Cyber Security

Microsoft Security Update - 9 September 2026

By Matsco Engineering Team

Microsoft Security Update - 9 September 2026

Microsoft has released a security advisory on the 9th of September in line with their regular monthly patch schedule which includes a number of updates to address a record 974 CVEs and two exploited zero-days in ten (10) medium risk products. 

These updates address vulnerabilities which may impact services through Elevation of Privilege, Denial of Service, Remote Code Execution, Information Disclosure, Data Manipulation, Security Restriction Bypass, and Spoofing. 

 For more information please see: Microsoft Security Update

 This release consists of security updates for the following products:

  • Azure    
  • Developer Tools
  • Exchange Server
  • Office
  • Office 2016
  • Other
  • SharePoint Server
  • Skype for Business
  • SQL
  • Windows

CVE-2026-85880  - A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) allows an authorized attacker to elevate privileges locally. An attacker who can execute code from a low-privilege AppContainer can exploit the vulnerability locally to escape the sandbox and elevate privileges on the affected system without requiring additional user interaction.

CVE-2026-81963 - This vulnerability is an improper link resolution before file access defect in Windows Update Stack. Successful exploitation could allow an authorized attacker to elevate privileges locally.

Matsco recommends any affected systems are updated as soon as convenient.

Please contact the Matsco Solutions team on the below if you would like any further information or would like to schedule a maintenance.

All resources

Get Started

Let's make technology work for you.

Get in touch about support, cloud, security, or a build-out, wherever in the world you operate.