Microsoft shipped 964 fixes on 8 September. The two flaws being exploited right now hit opposite halves of a Windows estate, so no version escapes. Here's the order of work.
September 2026 Patch Tuesday: What to Patch First, and Why "We're on Windows 11" Isn't an Answer
Microsoft shipped 964 fixes on 8 September. Two of the flaws are being exploited right now, and most of the coverage has reported them as a single problem with a single answer. They aren't. One of them affects Windows 10 and Server 2012 through 2022 and cannot touch Windows 11. The other affects Windows 11 and Server 2025 and cannot touch Windows 10.
So there's no version of a Windows estate that walks away from this month clean. If you run a mix, and nearly every business we see does, you're exposed to both.
The number is the least useful thing in the release
You'll see five different totals depending on where you read: 964, 966, 973, 974, even 1,169. Every one of them reconciles back to Microsoft's own security update document, and the difference is only what each outlet chose to count. Some include Azure Linux. Some include Chromium flaws that Google found and Microsoft merely shipped. Some include cloud services you can't patch because Microsoft already did.
The figure worth using is 964, the count that requires action from a customer. It splits into 104 Critical and 860 Important.
Now put it aside. Nobody patches 964 things. A number that large only tells you the month was busy, and it's the first thing to reach for if you want to frighten someone rather than help them. Three of those 964 are what your week should be about.
The two exploited flaws hit opposite halves of your estate
This is the part the headlines have flattened.
CVE-2026-85880 is an elevation-of-privilege flaw in the Windows Advanced Local Procedure Call system. An attacker who can already run low-privilege code on the machine uses it to escape the sandbox and become SYSTEM, with no user interaction. It's rated 7.8, and Microsoft confirms exploitation has been detected.
It affects Windows 10 (1607, 1809, 21H2 and 22H2) and Windows Server 2012, 2012 R2, 2016, 2019 and 2022, including Server Core. It does not affect Windows 11 in any version, and it does not affect Server 2025.
CVE-2026-81963 is an elevation-of-privilege flaw in the Windows Update Stack, also exploited, also ending in SYSTEM. It affects Windows 11 and Server 2025, and it does not affect Windows 10.
Both are already listed in CISA's Known Exploited Vulnerabilities catalogue, which is the closest thing to an official statement that attacks are happening rather than theoretical.
The practical consequence is simple. "We finished our Windows 11 migration" is not an answer this month, and neither is "we're still on 10 and nothing has happened yet". The first question is which machines you have, and the second is which of the two patches each one needs.
If you cannot answer that question today, the inventory is the job before the patching, because nobody can patch a machine they have not listed.
If you're still on Windows 10, the fix is behind a paywall
This is the part that turns a patching job into a purchasing decision.
The fix for the actively exploited ALPC flaw reaches Windows 10 22H2 through KB5122878, released on 8 September. That update only goes to devices enrolled in Extended Security Updates.
Windows 10 reached end of support in October 2025. If some machines stayed behind and nobody bought ESU cover for them, those machines are not getting this patch. Not late, not queued: not at all. They're running an operating system with a SYSTEM-level flaw that attackers are using today, and there is no fix coming through Windows Update.
Extended Security Updates run to October 2028, so enrolling is still possible. It costs money and the price rises each year, so it buys time without solving the problem. We made the case for moving off Windows 10 in our end-of-life post, and if you want to know which machines can take Windows 11, our compatibility guide covers the checks.
Windows Server 2012 and 2012 R2 sit in the same position. They're in the affected list for this zero-day and they've been out of mainstream support since October 2023.
How to tell where you stand, without waiting for a report
Each check runs on the machine itself and takes about a minute.
Which Windows is this? Press Windows and R, type winver, press Enter. The box names the edition and the version, so a machine reading "Windows 10, version 22H2" needs the ALPC fix and one reading "Windows 11" needs the Update Stack fix. On a server, the same command works.
Did the September update install? Settings, then Windows Update, then Update history. You're looking for a security update dated 8 September 2026 or later. On Windows 10 that entry is KB5122878, and if it isn't there on a Windows 10 machine, the ESU question below is the reason.
