——
CriticalVULNERABILITIES

Microsoft September 2026 Patch Tuesday: two exploited zero-days and critical DNS/DHCP RCEs

Two exploited Windows privilege-escalation flaws entered CISA KEV while unauthenticated DNS and DHCP Server RCEs scored 9.8. Identify affected roles, verify builds, patch, contain exposure and hunt for pre-patch compromise.

Two exploited Windows privilege-escalation flaws entered CISA KEV while unauthenticated DNS and DHCP Server RCEs scored 9.8. Identify affected roles, verify builds, patch, contain exposure and hunt for pre-patch compromise.

MicrosoftPatch TuesdayWindows SecurityCVEZero-DayWindows ServerDNSDHCPCISA KEV

Microsoft's September 2026 Patch Tuesday is not a routine Tuesday with a slightly nervous reboot. Microsoft lists 974 Microsoft CVEs in the release, but four Windows flaws deserve the first page of the change calendar:

  • CVE-2026-81963 — Windows Update Stack elevation of privilege, already exploited;
  • CVE-2026-85880 — Windows ALPC elevation of privilege, already exploited;
  • CVE-2026-69730 — Windows DNS Server unauthenticated remote code execution, CVSS 9.8;
  • CVE-2026-69845 — Windows DHCP Server unauthenticated remote code execution, CVSS 9.8.

The first two were added to the CISA Known Exploited Vulnerabilities catalogue on 8 September 2026, with a remediation due date of 22 September for US federal civilian agencies. That deadline is not a universal law for everyone else, but it is a useful indication that this is an incident-prevention job, not a task for the next quarterly housekeeping weekend.

The other two flaws affect services which spend their lives accepting network packets. DNS is blamed for nearly everything already; this month, for once, it genuinely deserves the attention.

Scope note: this guide is defensive. It shows how to identify exposed roles, verify servicing levels, reduce reachability, deploy the official updates and investigate suspicious behaviour. It does not contain exploit code. Build and product coverage can change as Microsoft revises an advisory, so use the linked MSRC record as the final authority for each product.

The one-minute priority table

CVE Component CVSS Practical attack path Exploited? Priority
CVE-2026-81963 Windows Update Stack 7.8 Local code execution to higher privilege Yes Emergency
CVE-2026-85880 Windows ALPC 7.8 Local/sandboxed code to higher privilege Yes Emergency
CVE-2026-69730 Windows DNS Server 9.8 Unauthenticated network RCE Not listed in KEV at publication Emergency on DNS servers
CVE-2026-69845 Windows DHCP Server 9.8 Unauthenticated network RCE Not listed in KEV at publication Emergency on DHCP servers

Do not sort this table only by the largest number. A 7.8 vulnerability with observed exploitation may be more urgent than a 9.8 vulnerability on a machine which does not run the affected role. Good prioritisation combines exploitation evidence, reachability, privilege gained and asset value.

First, establish what you actually run

Open an elevated PowerShell window and collect the product, release and full build:

$cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'

[PSCustomObject]@{
    Computer       = $env:COMPUTERNAME
    ProductName    = $cv.ProductName
    DisplayVersion = $cv.DisplayVersion
    Build           = "$($cv.CurrentBuild).$($cv.UBR)"
}

Example:

Computer       : DC-02
ProductName    : Windows Server 2022 Standard
DisplayVersion : 21H2
Build          : 20348.5622

The revision after the dot matters. “We installed some September updates” is not proof. A full build at or above Microsoft's fixed build is proof, provided the machine has rebooted where the update requires it.

Useful September 2026 servicing levels for common systems are:

Operating system September cumulative update Serviced build
Windows 11 24H2 KB5124008 26100.9445
Windows 11 25H2 KB5124008 26200.9445
Windows 10 21H2 KB5122878 19044.7725
Windows 10 22H2 KB5122878 19045.7725
Windows Server 2019 KB5122876 17763.9245
Windows Server 2022 KB5122882 20348.5622
Windows Server 2025 KB5122871 26100.33438

Microsoft's September Windows Server image list independently shows the Server 2019, 2022 and 2025 KB/build pairs. For older supported or ESU products, hotpatch variants and architectures, use the security-update table in the relevant MSRC CVE page rather than guessing from a neighbouring Windows version. Later cumulative updates supersede these September builds.

CVE-2026-81963 is a link-following weakness in the Windows Update Stack. An attacker who can already run code as a low-privileged local user may be able to manipulate filesystem links so that a more privileged component accesses an unintended location. NVD records Microsoft's 7.8 vector as local, low complexity, low privileges and no user interaction.

