Microsoft September 2026 Patch Tuesday: two exploited zero-days and critical DNS/DHCP RCEs
Two exploited Windows privilege-escalation flaws entered CISA KEV while unauthenticated DNS and DHCP Server RCEs scored 9.8. Identify affected roles, verify builds, patch, contain exposure and hunt for pre-patch compromise.
Scope
Two exploited Windows privilege-escalation flaws entered CISA KEV while unauthenticated DNS and DHCP Server RCEs scored 9.8. Identify affected roles, verify builds, patch, contain exposure and hunt for pre-patch compromise.
Microsoft's September 2026 Patch Tuesday is not a routine Tuesday with a slightly nervous reboot. Microsoft lists 974 Microsoft CVEs in the release, but four Windows flaws deserve the first page of the change calendar:
- CVE-2026-81963 — Windows Update Stack elevation of privilege, already exploited;
- CVE-2026-85880 — Windows ALPC elevation of privilege, already exploited;
- CVE-2026-69730 — Windows DNS Server unauthenticated remote code execution, CVSS 9.8;
- CVE-2026-69845 — Windows DHCP Server unauthenticated remote code execution, CVSS 9.8.
The first two were added to the CISA Known Exploited Vulnerabilities catalogue on 8 September 2026, with a remediation due date of 22 September for US federal civilian agencies. That deadline is not a universal law for everyone else, but it is a useful indication that this is an incident-prevention job, not a task for the next quarterly housekeeping weekend.
The other two flaws affect services which spend their lives accepting network packets. DNS is blamed for nearly everything already; this month, for once, it genuinely deserves the attention.
Scope note: this guide is defensive. It shows how to identify exposed roles, verify servicing levels, reduce reachability, deploy the official updates and investigate suspicious behaviour. It does not contain exploit code. Build and product coverage can change as Microsoft revises an advisory, so use the linked MSRC record as the final authority for each product.
The one-minute priority table
| CVE | Component | CVSS | Practical attack path | Exploited? | Priority |
|---|---|---|---|---|---|
| CVE-2026-81963 | Windows Update Stack | 7.8 | Local code execution to higher privilege | Yes | Emergency |
| CVE-2026-85880 | Windows ALPC | 7.8 | Local/sandboxed code to higher privilege | Yes | Emergency |
| CVE-2026-69730 | Windows DNS Server | 9.8 | Unauthenticated network RCE | Not listed in KEV at publication | Emergency on DNS servers |
| CVE-2026-69845 | Windows DHCP Server | 9.8 | Unauthenticated network RCE | Not listed in KEV at publication | Emergency on DHCP servers |
Do not sort this table only by the largest number. A 7.8 vulnerability with observed exploitation may be more urgent than a 9.8 vulnerability on a machine which does not run the affected role. Good prioritisation combines exploitation evidence, reachability, privilege gained and asset value.
First, establish what you actually run
Open an elevated PowerShell window and collect the product, release and full build:
$cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
[PSCustomObject]@{
Computer = $env:COMPUTERNAME
ProductName = $cv.ProductName
DisplayVersion = $cv.DisplayVersion
Build = "$($cv.CurrentBuild).$($cv.UBR)"
}
Example:
Computer : DC-02
ProductName : Windows Server 2022 Standard
DisplayVersion : 21H2
Build : 20348.5622
The revision after the dot matters. “We installed some September updates” is not proof. A full build at or above Microsoft's fixed build is proof, provided the machine has rebooted where the update requires it.
Useful September 2026 servicing levels for common systems are:
| Operating system | September cumulative update | Serviced build |
|---|---|---|
| Windows 11 24H2 | KB5124008 | 26100.9445 |
| Windows 11 25H2 | KB5124008 | 26200.9445 |
| Windows 10 21H2 | KB5122878 | 19044.7725 |
| Windows 10 22H2 | KB5122878 | 19045.7725 |
| Windows Server 2019 | KB5122876 | 17763.9245 |
| Windows Server 2022 | KB5122882 | 20348.5622 |
| Windows Server 2025 | KB5122871 | 26100.33438 |
Microsoft's September Windows Server image list independently shows the Server 2019, 2022 and 2025 KB/build pairs. For older supported or ESU products, hotpatch variants and architectures, use the security-update table in the relevant MSRC CVE page rather than guessing from a neighbouring Windows version. Later cumulative updates supersede these September builds.
CVE-2026-81963: Windows Update Stack link-following zero-day
CVE-2026-81963 is a link-following weakness in the Windows Update Stack. An attacker who can already run code as a low-privileged local user may be able to manipulate filesystem links so that a more privileged component accesses an unintended location. NVD records Microsoft's 7.8 vector as local, low complexity, low privileges and no user interaction.
