Microsoft September 2026 Patch Tuesday: Record 974 CVEs, Two Exploited Zero-Days, and a Silent Exchange Attack That Needs No Click
On the second Tuesday of September 2026, Microsoft dropped a patch bundle so large it shattered every record in the history of Patch Tuesday. Nearly 974 vulnerabilities fixed in a single release — including two Windows zero-days already being exploited in the wild, twenty bugs capable of worm-like self-propagation, and one Exchange Server flaw that lets a remote, unauthenticated attacker run code on your mail server simply by sending an email. No credentials. No click. No warning. The CISA deadline for US federal agencies falls on September 22, 2026 — three days from today. For Indian enterprises relying on on-premises Exchange and unpatched Windows endpoints, the clock is running.
KEY TAKEAWAYS
- Microsoft’s September 2026 Patch Tuesday is the largest ever: ~974 CVEs, 113 rated Critical, 2 actively exploited, 20 wormable.
- CVE-2026-85880 (Windows ALPC, CVSS 7.8) and CVE-2026-81963 (Windows Update Stack, CVSS 7.8) are confirmed exploited in the wild — both give SYSTEM-level access.
- CVE-2026-55007 (Exchange Server 2019/SE, CVSS 8.1) allows remote, unauthenticated code execution via a crafted email with a Visio attachment — the server’s indexing engine triggers the payload automatically.
- CISA added the two zero-days to its Known Exploited Vulnerabilities catalog on September 8 with a September 22 remediation deadline for federal agencies.
- Indian IT and NOC teams should patch the four high-priority CVEs this weekend and isolate any Exchange Server that cannot immediately be updated.
A Record-Breaking Patch Tuesday: By the Numbers
Every month, Microsoft bundles security fixes into what is colloquially called Patch Tuesday. September 2026’s release has no precedent. The previous record — just under 600 CVEs — was broken by a margin of nearly 400 vulnerabilities. Of the approximately 974 patches shipped:
- 113 are rated Critical, enabling remote code execution, privilege escalation, or information disclosure at the highest severity tier.
- 2 are actively exploited zero-days confirmed by Microsoft and added to CISA’s KEV catalog.
- 20 are wormable — capable of propagating across networks without any further attacker interaction after initial execution.
- The affected product surface spans Windows 10/11, Windows Server 2019–2025, Microsoft 365 Apps, Exchange Server, SharePoint, SQL Server, Azure services, Authenticator, and core Windows subsystems.
The scale reflects not just an expanding Microsoft product portfolio but a security industry under siege. As Trend Micro’s Zero Day Initiative notes in its September 2026 security update review, triage alone for a release of this magnitude can exhaust an under-resourced security team. The answer, as always, is ruthless prioritisation by exploitation probability — and this month’s list of urgent targets is unusually short and clear.
The Two Exploited Zero-Days: Privilege Escalation to SYSTEM
Both confirmed in-the-wild exploits are Elevation of Privilege (EoP) vulnerabilities. Neither is directly remotely exploitable from the internet in isolation — but that distinction provides cold comfort in the real threat landscape, where initial access through phishing, credential stuffing, or browser exploitation is commonplace.
| CVE | Component | CVSS | Weakness | CISA KEV Deadline |
|---|---|---|---|---|
| CVE-2026-85880 | Windows ALPC | 7.8 | Heap buffer overflow (CWE-122) | September 22, 2026 |
| CVE-2026-81963 | Windows Update Stack | 7.8 | Link following / improper access control (CWE-59) | September 22, 2026 |
CVE-2026-85880 exploits a heap-based buffer overflow in Windows Advanced Local Procedure Call — the foundational inter-process communication mechanism in every modern Windows release. An attacker who already has code execution inside a low-privilege or sandboxed process (think a compromised browser tab or a phished user) can trigger this overflow to escape the sandbox and achieve SYSTEM-level access. This is precisely the kind of “second-stage” exploit that threat actors chain after an initial browser or document exploit. It was being used in the wild before Microsoft published the patch.
CVE-2026-81963 targets the Windows Update Stack itself — the component responsible for downloading and applying patches. By planting a malicious symbolic link before the update stack resolves a file path, a locally authenticated low-privilege attacker can redirect the update engine to write files in locations it should never touch, escalating to SYSTEM. The bitter irony: the patch mechanism is the vector. SecurityWeek’s coverage confirms both vulnerabilities are present in all supported Windows client and server releases.
Technical Deep Dive: CVE-2026-55007 — The Exchange Email That Executes Itself
Of all the patches in September 2026’s release, ZDI’s analysts rank CVE-2026-55007 as their top priority — ranking it above the two actively exploited zero-days on the basis of potential blast radius.
Here is the anatomy of the attack:
- An attacker sends an email to any valid address on your on-premises Exchange Server 2019 or Exchange Server Subscription Edition deployment. The email contains a malicious Visio (.vsdx) attachment.
- Exchange’s built-in content-indexing engine automatically processes every incoming attachment to build the search index — with no user preview or administrator action required.
- The indexing engine triggers a double-free memory corruption bug (CWE-415) while parsing the Visio file, corrupting the heap in a controlled manner.
- Under low-memory conditions — achievable by an attacker who hammers the service with requests, or simply by waiting for a busy mail period — the double-free escalates to arbitrary code execution under Exchange’s process identity.
No credentials. No Preview Pane. No user click. Just send the email.