The important phrase is “already run code”. This is not a magic packet from the Internet. It is an excellent second stage after a malicious installer, a stolen user session or another initial-access flaw:

malicious file or stolen session
             ↓
low-privileged code execution
             ↓
       CVE-2026-81963
             ↓
      SYSTEM-level control
             ↓
credentials, persistence, lateral movement

CISA's KEV entry says exploitation can elevate to SYSTEM. It was added on 8 September, so a machine below the applicable servicing level should be treated as exposed rather than merely “theoretically vulnerable”.

What to do

  1. Deploy the 8 September cumulative security update, or a later superseding update, to affected Windows 11 and Windows Server 2025 systems listed by Microsoft.
  2. Reboot when required. Microsoft's September 2026 Windows 11 and Server 2025 baselines are standard updates and require restart for some security changes.
  3. Verify the full build after the reboot.
  4. Prioritise administrative workstations, jump hosts, developer machines and servers permitting interactive logon.

There is no configuration toggle which provides the same correction as the security update. If an emergency prevents immediate patching, reduce interactive access, block execution from user-writable locations with your application-control platform, and make low-privileged code execution harder. Those are seatbelts; the update repairs the brakes.

CVE-2026-85880: ALPC heap overflow under active exploitation

Windows Advanced Local Procedure Call, or ALPC, is a low-level mechanism used by Windows processes to communicate. CVE-2026-85880 is a heap-based buffer overflow in ALPC. NVD records the same 7.8 local privilege-escalation vector: local attack, low complexity, low privileges and no user interaction.

The flaw matters because a restricted application or low-privileged foothold is not where an intruder wants to remain. Privilege escalation turns a small problem into a system-wide one. CISA added the CVE to KEV on the day the fix arrived and describes exploitation as local privilege escalation.

Practical remediation

Install the applicable September cumulative update or later on every affected product in Microsoft's CVE table. Examples include:

Windows Server 2019  → 17763.9245 or later
Windows Server 2022  → 20348.5622 or later
Windows 10 21H2      → 19044.7725 or later
Windows 10 22H2      → 19045.7725 or later

Until deployment is complete:

  • remove unnecessary interactive and Remote Desktop logon rights from servers;
  • restrict unsigned or unapproved binaries in %TEMP%, %APPDATA% and downloads;
  • give shared workstations, RDS hosts and admin endpoints the highest priority;
  • alert on an ordinary user process followed by a new SYSTEM process, service or scheduled task;
  • preserve endpoint telemetry from before the patch rather than assuming that successful installation erases evidence of an earlier compromise.

CVE-2026-69730: unauthenticated Windows DNS Server RCE

CVE-2026-69730 is a use-after-free in Windows DNS Server. Microsoft's CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, producing a 9.8 Critical score. In plain English: the vulnerable component is network reachable, the attack requires neither credentials nor a helpful employee, and successful exploitation may affect confidentiality, integrity and availability. See the NVD record and Microsoft advisory.

The operational risk is concentrated on machines that actually run Windows DNS Server and accept traffic from the attacker's position. In many Active Directory environments that service runs on a domain controller. That is not an especially charming place to test one's luck.

Is the DNS role present and reachable?

Run on Windows Server:

Get-WindowsFeature DNS
Get-Service DNS -ErrorAction SilentlyContinue
Get-NetUDPEndpoint -LocalPort 53 -ErrorAction SilentlyContinue
Get-NetTCPConnection -LocalPort 53 -State Listen -ErrorAction SilentlyContinue

Then summarise the host:

$cv  = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
$dns = Get-Service DNS -ErrorAction SilentlyContinue

[PSCustomObject]@{
    Computer   = $env:COMPUTERNAME
    OS         = $cv.ProductName
    Build      = "$($cv.CurrentBuild).$($cv.UBR)"
    DNSPresent = [bool]$dns
    DNSStatus  = if ($dns) { $dns.Status } else { 'Not installed' }
}

Example:

Computer   : DC-02
OS         : Windows Server 2022 Standard
Build      : 20348.5500
DNSPresent : True
DNSStatus  : Running

That host is below the September Server 2022 build 20348.5622, runs DNS and should be patched immediately.

