BlackTree Security · Infrastructure · Automation · AI

September Patch Tuesday Forces Restarts Across Windows While Two Flaws Are Already Under Attack

Microsoft’s September security release gives defenders an unusually large number of reasons to be busy. It does not give them permission to treat every reason as equally urgent.

The company says the release addresses 974 Microsoft CVEs. Microsoft’s data marks 113 September entries as Critical. BlackTree’s provisional September Patch Intelligence cycle currently contains 152 approved Microsoft and SAP patch records linked to 1,019 unique CVEs. Eleven deployable records have been accelerated for immediate action.

Those figures describe the size of the release. They do not tell a business what to do first.

The decision that matters is which attack paths are already being used, which vulnerable services are reachable, which fixes will interrupt operations and how the organisation will prove that the risk has actually been removed. On that basis, September has a clear order: close the two exploited Windows privilege-escalation paths, deal with exposed network services, patch Outlook, then work through the remainder by applicability and consequence.

The number to watch is two, not 974

Microsoft reports active exploitation of two Windows vulnerabilities:

VulnerabilityWhat Microsoft says an attacker can achieveWhere BlackTree currently maps the fixBusiness priority
CVE-2026-85880Escape a low-privilege AppContainer and elevate to SYSTEM through Windows Advanced Local Procedure CallWindows 10 21H2 and 22H2, Windows 10 1607 and 1809, Windows Server 2012, 2012 R2, 2016, 2019 and 2022Patch applicable systems now, particularly shared endpoints, application servers and machines where browsers or document handlers create sandboxed processes
CVE-2026-81963Use a Windows Update Stack link-following and access-control weakness to gain SYSTEM privilegesWindows 11 23H2, 24H2, 25H2 and 26H1, plus Windows Server 2025Patch current Windows estates now and confirm the required restart has completed

Both vulnerabilities require an attacker to have some local access already. That does not make them secondary risks. Local elevation flaws often provide the bridge between an initial foothold and full control of a device. The first compromise may arrive through phishing, a malicious download, a browser flaw, stolen credentials or another route. A reliable path from a restricted context to SYSTEM can turn that limited entry into persistence, credential theft, security-tool interference and lateral movement.

Microsoft has not identified the attackers, campaigns, victim numbers or initial-access methods associated with the observed exploitation. There are no public Microsoft indicators in the advisories that would justify pretending an organisation can hunt its way out of patching. Treat the exploitation status as evidence for deployment urgency, not as licence to invent an incident narrative.

BlackTree’s eleven accelerated records are not eleven different zero-days. They are eleven applicable Windows update records driven by these two exploited vulnerabilities. That distinction matters to change teams because the work must be planned by operating-system version and knowledge-base package, not by counting headlines.

Our separate examination of the two exploited Windows flaws maps each path to the affected Windows generations and explains what Microsoft’s exploitation status does, and does not, reveal.

Open the live September 2026 Patch Intelligence cycle to map the relevant KBs, affected products, restart requirements and later revisions.

The next question is not “What scored 9.8?”

Several Critical vulnerabilities deserve rapid attention because an unauthenticated attacker can reach vulnerable services over a network. Their real priority depends on whether the relevant role is installed, exposed and business-critical.

VulnerabilityAttack prerequisiteThe team that should answer firstImmediate action
CVE-2026-73010A specially crafted network packet reaches Microsoft Failover ClusterWindows platform and service ownersIdentify clusters, map reachable cluster interfaces, patch through a tested rolling or failover sequence and verify cluster health afterwards
CVE-2026-69595A specially crafted packet reaches Windows Services for NFSStorage and Windows Server teamsConfirm where the NFS role is enabled, remove unnecessary exposure, patch active nodes and test mounts and dependent workloads
CVE-2026-73009A specially crafted packet reaches Secure Socket Tunnelling ProtocolNetwork access and remote-access ownersLocate RRAS and SSTP endpoints, prioritise internet-facing systems, patch and test remote-access authentication and connectivity
CVE-2026-72982A specially crafted packet reaches Windows NetlogonIdentity and Active Directory teamsPrioritise domain controllers, use the organisation’s established DC rollout sequence and verify replication, authentication and dependent services
CVE-2026-69845An attacker already on the network can call arbitrary endpoints exposed by Windows DHCP ServerNetwork infrastructure and Windows Server teamsPatch DHCP servers using failover where available, restrict management and service reachability, then validate leases, reservations and failover state

Four of these entries have a CVSS base score of 9.8 and require no authentication or user interaction. The DHCP Server flaw is also scored 9.8, but Microsoft describes an in-network prerequisite. That difference is operationally significant. An internet-reachable SSTP endpoint and an isolated internal role do not present the same immediate probability, even when the score printed beside them is identical.

Inventory must therefore come before blanket prioritisation. A Critical vulnerability in a role that is not installed is not the next deployment. A vulnerability already being exploited on thousands of applicable endpoints is.

Outlook removes the click from the risk conversation

CVE-2026-78509 is a Critical Microsoft Outlook remote-code-execution vulnerability with a CVSS score of 9.8. Microsoft says an attacker can send a specially crafted email and trigger the flaw when the message is displayed in Outlook’s Reading Pane. The recipient does not need to open an attachment or click a link.

Microsoft separately says the Preview Pane is not an attack vector. Those two product terms must not be collapsed into a vague claim that every preview is dangerous. The defensible conclusion is narrower and more important: familiar awareness advice such as “do not click” is not a compensating control for this vulnerability.

