CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1

unknownknown exploitedCVE-2026-81963CVE-2026-85880
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-896 Date: September 8, 2026 As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 11.0 installed on Linux .NET 11.0 installed on Mac OS .NET 11.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows ASP.NET Core 10.0 ASP.NET Core 11.0 ASP.NET Core 8.0 ASP.NET Core 9.0 Azure AI Language Authoring Azure Arc SQL Server Extension Azure Cosmos DB Azure CycleCloud Azure HDInsight HEIF Image Extension HEVC Video Extensions HEVC Video Extensions for Licensed Applications HEVC Video Extensions from Device Manufacturer Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Authentication Library (MSAL) Microsoft Authenticator for Android Microsoft Azure Active Directory B2C Microsoft Azure CLI Microsoft Copilot Studio Microsoft Discovery Studio Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Customer Engagement Microsoft Entra ID Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Fabric Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac Microsoft Office for Android Microsoft Outlook 2016 Microsoft Power Platform Microsoft PowerPoint 2016 Microsoft Publisher 2016 Microsoft SQL Server 2017 Microsoft SQL Server 2019 Microsoft SQL Server 2022 Microsoft SQL Server 2025 Microsoft SharePoint Server Subs

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-09-08
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-september-2026-monthly-rollup-av26-896

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-81963coverage & exploitation statusNVD · CVE.org
CVE-2026-85880coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security