The affected versions are Exchange Server 2019 Cumulative Update 14 and CU15, and Exchange Server Subscription Edition RTM. Exchange Online (Microsoft 365) is not affected — only on-premises deployments. In India, where thousands of enterprises in banking, manufacturing, and government continue to run on-premises Exchange for data-residency or latency reasons, this vulnerability is particularly acute. The CVSS base score of 8.1 from Microsoft’s own Security Update Guide understates the real-world risk because it accounts for the “sustained low-memory” prerequisite — a bar that a motivated attacker can meet with patience or a modest DDoS against the indexing service.
Twenty Wormable Vulnerabilities: The Escalation Wildcard
The September 2026 release also includes twenty vulnerabilities classified as wormable — meaning that once a single host is compromised, the exploit can propagate laterally to other vulnerable systems with zero additional human interaction. Security Affairs notes that the wormable bugs span Windows networking components, remote service protocols, and server-side services.
For organisations with flat, insufficiently segmented networks — a common pattern in Indian mid-market enterprises — a single compromised host exploiting a wormable bug can spread to hundreds of systems before a SOC alert fires. This is precisely the scenario that zero-trust network segmentation with FortiGate and FortiAuthenticator is designed to contain. Without micro-segmentation, a wormable vulnerability in a flat /16 internal network is effectively a mass-compromise waiting for a single patient-zero infection.
What You Should Do Right Now (Sanjay’s Priority Order)
With a release of 974 CVEs, paralysis is the enemy. Here is the action sequence that I recommend to every IT head, NOC manager, and CISO in my network:
Immediate (this weekend)
- Patch CVE-2026-85880 and CVE-2026-81963 on all Windows endpoints and servers. Both are in active exploitation. Use WSUS, SCCM, or Intune to push the September 2026 cumulative updates immediately. Do not wait for your next scheduled maintenance window.
- Patch CVE-2026-55007 on all on-premises Exchange 2019 and Exchange SE deployments. If you cannot patch immediately, consider blocking inbound Visio attachments (.vsd, .vsdx) at the gateway or disabling the Exchange content-indexing service on the SMTP receive connector until the patch can be applied.
- Run
Get-ExchangeDiagnosticInfoor review Exchange application event logs for any anomalous indexing activity since September 8, 2026 — the date CISA publicly flagged these bugs.
This week
- Inventory wormable CVE exposure. Pull the September 2026 Patch Tuesday list from CISA’s KEV catalog and cross-reference against your asset inventory. Any internet-facing Windows Server or host running affected network services is highest priority.
- Review network segmentation. If your VLAN architecture does not prevent east-west propagation between endpoints and servers, escalate a segmentation review. A flat network and 20 wormable bugs are a genuinely dangerous combination.
- Validate your EDR detections for ALPC exploitation attempts (look for unusual
alpc.sysinteractions or SYSTEM token impersonation from low-privilege processes) and update signatures to detect the Windows Update Stack symlink attack pattern.
This month
- Consider a FortiGate firewall policy review to ensure your perimeter is correctly blocking attachment-type SMTP flows and that IPS signatures are updated to detect Exchange-targeting probes.
- Review your organisation’s patch SLA against CISA’s September 22 deadline as a benchmark, even if you are not a US federal agency. That deadline reflects the threat actor timeline, not regulatory compliance alone.
Frequently Asked Questions
Does CVE-2026-55007 affect Exchange Online (Microsoft 365)?
No. Microsoft has confirmed that Exchange Online is not affected. CVE-2026-55007 is exclusively a risk for on-premises deployments of Exchange Server 2019 (CU14 and CU15) and Exchange Server Subscription Edition RTM. If your organisation has fully migrated to Exchange Online, you are not exposed to this specific vulnerability.
Are the two Windows zero-days remotely exploitable?
Both CVE-2026-85880 and CVE-2026-81963 are classified as Local Privilege Escalation vulnerabilities — an attacker needs some form of local code execution (e.g. from a phishing payload, compromised browser, or insider threat) before they can use these flaws to escalate to SYSTEM. However, in chained attack scenarios, this distinction is largely academic. Threat actors routinely pair a remote initial-access exploit with a local privilege escalation to achieve full control.
How do I know if CVE-2026-55007 has been exploited on my Exchange server?
Look in the Windows Application event log for EventID 4999 (Watson report for Exchange), unusual entries in the MSExchangeTransport log around the indexer, and unexpected child processes spawned by the Microsoft.Exchange.Search.ExSearch.exe process. Any SYSTEM-level process spawned from the Exchange indexer after September 8, 2026 should be treated as a high-confidence indicator of compromise until proven otherwise.
My organisation cannot patch immediately. Is there a workaround for CVE-2026-55007?
Microsoft’s official guidance is to apply the patch. As an interim measure, you can block .vsd and .vsdx attachments at the email gateway or anti-spam appliance. You may also consider disabling the MSExchangeTransportLogSearch service, though this impacts eDiscovery and compliance workflows. Neither workaround eliminates the attack surface entirely — they reduce it. Treat any workaround as a 48-hour bridge, not a long-term solution.
Nearly 1,000 CVEs in a single month is a signal, not just a statistic. It signals that the attack surface of modern Windows-based infrastructure is now so large that no organisation can patch everything simultaneously — which means threat actors will always find the gap between “patched” and “exploited.” The answer is defence-in-depth: patch the critical few immediately, segment your network so wormable bugs cannot travel freely, monitor your Exchange environment for signs of silent exploitation, and maintain the visibility to detect the privilege escalation that follows initial compromise.
If your team needs help assessing your current patch posture, reviewing your Exchange or Windows Server exposure, or implementing the zero-trust segmentation that limits the blast radius of wormable vulnerabilities, reach out for a security assessment. With nearly three decades spent hardening enterprise networks across India, I can help your organisation prioritise what matters before the next threat actor does it for you.