Organisations should accelerate supported Outlook updates, identify unmanaged desktop Office installations and avoid closing the risk simply because email filtering or staff training exists. At publication, Microsoft said the updates for Office LTSC for Mac 2021 and 2024 were not yet available and would be added through a later advisory revision. Mac administrators should verify the fix has actually been released and installed before reporting the estate as compliant.

This vulnerability is not known to be exploited at publication. It still belongs near the front of the queue because message delivery is a routine business function and the interaction threshold is unusually low.

Read the full Outlook Reading Pane analysis for the product-language distinction, Mac update gap and business response.

Two perfect scores that do not need a customer patch

September also demonstrates why CVSS cannot be used as an automatic deployment queue. CVE-2026-83711, an Azure AD B2C authorisation bypass, and CVE-2026-70352, an Azure AI Language authentication weakness, both carry a 10.0 score.

Microsoft says both cloud-service vulnerabilities have been fully mitigated and require no customer action. They still matter for assurance, supplier-risk records and incident review, but they should not displace an exploited Windows fix from tonight’s deployment window.

A mature patch programme distinguishes between a severe weakness, an applicable exposure and an action the customer can actually take.

What Security, IT and business owners should do now

During the first four hours

  1. Freeze the facts. Record the Microsoft release date, BlackTree cycle revision and the time the organisation made its decision. The cycle is provisional and can change after publication.
  2. Query the asset inventory by exact operating-system release. Separate Windows 11 and Server 2025 devices affected by CVE-2026-81963 from the older Windows and server releases affected by CVE-2026-85880.
  3. Find the exposed roles. Assign owners for Failover Cluster, NFS, SSTP, Netlogon and DHCP. Ask whether the role is enabled, where it is reachable from and what breaks if the service is restarted.
  4. Identify unsupported or exceptional systems. Windows 10 devices receiving Extended Security Updates, legacy Server 2012 systems, isolated operational technology, golden images and systems outside normal endpoint management require an explicit owner. “Not in the console” is not a risk decision.
  5. Open a restart window. All eleven BlackTree-accelerated Windows records currently require a restart. Even devices enrolled in Windows hotpatching may require one this month because Microsoft classifies September as a baseline release.

During the first 12 hours

  1. Run a representative pilot. Include a current Windows 11 endpoint, an applicable older Windows endpoint, at least one server from every exposed role, a domain controller according to established sequencing, and an Outlook desktop build used in production.
  2. Test the business service, not just update installation. A successful package status does not prove that remote access, failover, authentication, storage or email still works.
  3. Check prerequisites and known issues for each KB. Windows cumulative updates may include servicing-stack components, but teams should still check the exact package, prerequisites, release health and known issues that apply to their build.
  4. Prepare rollback without treating it as the default response. Confirm backups, cluster failover, recovery keys and recovery procedures before broad deployment. Document who can pause the rollout and what evidence justifies that decision.

During the first 24 hours

  1. Deploy the two exploited fixes across applicable systems. Prioritise endpoints exposed to untrusted content, shared systems, privileged workstations and servers that would provide valuable credentials or lateral-movement paths.
  2. Patch internet-facing and broadly reachable network services. Handle SSTP, NFS and cluster systems according to actual exposure and redundancy. Protect service availability through sequencing, not through indefinite delay.
  3. Deploy supported Outlook fixes. Track desktop Office separately from web and mobile access, and keep the Mac exception visible until Microsoft publishes the relevant update.
  4. Enforce the restart. A package staged but awaiting reboot is not equivalent to a closed vulnerability. Measure pending-restart devices as a separate exception population.

During the next 72 hours

  1. Complete the applicable remainder of the September cycle. Use exploit status, attack preconditions, asset exposure, business impact and compensating controls together.
  2. Reconcile failures and blind spots. Devices that did not report, did not download, failed installation or missed their restart need named owners and deadlines.
  3. Watch for revisions. Microsoft may add packages, known issues or platform-specific guidance. The September BlackTree cycle will also change as vendor data is reprocessed and validated.
  4. Close with evidence. Retain the device identifier, applicable KB, installed build, deployment time, restart time, validation result and exception reason. A dashboard percentage alone is not an audit trail.

What good reporting looks like on Wednesday morning

Executives do not need a screenshot that says “95 per cent compliant”. They need to know whether the organisation’s credible attack paths remain open.

A useful status report answers six questions:

  • How many devices were applicable to each exploited vulnerability?
  • How many have installed the correct update and restarted?
  • Which exposed servers remain vulnerable, and why?
  • Which business services were tested after deployment?
  • Which devices or roles are outside central management?
  • What new Microsoft revisions or known issues could change the decision?

The remaining five per cent matters far more if it contains domain controllers, remote-access gateways or executive laptops than if it contains powered-off laboratory machines. Report residual risk by asset importance and exposure, not just by percentage.

The business lesson in this Patch Tuesday

September’s release is large enough to encourage an unhelpful response: treat everything as urgent, push everything at once and declare success when the management console turns green.

The better response is more disciplined. Start with exploitation evidence. Map each flaw to the machines and services that can actually be reached. Make the restart a planned business event. Test the service after the patch. Keep unsupported and unmanaged assets visible. Then preserve enough evidence to prove that the path an attacker would use is no longer available.

Patch Tuesday is not a download ritual. It is a monthly exercise in deciding which pieces of the business can be taken over, which fixes can interrupt them and how quickly the organisation can reduce both risks without losing control of either.

Go deeper on September’s most urgent risks

Sources and live references

Editorial note: Counts and catalogue status were checked on 8 September 2026 at 21:10 CEST. Microsoft and BlackTree can revise advisories, applicability, packages and known-issue information after publication. Recheck the linked live records before deployment.

Leave a Reply

Your email address will not be published. Required fields are marked *