Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-896 Date: September 8, 2026 As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 11.0 installed on Linux .NET 11.0 installed on Mac OS .NET 11.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows ASP.NET Core 10.0 ASP.NET Core 11.0 ASP.NET Core 8.0 ASP.NET Core 9.0 Azure AI Language Authoring Azure Arc SQL Server Extension Azure Cosmos DB Azure CycleCloud Azure HDInsight HEIF Image Extension HEVC Video Extensions HEVC Video Extensions for Licensed Applications HEVC Video Extensions from Device Manufacturer Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Authentication Library (MSAL) Microsoft Authenticator for Android Microsoft Azure Active Directory B2C Microsoft Azure CLI Microsoft Copilot Studio Microsoft Discovery Studio Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Customer Engagement Microsoft Entra ID Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Fabric Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac Microsoft Office for Android Microsoft Outlook 2016 Microsoft Power Platform Microsoft PowerPoint 2016 Microsoft Publisher 2016 Microsoft SQL Server 2017 Microsoft SQL Server 2019 Microsoft SQL Server 2022 Microsoft SQL Server 2025 Microsoft SharePoint Server Subs
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-september-2026-monthly-rollup-av26-896
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-81963Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 48% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-85880Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 45% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-81963 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85880 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl
- unknownexploitedMicrosoft Monthly Security Update (September 2026)hkcert
- unknownexploitedSecurity Alert: Microsoft Releases September 2026 Security Updatesjpcert
- unknownexploitedMultiples vulnérabilités dans Microsoft Windows (09 septembre 2026)cert-fr-avis
- highexploitedCVE-2026-85880: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges…nvd
- highexploitedCVE-2026-81963: Improper link resolution before file access ('link following') in Windows Update Stack allows …nvd
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- highexploitedCVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerabilitymsrc
- highexploitedCVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerabilitymsrc
- criticalexploitedCVE-2026-81963: Microsoft Windows Link Following Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerabilitycisa-kev
More from Canadian Centre for Cyber Security
- unknownFortra security advisory (AV26-906)2026-09-10
- unknownPalo Alto Networks security advisory (AV26-905)2026-09-10
- unknownAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…2026-09-09
- unknownCitrix security advisory (AV26-833) - Update 12026-09-09
- criticalCisco security advisory (AV26-197) – Update 32026-09-09