973 vulnerabilities across Windows, Office, Exchange, SharePoint, SQL Server and Azure. Two of those flaws are already being exploited in the wild.
The actively exploited pair are both elevation-of-privilege bugs. CVE-2026-85880 targets Windows Advanced Local Procedure Call (ALPC), and CVE-2026-81963 abuses a link-following weakness in the Windows Update Stack. Neither is rated Critical — both sit at Important — which is exactly the kind of thing that causes them to slip through a patch cycle if your team only triages by severity rating. Attackers don’t care about your triage labels; they care about what works.
That’s worth pausing on, because it’s a pattern we see repeatedly across our Australian client base. Businesses that patch only Critical-rated CVEs within the first week end up leaving actively exploited Important-rated flaws open for weeks. In a managed environment we treat any “exploitation detected” flag as a Critical-equivalent, regardless of Microsoft’s rating. If you’re not doing the same, these two will sit unpatched while someone uses them for lateral movement.
What else matters in this release
Beyond the two zero-days, there are Critical remote-code-execution fixes in Excel (CVE-2026-81959, CVE-2026-81953) and Word (CVE-2026-81952). If your staff open Office documents from external sources — and they do — these need attention. Windows Print Spooler, Remote Desktop Client and Message Queuing also picked up Important-rated RCE fixes.
Exchange Server gets nine patches. If you’re still running on-prem Exchange (and after the 22,000-server exposure story we covered last week, plenty of Australian businesses are), don’t let this batch sit in the queue.
What to do right now
1. Prioritise the two exploited flaws. CVE-2026-85880 and CVE-2026-81963 should go out this week, not next cycle.
2. Patch Office separately. Windows cumulative updates don’t cover Office. Check your update channel and confirm Excel and Word fixes are deploying.
3. Review known issues before pushing to production. Microsoft flags issues with Exchange, SQL Server and Windows Server in this release. Test before you approve a broad rollout.
How All IT Services can help
We manage patching for businesses across Sydney, the Central West, Brisbane and Melbourne. Our clients had both zero-day patches triaged and scheduled within hours of release — not waiting for next month’s maintenance window. If your current patch process relies on someone remembering to check, talk to us about managed IT or get in touch.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