The important phrase is “already run code”. This is not a magic packet from the Internet. It is an excellent second stage after a malicious installer, a stolen user session or another initial-access flaw:
malicious file or stolen session
↓
low-privileged code execution
↓
CVE-2026-81963
↓
SYSTEM-level control
↓
credentials, persistence, lateral movement
CISA's KEV entry says exploitation can elevate to SYSTEM. It was added on 8 September, so a machine below the applicable servicing level should be treated as exposed rather than merely “theoretically vulnerable”.
What to do
- Deploy the 8 September cumulative security update, or a later superseding update, to affected Windows 11 and Windows Server 2025 systems listed by Microsoft.
- Reboot when required. Microsoft's September 2026 Windows 11 and Server 2025 baselines are standard updates and require restart for some security changes.
- Verify the full build after the reboot.
- Prioritise administrative workstations, jump hosts, developer machines and servers permitting interactive logon.
There is no configuration toggle which provides the same correction as the security update. If an emergency prevents immediate patching, reduce interactive access, block execution from user-writable locations with your application-control platform, and make low-privileged code execution harder. Those are seatbelts; the update repairs the brakes.
CVE-2026-85880: ALPC heap overflow under active exploitation
Windows Advanced Local Procedure Call, or ALPC, is a low-level mechanism used by Windows processes to communicate. CVE-2026-85880 is a heap-based buffer overflow in ALPC. NVD records the same 7.8 local privilege-escalation vector: local attack, low complexity, low privileges and no user interaction.
The flaw matters because a restricted application or low-privileged foothold is not where an intruder wants to remain. Privilege escalation turns a small problem into a system-wide one. CISA added the CVE to KEV on the day the fix arrived and describes exploitation as local privilege escalation.
Practical remediation
Install the applicable September cumulative update or later on every affected product in Microsoft's CVE table. Examples include:
Windows Server 2019 → 17763.9245 or later
Windows Server 2022 → 20348.5622 or later
Windows 10 21H2 → 19044.7725 or later
Windows 10 22H2 → 19045.7725 or later
Until deployment is complete:
- remove unnecessary interactive and Remote Desktop logon rights from servers;
- restrict unsigned or unapproved binaries in
%TEMP%,%APPDATA%and downloads; - give shared workstations, RDS hosts and admin endpoints the highest priority;
- alert on an ordinary user process followed by a new SYSTEM process, service or scheduled task;
- preserve endpoint telemetry from before the patch rather than assuming that successful installation erases evidence of an earlier compromise.
CVE-2026-69730: unauthenticated Windows DNS Server RCE
CVE-2026-69730 is a use-after-free in Windows DNS Server. Microsoft's CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, producing a 9.8 Critical score. In plain English: the vulnerable component is network reachable, the attack requires neither credentials nor a helpful employee, and successful exploitation may affect confidentiality, integrity and availability. See the NVD record and Microsoft advisory.
The operational risk is concentrated on machines that actually run Windows DNS Server and accept traffic from the attacker's position. In many Active Directory environments that service runs on a domain controller. That is not an especially charming place to test one's luck.
Is the DNS role present and reachable?
Run on Windows Server:
Get-WindowsFeature DNS
Get-Service DNS -ErrorAction SilentlyContinue
Get-NetUDPEndpoint -LocalPort 53 -ErrorAction SilentlyContinue
Get-NetTCPConnection -LocalPort 53 -State Listen -ErrorAction SilentlyContinue
Then summarise the host:
$cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
$dns = Get-Service DNS -ErrorAction SilentlyContinue
[PSCustomObject]@{
Computer = $env:COMPUTERNAME
OS = $cv.ProductName
Build = "$($cv.CurrentBuild).$($cv.UBR)"
DNSPresent = [bool]$dns
DNSStatus = if ($dns) { $dns.Status } else { 'Not installed' }
}
Example:
Computer : DC-02
OS : Windows Server 2022 Standard
Build : 20348.5500
DNSPresent : True
DNSStatus : Running
That host is below the September Server 2022 build 20348.5622, runs DNS and should be patched immediately.
Containment while the change window is being opened
- Block unsolicited TCP and UDP port 53 from the Internet and other untrusted zones.
- Permit queries only from networks and forwarders which genuinely need the service.
- Do not make an Active Directory-integrated DNS server double as an unrestricted public authoritative server.
- Remove the DNS role if it is obsolete rather than preserving it as a museum exhibit.