Containment while the change window is being opened

  • Block unsolicited TCP and UDP port 53 from the Internet and other untrusted zones.
  • Permit queries only from networks and forwarders which genuinely need the service.
  • Do not make an Active Directory-integrated DNS server double as an unrestricted public authoritative server.
  • Remove the DNS role if it is obsolete rather than preserving it as a museum exhibit.
  • Monitor service crashes and unexpected restarts, but do not treat their absence as proof that exploitation did not occur.

Review enabled DNS firewall rules:

Get-NetFirewallRule -Enabled True |
    Where-Object DisplayName -Match 'DNS' |
    Select-Object DisplayName,Direction,Action,Profile

Firewall restrictions reduce reachability. They do not repair the vulnerable memory handling. The supported remedy is the applicable Windows security update.

CVE-2026-69845: unauthenticated Windows DHCP Server RCE

CVE-2026-69845 is a heap-based buffer overflow in Windows DHCP Server. It carries the same 9.8 network vector: no privileges, low complexity and no user interaction. The NVD entry describes unauthorised network remote-code execution; Microsoft's product table is in the MSRC advisory.

At publication the CVE was not in CISA KEV. That means CISA had not listed evidence meeting its KEV criteria; it does not mean the flaw is harmless or that exploitation is impossible.

Is DHCP Server installed?

Get-WindowsFeature DHCP
Get-Service DHCPServer -ErrorAction SilentlyContinue
Get-NetUDPEndpoint -LocalPort 67 -ErrorAction SilentlyContinue

Collect a compact result:

$cv   = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
$dhcp = Get-Service DHCPServer -ErrorAction SilentlyContinue

[PSCustomObject]@{
    Computer    = $env:COMPUTERNAME
    OS          = $cv.ProductName
    Build       = "$($cv.CurrentBuild).$($cv.UBR)"
    DHCPPresent = [bool]$dhcp
    DHCPStatus  = if ($dhcp) { $dhcp.Status } else { 'Not installed' }
}

Do not assume an attacker must share the same physical Ethernet cable. DHCP relay agents can forward traffic across routed networks. Review relay destinations, ACLs and which less-trusted segments can ultimately reach the server.

If patching must briefly wait, allow DHCP traffic only from required client or relay paths, remove unused DHCP roles, segment infrastructure services, and alert on DHCP Server crashes or unexplained restarts. Then patch: containment is not a permanent exemption form.

Audit DNS and DHCP across a domain

On a server, check both roles locally:

Get-WindowsFeature DNS,DHCP |
    Select-Object DisplayName,Name,InstallState

For a controlled list of servers, PowerShell remoting can collect the same facts centrally. Supply a reviewed server inventory; do not point administrative remoting at an unbounded address range.

$servers = Get-Content .\windows-servers.txt

Invoke-Command -ComputerName $servers -ScriptBlock {
    $cv = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
    $dns = Get-Service DNS -ErrorAction SilentlyContinue
    $dhcp = Get-Service DHCPServer -ErrorAction SilentlyContinue

    [PSCustomObject]@{
        Computer = $env:COMPUTERNAME
        OS       = $cv.ProductName
        Build    = "$($cv.CurrentBuild).$($cv.UBR)"
        DNS      = if ($dns) { $dns.Status } else { 'Absent' }
        DHCP     = if ($dhcp) { $dhcp.Status } else { 'Absent' }
    }
} | Export-Csv .\september-2026-windows-triage.csv -NoTypeInformation

The resulting CSV is useful, but it still needs three additional columns from your network and asset inventories: reachability, business criticality and patch owner. Vulnerability scanners are helpful; ownership is what gets the reboot approved.

Patch without losing the plot

A sensible enterprise sequence is:

  1. Patch actively exploited CVEs first. Prioritise systems affected by CVE-2026-81963 and CVE-2026-85880, especially admin endpoints and interactive servers.
  2. Patch DNS and DHCP infrastructure immediately. Start with domain controllers, servers reachable from less-trusted networks and DHCP servers fed by relays.
  3. Patch Internet-facing Microsoft services. The September release contains far more than these four CVEs.
  4. Complete the remaining Windows fleet. A selective four-CVE response is not the same as installing the full applicable cumulative update.
  5. Reboot and verify. The September baseline requires restarts on affected systems; a pending-reboot server is not a finished change.

Check installed hotfix history:

Get-HotFix |
    Sort-Object InstalledOn -Descending |
    Select-Object -First 15 HotFixID,InstalledOn

Then verify the build again. Get-HotFix can be incomplete for some servicing paths; the full build plus the applicable Microsoft update history is the stronger final check.

