{"id":9351,"date":"2026-09-09T03:27:36","date_gmt":"2026-09-09T03:27:36","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9351"},"modified":"2026-09-09T03:27:36","modified_gmt":"2026-09-09T03:27:36","slug":"september-2026-patch-tuesday-roundup-plugs-for-two-zero-day-holes-among-almost-1000-fixes-in-windows","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9351","title":{"rendered":"September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2026-Sep\" target=\"_blank\" rel=\"noopener\">September Patch Tuesday release<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer action. Excluded are 174 third-party\/open-source CVEs and 23 Chromium\/Edge CVEs, as well as nine Microsoft mitigated vulnerabilities in applications like Azure, Entra, and Copilot Studio where no customer action is required.<\/p>\n<p class=\"wp-block-paragraph\">Separately, developers and SAP admins whose staff use SAP\u2019s ABAP (Advanced Business Application Programming) should take action to close a critical vulnerability, with a CVSS score of 10.0, in the Extended Passport Processing (EPP) component. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application, say researchers at Onapsys. EPP is used in enterprise suites like SAP S\/4Hana and NetWeaver to log document creation or trace end-to-end transactions.<\/p>\n<h2 class=\"wp-block-heading\">Microsoft vulnerabilities<\/h2>\n<p class=\"wp-block-paragraph\">The two zero-days revealed today are:<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-85880\">CVE-2026-85880<\/a>, a heap-based buffer overflow in Windows ALPC (Advanced Local Procedure Call), which is already being exploited. ALPC is an internal messaging system in Windows that lets programs talk to each other. An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required, <a href=\"https:\/\/www.action1.com\/patch-tuesday\/patch-tuesday-september-2026\/\">said Action1.<\/a>\u00a0<br \/>Microsoft said affected products include certain versions of Windows Server 2012, Windows Server 2016, and Windows 10 Desktop.<br \/><a href=\"https:\/\/www.ivanti.com\/blog\/authors\/chris-goettl\">Chris Goettl<\/a>, Ivanti\u2019s vice-president of product management, said this vulnerability \u201caffects the entire Windows fleet.\u201d<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-81963\">CVE-2026-81963<\/a>, an escalation of privilege stemming from an improper link resolution before file access (also called link following) in Windows Update Stack. An attacker who successfully exploits this vulnerability could gain System privileges. Affected versions include Windows 11 Desktop and Windows Server 2025, said Microsoft. However <a href=\"https:\/\/www.action1.com\/patch-tuesday\/patch-tuesday-september-2026\/\">researchers at Action1 said<\/a> specific affected Windows versions cannot be confirmed from the available data.<br \/>There is no workaround other than installing the fix. Exploitation has been detected, Action1 noted, making remediation a high priority even though the severity and CVSS score cannot be confirmed.\u00a0<br \/>This is the first zero-day of the seven privilege escalation flaws discovered in Windows Update Stack since 2022, and the first to be exploited, added <a href=\"https:\/\/www.tenable.com\/profile\/satnam-narang\">Satnam Narang<\/a>, senior staff research engineer at Tenable.<\/p>\n<p class=\"wp-block-paragraph\">The sheer number of this month\u2019s Microsoft patches stunned some experts. <a href=\"https:\/\/www.linkedin.com\/in\/dustincchilds\/\" target=\"_blank\" rel=\"noopener\">Dustin Childs<\/a>, head of threat awareness at the Zero Day Initiative, said, in a reference to the film <em>2001: A Space Odyssey<\/em>, \u201clooking at nearly 1,000 vulnerabilities in a single month, all I can think is: \u2018My God, it\u2019s full of stars.&#8217;\u201d <\/p>\n<p class=\"wp-block-paragraph\">\u201cAI-assisted bug discovery has exploded patch counts into a whole new galaxy,\u201d he said, \u201cand defenders simply have to embrace the suck.\u201d<\/p>\n<p class=\"wp-block-paragraph\">About 20 of the vulnerabilities could be wormable bugs, he warned. \u201cWe haven\u2019t seen a global worm in years, but with a DNS flaw acting as the spiritual successor to <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2020-1350\" target=\"_blank\" rel=\"noopener\">SigRed<\/a>, that reality could change fast.