- Monitor service crashes and unexpected restarts, but do not treat their absence as proof that exploitation did not occur.
Review enabled DNS firewall rules:
Get-NetFirewallRule -Enabled True |
Where-Object DisplayName -Match 'DNS' |
Select-Object DisplayName,Direction,Action,Profile
Firewall restrictions reduce reachability. They do not repair the vulnerable memory handling. The supported remedy is the applicable Windows security update.
CVE-2026-69845: unauthenticated Windows DHCP Server RCE
CVE-2026-69845 is a heap-based buffer overflow in Windows DHCP Server. It carries the same 9.8 network vector: no privileges, low complexity and no user interaction. The NVD entry describes unauthorised network remote-code execution; Microsoft's product table is in the MSRC advisory.
At publication the CVE was not in CISA KEV. That means CISA had not listed evidence meeting its KEV criteria; it does not mean the flaw is harmless or that exploitation is impossible.
Is DHCP Server installed?
Get-WindowsFeature DHCP
Get-Service DHCPServer -ErrorAction SilentlyContinue
Get-NetUDPEndpoint -LocalPort 67 -ErrorAction SilentlyContinue
Collect a compact result:
$cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
$dhcp = Get-Service DHCPServer -ErrorAction SilentlyContinue
[PSCustomObject]@{
Computer = $env:COMPUTERNAME
OS = $cv.ProductName
Build = "$($cv.CurrentBuild).$($cv.UBR)"
DHCPPresent = [bool]$dhcp
DHCPStatus = if ($dhcp) { $dhcp.Status } else { 'Not installed' }
}
Do not assume an attacker must share the same physical Ethernet cable. DHCP relay agents can forward traffic across routed networks. Review relay destinations, ACLs and which less-trusted segments can ultimately reach the server.
If patching must briefly wait, allow DHCP traffic only from required client or relay paths, remove unused DHCP roles, segment infrastructure services, and alert on DHCP Server crashes or unexplained restarts. Then patch: containment is not a permanent exemption form.
Audit DNS and DHCP across a domain
On a server, check both roles locally:
Get-WindowsFeature DNS,DHCP |
Select-Object DisplayName,Name,InstallState
For a controlled list of servers, PowerShell remoting can collect the same facts centrally. Supply a reviewed server inventory; do not point administrative remoting at an unbounded address range.
$servers = Get-Content .\windows-servers.txt
Invoke-Command -ComputerName $servers -ScriptBlock {
$cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
$dns = Get-Service DNS -ErrorAction SilentlyContinue
$dhcp = Get-Service DHCPServer -ErrorAction SilentlyContinue
[PSCustomObject]@{
Computer = $env:COMPUTERNAME
OS = $cv.ProductName
Build = "$($cv.CurrentBuild).$($cv.UBR)"
DNS = if ($dns) { $dns.Status } else { 'Absent' }
DHCP = if ($dhcp) { $dhcp.Status } else { 'Absent' }
}
} | Export-Csv .\september-2026-windows-triage.csv -NoTypeInformation
The resulting CSV is useful, but it still needs three additional columns from your network and asset inventories: reachability, business criticality and patch owner. Vulnerability scanners are helpful; ownership is what gets the reboot approved.
Patch without losing the plot
A sensible enterprise sequence is:
- Patch actively exploited CVEs first. Prioritise systems affected by CVE-2026-81963 and CVE-2026-85880, especially admin endpoints and interactive servers.
- Patch DNS and DHCP infrastructure immediately. Start with domain controllers, servers reachable from less-trusted networks and DHCP servers fed by relays.
- Patch Internet-facing Microsoft services. The September release contains far more than these four CVEs.
- Complete the remaining Windows fleet. A selective four-CVE response is not the same as installing the full applicable cumulative update.
- Reboot and verify. The September baseline requires restarts on affected systems; a pending-reboot server is not a finished change.
Check installed hotfix history:
Get-HotFix |
Sort-Object InstalledOn -Descending |
Select-Object -First 15 HotFixID,InstalledOn
Then verify the build again. Get-HotFix can be incomplete for some servicing paths; the full build plus the applicable Microsoft update history is the stronger final check.
You can also inspect pending restart indicators:
$paths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\RebootPending',
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired'
)
$paths | ForEach-Object {
[PSCustomObject]@{
RegistryPath = $_
RebootPending = Test-Path $_
}
}
What to hunt for before declaring victory
Microsoft and CISA do not provide a single universal malicious hash, filename or IP address for the two exploited privilege-escalation bugs. That is normal: the vulnerabilities are techniques within an attack chain, not a complete campaign identity.
