01303 883111 info@meridian-micro.com Support Login
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
Security

Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities Including 2 Actively Exploited Zero-Days: What Kent SMEs Must Deploy This Week

September 9, 2026 Meridian Micro
little helpers

Microsoft released its September 2026 Patch Tuesday security updates yesterday, 8 September, addressing
973 vulnerabilities, including two zero-days already exploited in attacks
. For Kent SMEs, this is one of the largest and most critical patch releases of the year, requiring immediate deployment to protect against privilege escalation attacks that are actively compromising Windows systems in the wild.

Microsoft September 2026 Patch Tuesday: The Numbers

The scale of this month’s release is unprecedented.
The broader Patch Tuesday release addresses 974 CVEs across Microsoft’s products, including 723 affecting Windows
.
The release spans Windows, Microsoft Office, SQL Server, Exchange, SharePoint, Azure, and developer tools, requiring organisations to coordinate remediation across endpoints, servers, and enterprise application environments
.

This represents one of the largest monthly security releases from Microsoft since the company began its Patch Tuesday cycle, and for UK SMEs, it demands immediate attention from IT teams or managed service providers who prepared for the 8 September release.

CVE-2026-85880 and CVE-2026-81963: Two Zero-Days Under Active Exploitation

The two actively exploited flaws are tracked as CVE-2026-85880 and CVE-2026-81963. Microsoft says neither vulnerability was publicly disclosed before patches became available on September 8, but it has already detected exploitation in the wild
.

CVE-2026-85880: Windows ALPC Privilege Escalation

The heap-based buffer overflow flaw in Windows ALPC may allow an authenticated attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges
.
CISA added the CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026
.

For Kent businesses, this is a critical concern. An attacker who has already gained initial access to a Windows system—through phishing, credential theft, or any other means—can use this vulnerability to gain complete control of the device.

CVE-2026-81963: Windows Update Stack Privilege Escalation

The second zero-day, CVE-2026-81963, is an Important-rated elevation-of-privilege vulnerability in Windows Update Stack. Check Point’s advisory describes improper link resolution before file access, commonly called link following, that allows an authorized attacker to elevate privileges locally
.

CISA added the CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 22, 2026
.
Since 2022, seven Windows Update Stack EoP vulnerabilities have been patched across Patch Tuesday releases, but CVE-2026-81963 is the first to have been exploited in the wild as a zero-day
.

Critical Vulnerabilities Across Microsoft’s Product Stack

Beyond the two actively exploited zero-days, this month’s Patch Tuesday includes numerous high-severity issues.
This month’s release includes fixes for several high-severity issues that could potentially enable remote code execution, privilege escalation, or denial-of-service attacks
.

Microsoft’s release notes attribute 723 addressed vulnerabilities to Windows, 111 to Office, 62 to SQL, 22 to developer tools, 16 to SharePoint Server and nine to Exchange Server
. For SMEs running on-premises Exchange Server,
only customers who enrolled in the Period 2 Extended Security Update (ESU) program are eligible to receive Exchange Server 2016 and 2019 security updates released between May and October 2026
.

What Kent SMEs Must Do This Week

The presence of two actively exploited zero-days makes immediate deployment non-negotiable. Here’s what your business must do:

The Broader Security Context for UK SMEs

This massive patch release comes at a time when
43% of UK businesses, roughly 612,000 organisations, and 28% of charities identified a cyber breach or attack in the previous 12 months
. Privilege escalation vulnerabilities like CVE-2026-85880 and CVE-2026-81963 are particularly dangerous because they’re typically used in the second stage of an attack, after an attacker has already gained initial access through phishing or business email compromise.

As always, timely patch deployment is crucial to reduce exposure and ensure systems remain resilient against exploitation attempts
. With
Windows 11 24H2 Home or Pro reaching end of servicing on October 13, 2026, after that date they will no longer receive monthly security updates, making an upgrade to a supported Windows release increasingly important
, businesses must also plan for longer-term Windows version management alongside monthly patching.

Need Help Deploying the September 2026 Patch Tuesday Updates?

Meridian Micro provides comprehensive Windows update management for SMEs across Kent and the South East, including testing, deployment, and rollback support for critical security patches. We ensure your systems remain secure without disrupting business operations.

If your business needs assistance deploying this month’s critical security updates or implementing a proactive patch management process, call our Saltwood team on 01303 883111 or visit our offices in Hythe to discuss how we can strengthen your security posture.