Microsoft Monthly Security Update (September 2026)
Microsoft has released monthly security update for their products:
| Vulnerable Product | Risk Level | Impacts | Notes |
| Open Source Software | Medium Risk | Elevation of Privilege | |
| Developer Tools | Medium Risk | Denial of Service Information Disclosure Elevation of Privilege Remote Code Execution Security Restriction Bypass Data Manipulation | |
| SQL Server | Medium Risk | Remote Code Execution Elevation of Privilege Security Restriction Bypass Information Disclosure Denial of Service | |
| Windows | Medium Risk | Elevation of Privilege Information Disclosure Remote Code Execution Spoofing Denial of Service Security Restriction Bypass Data Manipulation | CVE-2026-81963 is being exploited in the wild. This vulnerability is an improper link resolution before file access defect in Windows Update Stack. Successful exploitation could allow an authorized attacker to elevate privileges locally. Hence, the risk level of this vulnerability is rated as Medium Risk. |
| Extended Security Updates (ESU) | Medium Risk | Elevation of Privilege Remote Code Execution Spoofing Denial of Service Security Restriction Bypass Information Disclosure Data Manipulation | CVE-2026-85880 is being exploited in the wild. A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) allows an authorized attacker to elevate privileges locally. An attacker who can execute code from a low-privilege AppContainer can exploit the vulnerability locally to escape the sandbox and elevate privileges on the affected system without requiring additional user interaction. Hence, the risk level of this vulnerability is rated as Medium Risk. |
| Server Software | Medium Risk | Remote Code Execution Spoofing Data Manipulation Denial of Service Elevation of Privilege Information Disclosure | |
| Apps | Medium Risk | Elevation of Privilege | |
| Microsoft Office | Medium Risk | Remote Code Execution Spoofing Information Disclosure Denial of Service Elevation of Privilege | |
| Azure | Medium Risk | Elevation of Privilege Information Disclosure Spoofing Remote Code Execution | |
| Microsoft Dynamics | Medium Risk | Remote Code Execution Elevation of Privilege |
Number of 'Extremely High Risk' product(s): 0
Number of 'High Risk' product(s): 0
Number of 'Medium Risk' product(s): 10
Number of 'Low Risk' product(s): 0
Evaluation of overall 'Risk Level': Medium Risk
Impact
- Elevation of Privilege
- Denial of Service
- Remote Code Execution
- Information Disclosure
- Data Manipulation
- Security Restriction Bypass
- Spoofing
System / Technologies affected
- Open Source Software
- Developer Tools
- SQL Server
- Windows
- Extended Security Updates (ESU)
- Server Software
- Apps
- Microsoft Office
- Azure
- Microsoft Dynamics
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor.

沒有留言:
發佈留言