Review telemetry from the period before patch installation for:
- an ordinary user process spawning or being followed by a SYSTEM process;
- service creation, scheduled-task creation or new local administrators;
- binaries launched from
%TEMP%,%APPDATA%, downloads or other user-writable paths; - endpoint-protection tampering after suspicious low-privileged execution;
- credential dumping or lateral movement following an endpoint alert;
- unexplained DNS or DHCP service crashes and restarts;
- privileged logons from a host which had suspicious user-level activity.
Example Windows event pivots:
# Newly installed services — System event 7045
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-7)} |
Select-Object TimeCreated,MachineName,Message
# New processes if Security 4688 auditing is enabled
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=(Get-Date).AddDays(-2)} |
Select-Object TimeCreated,Id,Message
# Unexpected DNS and DHCP service events
Get-WinEvent -FilterHashtable @{LogName='System'; StartTime=(Get-Date).AddDays(-7)} |
Where-Object ProviderName -Match 'DNS|DHCP|Service Control Manager' |
Select-Object TimeCreated,ProviderName,Id,LevelDisplayName,Message
These queries produce leads, not verdicts. Normal software installs also create services; normal maintenance restarts services. Correlate with EDR process trees, administrator activity, change tickets and network telemetry. If evidence suggests active compromise, isolate the affected system through your approved incident process and preserve volatile and forensic data before rebuilding or cleaning it.
What “patched” should mean
A defensible closure record should contain:
[ ] Affected products and installed DNS/DHCP roles inventoried
[ ] Network and relay reachability reviewed
[ ] Applicable September update or later deployed
[ ] Required restart completed
[ ] Full OS build verified after restart
[ ] Failed and offline endpoints remediated or formally excepted
[ ] Pre-patch EDR/SIEM telemetry reviewed on high-value systems
[ ] Any suspicious findings handed to incident response
Do not close the ticket because the deployment console says “95% successful”. The remaining five per cent have a peculiar habit of containing the old server under someone's desk which runs payroll, door access and an undocumented fox sanctuary.
FAQ
Are the September 2026 flaws really being exploited?
Yes, for CVE-2026-81963 and CVE-2026-85880. CISA's KEV data marks both as known exploited vulnerabilities added on 8 September 2026. The DNS and DHCP CVEs were not in KEV at the time this article was prepared.
Does CVSS 9.8 mean every Windows machine is remotely exploitable?
No. The DNS and DHCP findings concern the affected server components. Practical exposure depends on whether the role is installed, running, vulnerable and reachable from the attacker's network position. The CVSS vector describes the vulnerable component, not your entire estate.
Is an internal-only DNS server safe enough to leave unpatched?
No. Restricted reachability lowers risk, but an intruder who has already compromised a workstation, VPN account or another internal system may reach infrastructure which the Internet cannot. Segmentation is useful defence in depth, not a substitute for the update.
Can antivirus block these vulnerabilities?
EDR or antivirus may detect parts of an exploitation chain or post-exploitation behaviour. It does not correct the vulnerable Windows code. Apply the operating-system security update.
Is a later cumulative update acceptable?
Yes. Windows cumulative updates supersede previous cumulative updates. Verify that the later build is applicable to the exact product and architecture, and that the required restart completed.
What if Windows Update reports “You're up to date”?
Record the exact product and build, compare it with the appropriate Microsoft update history, check for a pending restart, and investigate update-management rings, deferrals, WSUS approvals or servicing prerequisites. A friendly green tick is not an audit trail.
Bottom line
The September 2026 release is unusually large, but the response does not need to be theatrical:
Inventory the products and roles.
Map who can reach DNS and DHCP.
Patch the exploited elevation-of-privilege flaws.
Patch the network-facing server roles.
Reboot.
Verify the build.
Hunt backwards through pre-patch telemetry.
The two exploited CVEs show why CVSS alone cannot run a patch queue. The two 9.8 server flaws show why an accurate role and reachability inventory matters. Put those facts together and the priority becomes quite clear — even before the change meeting produces its customary ceremonial biscuits.
Primary sources
- Microsoft: September 2026 Security Updates release notes
- Microsoft Security Update Guide
- CISA Known Exploited Vulnerabilities catalogue
- CISA machine-readable KEV data
- NVD: CVE-2026-81963
- NVD: CVE-2026-85880
- NVD: CVE-2026-69730
- NVD: CVE-2026-69845
- Microsoft: KB5124008 for Windows 11 24H2 and 25H2
- Microsoft: KB5122878 for Windows 10 21H2 and 22H2
- Microsoft: September 2026 Windows Server images and build numbers