\u201d <\/p>\n<p class=\"wp-block-paragraph\">That new vulnerability is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-69730\" target=\"_blank\" rel=\"noopener\">CVE-2026-69730<\/a>, a Windows DNS remote code execution hole. As of Tuesday, it hadn\u2019t yet been exploited, Microsoft said, but the company expects it will be. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system, with no authentication or user interaction required.<\/p>\n<p class=\"wp-block-paragraph\">Asked about vulnerabilities that could be wormed, <a href=\"https:\/\/www.linkedin.com\/in\/bicer\/\" target=\"_blank\" rel=\"noopener\">Jack Bicer<\/a>, Action1\u2019s director of vulnerability research, drew attention to <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-62893\" target=\"_blank\" rel=\"noopener\">CVE-2026-62893<\/a>, a Windows Deployment Services TFTP Server Remote Code Execution issue first patched in August, and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-69590\" target=\"_blank\" rel=\"noopener\">CVE-2026-69590<\/a>, a Windows Routing and Remote Access Service Remote Code Execution. Neither requires authentication or user interaction. Because of this, he said, these types of vulnerability could spread quickly across a network if affected systems are not patched.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.fortra.com\/profile\/tyler-reguly\" target=\"_blank\" rel=\"noopener\">Tyler Reguly<\/a>, Fortra\u2019s associate director of security R&amp;D, pointed out that as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning. <\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is not a Microsoft-specific problem,\u201d he noted. \u201cWe see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing, as we\u2019re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed, and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key, and gift cards for extra coffee for your admins would likely be appreciated.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Bicer added that the scale of this month\u2019s Microsoft releases requires security leaders to move beyond CVSS-driven patching and prioritize systems according to exploitability, network exposure, privilege requirements, business criticality, and the consequences of compromise. The most consequential risks, he said, are concentrated in remotely reachable infrastructure, identity and authentication services, database platforms, virtualization environments, and Windows components where successful exploitation could provide code execution or elevated privileges.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cOne of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,\u201d Bicer stressed. \u201cAI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn\u2019t finding more needles. It\u2019s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Patches from other vendors<\/h2>\n<p class=\"wp-block-paragraph\">Researchers at Nightwing also noted that this week Adobe patched an actively exploited zero-day in Adobe Commerce and Magento (<a href=\"https:\/\/experienceleague.adobe.com\/en\/docs\/commerce-knowledge-base\/kb\/announcements\/commerce-apsb26-146\" target=\"_blank\" rel=\"noopener\">CVE-2026-75650<\/a>, CVSS 10.0), dubbed StyleSmuggler, which drops Linux backdoors and web shells. Adobe said \u201cUrgent Action\u201d is required.<\/p>\n<p class=\"wp-block-paragraph\">Fortinet confirmed ongoing active exploitation of older two authentication bypass vulnerabilities in FortiOS (<a href=\"https:\/\/www.tenable.com\/cve\/CVE-2024-55591\" target=\"_blank\" rel=\"noopener\">CVE-2024-55591<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2025-24472\" target=\"_blank\" rel=\"noopener\">CVE-2025-24472<\/a>), allowing unauthenticated remote attackers to seize administrative control of edge firewalls.<\/p>\n<p class=\"wp-block-paragraph\">Cisco Systems addressed <a href=\"https:\/\/www.csoonline.com\/article\/4219968\/cisco-bundles-fixes-for-multiple-vulnerabilities-some-critical-into-one-patch-2.html\" target=\"_blank\" rel=\"noopener\">eight serious vulnerabilities<\/a> across IOS XR systems while warning of active exploitation targeting an unauthenticated denial-of-service flaw in Secure Firewall ASA devices (<a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-asaftd-vpn-dos-dzv4mQFF\" target=\"_blank\" rel=\"noopener\">CVE-2026-20349<\/a>) first described last month.