01303 883111 info@meridian-micro.com
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
Security

Microsoft Office September 2026 Critical Updates Fix 22 High-Risk Vulnerabilities Including 12 Preview Pane Exploits: What Kent SMEs Must Patch Now

September 23, 2026 Meridian Micro
Mobile Worker

Microsoft’s September 2026 Patch Tuesday delivered critical security updates for Office products that demand immediate attention from Kent SMEs.
This month’s release includes 21 Critical RCE vulnerabilities and one Critical information disclosure flaw spanning Outlook, Word, Excel, PowerPoint, Office Graphics Component, and Windows Graphics Component.
The most concerning aspect:
Microsoft Office received 22 Critical patches this month, of which 12 are exploitable via Preview Pane or Reading Pane. When Preview Pane or Reading Pane is enabled, merely previewing a crafted file triggers code execution without any click, attachment open, or macro prompt.

For UK businesses running Microsoft Office 2019, Office 2021, or Microsoft 365 Apps for Enterprise, these vulnerabilities represent an immediate threat that requires action this week—not during the next scheduled maintenance window.

Why Microsoft Office September 2026 Updates Are Urgent for Kent SMEs

This attack pattern has historically been favored by both commodity phishing campaigns and targeted intrusion operators because it eliminates much of the social-engineering friction of convincing users to take an action.
An attacker no longer needs an employee to double-click a file or enable macros; the malicious code executes the moment the file appears in the Preview Pane.

The sheer volume of fixes compounds the risk.
Microsoft addressed across 61 updates, prioritizing .NET 10.0, 8.0, and 9.0 on Windows and Office 2019 and Microsoft 365 Apps for Enterprise, which show the heaviest concentration of fixes.
This concentration means businesses running these specific Office versions face the greatest exposure.

The Preview Pane Threat: No User Action Required

Traditional security awareness training teaches staff to avoid opening suspicious attachments. Preview Pane vulnerabilities render that advice insufficient. If Outlook’s Reading Pane or Windows Explorer’s Preview Pane is enabled—the default configuration in many Office installations—simply selecting a malicious email or file in the folder view executes the attack code.

The implications for UK SMEs are significant. Email remains the primary attack vector for most cyber incidents affecting small businesses, and
the heaviest client entries are CVE-2026-78510 in Word and CVE-2026-78509 in Outlook, both critical remote code execution at CVSS 9.8, in document-rendering paths that fire on preview or open.

Which Microsoft Office Products Kent Businesses Must Update This Week

The September 2026 security updates affect multiple Office applications and deployment models. Kent SMEs must check update status across all of the following:

Microsoft’s Office suite also drew heavy attention this cycle, with Word taking 38 fixes and Excel receiving 32, several of which are rated Critical remote code execution flaws that could be triggered through a malicious document opened by an unsuspecting user. The Critical remote-code-execution fixes include CVE-2026-81959 and CVE-2026-81953 in Excel, and CVE-2026-81952 in Word.

Relationship to Broader September 2026 Patch Tuesday

The Office updates form part of Microsoft’s largest security release of 2026.
Microsoft’s September 2026 Patch Tuesday is the year’s largest release, with 963 CVEs requiring customer action, 106 rated critical. Two are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local Procedure Call.
While those two actively exploited zero-day vulnerabilities affect Windows components rather than Office directly, they underscore the urgency of comprehensive patching across all Microsoft products this month.

How Kent SMEs Should Deploy Microsoft Office September 2026 Updates

Deployment approach depends on your Office licensing model and IT management structure.

Microsoft 365 Apps for Enterprise

Cloud-connected Microsoft 365 installations typically receive updates automatically through the Office Content Delivery Network (CDN). However, businesses that have configured update deferrals or use on-premises update servers must verify installation manually:

Office 2019 and Office 2021 Perpetual Licences

Perpetual-licence Office installations receive updates through Windows Update or Microsoft Update. IT teams managing these versions should:

Readiness recommends a Patch Now scheduling for Windows, Office, SQL Server and the developer tooling, and standard patch release for Exchange.