You can also inspect pending restart indicators:

$paths = @(
  'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\RebootPending',
  'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired'
)

$paths | ForEach-Object {
    [PSCustomObject]@{
        RegistryPath  = $_
        RebootPending = Test-Path $_
    }
}

What to hunt for before declaring victory

Microsoft and CISA do not provide a single universal malicious hash, filename or IP address for the two exploited privilege-escalation bugs. That is normal: the vulnerabilities are techniques within an attack chain, not a complete campaign identity.

Review telemetry from the period before patch installation for:

  • an ordinary user process spawning or being followed by a SYSTEM process;
  • service creation, scheduled-task creation or new local administrators;
  • binaries launched from %TEMP%, %APPDATA%, downloads or other user-writable paths;
  • endpoint-protection tampering after suspicious low-privileged execution;
  • credential dumping or lateral movement following an endpoint alert;
  • unexplained DNS or DHCP service crashes and restarts;
  • privileged logons from a host which had suspicious user-level activity.

Example Windows event pivots:

# Newly installed services — System event 7045
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-7)} |
    Select-Object TimeCreated,MachineName,Message

# New processes if Security 4688 auditing is enabled
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=(Get-Date).AddDays(-2)} |
    Select-Object TimeCreated,Id,Message

# Unexpected DNS and DHCP service events
Get-WinEvent -FilterHashtable @{LogName='System'; StartTime=(Get-Date).AddDays(-7)} |
    Where-Object ProviderName -Match 'DNS|DHCP|Service Control Manager' |
    Select-Object TimeCreated,ProviderName,Id,LevelDisplayName,Message

These queries produce leads, not verdicts. Normal software installs also create services; normal maintenance restarts services. Correlate with EDR process trees, administrator activity, change tickets and network telemetry. If evidence suggests active compromise, isolate the affected system through your approved incident process and preserve volatile and forensic data before rebuilding or cleaning it.

What “patched” should mean

A defensible closure record should contain:

[ ] Affected products and installed DNS/DHCP roles inventoried
[ ] Network and relay reachability reviewed
[ ] Applicable September update or later deployed
[ ] Required restart completed
[ ] Full OS build verified after restart
[ ] Failed and offline endpoints remediated or formally excepted
[ ] Pre-patch EDR/SIEM telemetry reviewed on high-value systems
[ ] Any suspicious findings handed to incident response

Do not close the ticket because the deployment console says “95% successful”. The remaining five per cent have a peculiar habit of containing the old server under someone's desk which runs payroll, door access and an undocumented fox sanctuary.

FAQ

Are the September 2026 flaws really being exploited?

Yes, for CVE-2026-81963 and CVE-2026-85880. CISA's KEV data marks both as known exploited vulnerabilities added on 8 September 2026. The DNS and DHCP CVEs were not in KEV at the time this article was prepared.

Does CVSS 9.8 mean every Windows machine is remotely exploitable?

No. The DNS and DHCP findings concern the affected server components. Practical exposure depends on whether the role is installed, running, vulnerable and reachable from the attacker's network position. The CVSS vector describes the vulnerable component, not your entire estate.

Is an internal-only DNS server safe enough to leave unpatched?

No. Restricted reachability lowers risk, but an intruder who has already compromised a workstation, VPN account or another internal system may reach infrastructure which the Internet cannot. Segmentation is useful defence in depth, not a substitute for the update.

Can antivirus block these vulnerabilities?

EDR or antivirus may detect parts of an exploitation chain or post-exploitation behaviour. It does not correct the vulnerable Windows code. Apply the operating-system security update.

Is a later cumulative update acceptable?

Yes. Windows cumulative updates supersede previous cumulative updates. Verify that the later build is applicable to the exact product and architecture, and that the required restart completed.

What if Windows Update reports “You're up to date”?

Record the exact product and build, compare it with the appropriate Microsoft update history, check for a pending restart, and investigate update-management rings, deferrals, WSUS approvals or servicing prerequisites. A friendly green tick is not an audit trail.

Bottom line

The September 2026 release is unusually large, but the response does not need to be theatrical:

Inventory the products and roles.
Map who can reach DNS and DHCP.
Patch the exploited elevation-of-privilege flaws.
Patch the network-facing server roles.
Reboot.
Verify the build.
Hunt backwards through pre-patch telemetry.

The two exploited CVEs show why CVSS alone cannot run a patch queue. The two 9.8 server flaws show why an accurate role and reachability inventory matters. Put those facts together and the priority becomes quite clear — even before the change meeting produces its customary ceremonial biscuits.

Primary sources