<\/p>\n<p class=\"wp-block-paragraph\">\u00a0Red Hat\u00a0fixed a critical privilege escalation vulnerability in Advanced Cluster Management for Kubernetes 2 (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-10090\" target=\"_blank\" rel=\"noopener\">CVE-2026-10090<\/a>, CVSS 9.0, described last month) that enables attackers to breach multi-tenant container boundaries; and Tenable resolved a critical flaw in Sensor Proxy protecting the core pipeline organizations rely on for security auditing (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-18667\" target=\"_blank\" rel=\"noopener\">CVE-2026-18667<\/a>, CVSS 9.6) that had permitted code execution with elevated privileges.<\/p>\n<h2 class=\"wp-block-heading\">SAP vulnerabilities<\/h2>\n<p class=\"wp-block-paragraph\">Jonathan Stross, Pathlock\u2019s senior product manager for cybersecurity R&amp;I, noted that three of the Security Notes this month reach full compromise territory without a single valid credential. \u201cThat is an unusually concentrated cluster of unauthenticated, network-reachable, maximum-impact issues for a single Patch Day,\u201d <a href=\"https:\/\/pathlock.com\/blog\/sap-security-patch-day-september-2026\/\" target=\"_blank\" rel=\"noopener\">he said in a commentary<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The critical hole plugged by SAP Security Note\u00a0<a href=\"https:\/\/me.sap.com\/notes\/3747649\" target=\"_blank\" rel=\"noopener\">#3747649<\/a>\u00a0is a memory corruption vulnerability in the Extended Passport Processing (EPP) component in ABAP-based systems. Researchers at Onapsis Research Labs, <a href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-september-2026\/\" target=\"_blank\" rel=\"noopener\">who discovered the vulnerability<\/a>, have dubbed it OVERPASS. <\/p>\n<p class=\"wp-block-paragraph\">Boundary validation is missing during the deserialization of EPP data, resulting in a memory safety violation when processing externally supplied length fields. This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination. The SAP Security Note provides a patch for ABAP and Java kernels, and for SAP Web Dispatcher, version 9.16. Other Web Dispatcher versions and Web Dispatcher included in SAP S\/4HANA Extended Application Services are not affected.<\/p>\n<p class=\"wp-block-paragraph\">Onapsys urged immediate patching, since the vulnerability exists by default in a wide range of SAP components, is exploitable remotely and without authentication, allows remote attackers to run arbitrary operating system commands on the SAP host with SAP administrative privileges that results in full compromise of the underlying SAP business data and processes, and is reachable through several SAP components and several communication protocols. None of these require credentials, Onapsys pointed out, so no single network control can fully mitigate risk.<\/p>\n<p class=\"wp-block-paragraph\">Onapsys also drew attention to SAP Security Note\u00a0<a href=\"https:\/\/me.sap.com\/notes\/3759472\" target=\"_blank\" rel=\"noopener\">#3759472<\/a>, with a CVSS score of 9.8, in NetWeaver Message Server. This bug is the result of insufficient validation of the authenticity of internal application server components during registration. Consequently, unauthenticated attackers with network access can register unauthorized components and potentially perform unauthorized actions within the application environment. <\/p>\n<p class=\"wp-block-paragraph\">A successful exploitation could result in a high impact on the confidentiality, integrity, and availability of the affected system, SAP said. The vulnerability, which the Onapsis Research Labs is dubbing S4GET, is present across SAP\u2019s entire modern kernel family (9.16, 9.18, 9.19, 9.20), meaning every S\/4HANA 2025 system, and any earlier release already moved to one of those kernels, is affected.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release. The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer action. Excluded are 174 third-party\/open-source CVEs and 23 Chromium\/Edge CVEs, as well [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9352,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9351","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9351"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9351"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9351\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9352"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9351"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9351"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9351"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}