Businesses Using Managed IT Support

If Meridian Micro or another IT provider manages your systems, contact your account manager this week to confirm Office update status. Managed service providers typically deploy critical Office patches within the first week of release, but verification remains prudent given the severity of this month’s vulnerabilities.

Office Update Verification and Rollback Planning

Office updates occasionally introduce compatibility issues with line-of-business applications or macros. Before mass deployment across your organisation, test the September updates on a small group of representative users covering different roles and workflows.

Monitor for:

Document the pre-update Office version number so you can request a rollback if critical business processes break. However, given the severity of the Preview Pane vulnerabilities, tolerance for delayed patching should be minimal—measured in days, not weeks.

Complementary Security Measures for Kent Businesses Running Office

While patching remains the definitive fix, several complementary controls reduce exposure during the deployment window:

Disable Preview Pane in Outlook

In Outlook, navigate to the View tab and deselect Reading Pane. This forces users to double-click emails to open them, restoring a manual step that prevents automatic exploitation. Deploy this configuration via Group Policy if managing multiple workstations.

Disable Preview Pane in Windows Explorer

In File Explorer, select the View tab and ensure Preview pane is unticked. This prevents automatic rendering of Office documents when browsing file shares or local folders.

Email Attachment Filtering

Review your email security gateway configuration to block or quarantine high-risk Office file types arriving from external senders, particularly:

Balance security against legitimate business communication requirements, but err toward caution during the immediate post-release period when exploit development accelerates.

Why Preview Pane Vulnerabilities Affect UK SME Cyber Insurance Claims

Cyber insurance policies increasingly scrutinise patch management practices when assessing claims. Failure to deploy critical security updates within a reasonable timeframe—typically 14 to 30 days, depending on the insurer—can result in claim denial or reduced settlement amounts.

The Preview Pane attack vector is particularly relevant because it bypasses traditional “user error” defences. Insurers may view unpatched Preview Pane vulnerabilities as a failure of technical controls rather than employee training, strengthening their position in claim disputes.

Given
CVE-2026-81963 and CVE-2026-85880 as exploited, which means attacks have already been observed rather than being only theoretical possibilities. Microsoft has released its September 2026 security updates, including fixes for two vulnerabilities it says are already being exploited.
The presence of in-the-wild exploitation across the broader September patch set increases the likelihood of rapid weaponisation of the Office vulnerabilities as well.

Long-Term Office Security Strategy Beyond September 2026 Patches

This month’s exceptional patch volume reflects broader trends in vulnerability discovery that will continue affecting UK SMEs throughout 2026 and beyond. As we documented in our analysis of AI-powered vulnerability discovery driving record patch volumes, automated security research is identifying flaws faster than ever.

Kent businesses should adopt a more aggressive patch cadence rather than treating each monthly release as discretionary. Microsoft now recommends deploying Windows updates within 3 days, and that same urgency increasingly applies to Office, Exchange, and other productivity applications.

Consider moving from perpetual Office licences to Microsoft 365 subscriptions if update management has become a persistent challenge. Cloud-connected Office installations receive automatic updates with less administrative overhead, reducing the window of exposure to newly disclosed vulnerabilities.

Next Steps for Kent SMEs This Week

Immediate actions for the next 48 hours:

The combination of Preview Pane exploitability and the sheer number of critical Office vulnerabilities in September 2026 makes this one of the most significant Office security releases in recent years. Kent SMEs cannot afford to delay deployment while waiting for the next convenient maintenance window.

If you need assistance verifying Office update status across your organisation, troubleshooting failed installations, or deploying the September 2026 patches to remote workers, Meridian Micro’s IT support team in Saltwood, Hythe can help. Call us on 01303 883111 to schedule an urgent patch verification appointment this week.