Is this machine enrolled in ESU? On Windows 10, the Windows Update screen says so directly when enrolment is active. If it doesn't, and the machine is still running, it's receiving no security updates of any kind and hasn't been since October 2025.
Do this on a sample rather than the whole estate. If three machines picked at random all check out, your process is probably working. If one of them doesn't, you've found something worth a proper audit.
Reading Microsoft's own risk labels
Microsoft attaches two separate flags to every vulnerability, and they decide the order of work in any month.
Publicly Disclosed means the details were public before a fix existed. Nothing in September's release carries that flag, which is genuinely good news and worth noting given the size of the release.
Exploited means attacks have been observed. Only the two flaws above carry it out of all 964, which is the whole argument for ignoring the headline number.
Then there's an assessment Microsoft calls the Exploitability Index. "Exploitation Detected" is the top of it and applies to those two. "Exploitation More Likely" is the next rung, and it's the label on the DNS flaw. It means Microsoft's own analysts think working exploit code is straightforward to produce and expect to see it.
That last category is the one most patching programmes underweight, because it doesn't come with a headline. A flaw nobody has exploited yet, that is trivially exploitable and reachable from the network without credentials, is a better argument for patching tonight than one that needs an attacker already inside.
Patch the domain controller before you patch the laptops
One flaw in this release deserves more attention than either zero-day, and almost no coverage has led with it.
CVE-2026-69730 is a remote code execution vulnerability in Windows DNS Server, rated CVSS 9.8. Microsoft's own description is that an unauthenticated attacker can exploit it by sending a crafted packet over the network. Anyone who can reach the service can attempt it, without credentials and without already having a foothold on any machine.
Compare that with the two zero-days. Both of those require an attacker to already be running code on the machine. This one doesn't require them to be inside at all.
Microsoft rates it "Exploitation More Likely" rather than exploited, so there's a window. On a typical small business network the DNS role sits on the on-premises domain controller, which is also where your authentication lives. Microsoft's DNS components carry 14 vulnerabilities this month and four of them are Critical.
If you're sequencing the work, the domain controller goes first. A compromised laptop is a bad day that ends with a rebuild. A compromised domain controller hands over every account in the business at once, and the recovery is measured in days rather than hours.
The DNS role often runs on the same box as Active Directory in a small business, so patching it usually means a reboot of the thing everything else authenticates against, which is a scheduling problem worth raising today rather than on Friday afternoon. And if your DNS server is reachable from outside the network, that is worth checking regardless of this month's fix, because it should not be.
What to do this week
Establish which half of the estate you're on. Not roughly, and not from memory. Windows 11 and Server 2025 machines need CVE-2026-81963. Windows 10 and Server 2012 to 2022 machines need CVE-2026-85880. A mixed estate needs both, which is most businesses.
Confirm ESU enrolment for anything still on Windows 10. This is the one to escalate rather than ticket, because if the answer is no, somebody has to authorise spending before any patch can arrive.
Patch the domain controller first, for the DNS flaw, ahead of end-user machines.
Check the updates landed. Approved in your patching tool and installed on the device are different states, and the gap between them is where most patching programmes quietly fail. Both zero-days are in CISA KEV, so this is the month to verify rather than assume.
Then look at your patching window rather than this month's patches. If your process would have taken three weeks to get here, September was never the problem. Cyber Essentials Plus expects critical and high-severity patches inside 14 days, which is the first thing an assessor tests, and we've written about what that assessment involves.
The honest summary
One busy Patch Tuesday isn't an emergency. Two actively exploited privilege-escalation flaws that between them cover every supported version of Windows, plus an unauthenticated 9.8 against the DNS role, is a week where the order of work matters.
What decides how this goes for a business is whether somebody can already say what is in the estate and which half is which. Patching speed comes second.
If you'd like us to answer that question for your business, and tell you plainly which machines are covered this month and which are not, book a discovery call and we'll go through it with you.

