Action1 5 Patch Tuesday 5 September 2026 Patch Tuesday Brief: Start With Exposure, Not the Patch Count

September 2026 Patch Tuesday Brief: Start With Exposure, Not the Patch Count

Published:
September 8, 2026
Last Updated:
September 8, 2026

By Jack Bicer

First 200 endpoints free, no feature limits.

No credit card required, full access to all features.

September 2026 Patch Tuesday: What Sysadmins Should Patch First

September is a heavy patching month, but the real challenge is not the raw vulnerability count. It is deciding which systems create the clearest path to compromise in your environment.

Microsoft’s September release covers 995 vulnerabilities, including 119 rated Critical and two Important zero-days under active exploitation. The most serious risks are concentrated around Windows endpoints, network-reachable infrastructure, identity services, virtualization, databases, and other business-critical systems.

For patch administrators, the useful question is simple: Does this affect my environment, and where should I start?

 

This month at a glance

  • Two actively exploited Windows privilege-escalation zero-days should move to the front of endpoint deployment.
  • Critical unauthenticated RCE affects infrastructure services including DNS, DHCP, failover clustering, NFS, and other Windows components.
  • Hyper-V, SQL Server, Windows Hello, and identity-related services deserve accelerated attention where they support important workloads.
  • Third-party risk is significant, with actively exploited or public-exploit issues affecting products including Fortinet FortiOS and Progress LoadMaster.
  • Do not treat every Critical vulnerability equally. Exposure, authentication requirements, business role, and attack path should determine what moves first.

 

Explore the full September Patch Tuesday release

Use Patch Tuesday Watch to move from this prioritization brief to the actual vulnerability data. Review Microsoft and third-party vulnerabilities, filter updates by Deployment Urgency or application, and drill into individual CVE details.

Explore September Patch Tuesday →

Using Action1 Deployment Colors

With 995 Microsoft vulnerabilities plus the month’s third-party updates, severity alone does not tell you what should move first. Action1 Deployment Colors turn vulnerability information into an operational deployment signal. The same Deployment Urgency ratings are used across Patch Tuesday Watch and our Microsoft and third-party vulnerability overviews, where you can filter updates by urgency and application.

  • 🟥 Red: Zero-day vulnerabilities. Immediate deployment.
  • 🟪 Purple: Critical vulnerabilities. Same day deployment.
  • 🟦 Blue: High-severity RCE or elevation-of-privilege vulnerabilities. Expedited deployment.
  • 🟨 Yellow: Other High and Medium vulnerabilities. Important deployment.
  • 🟩 Green: Low-severity vulnerabilities. Deploy based on your environment.

The colors are a starting point, not a substitute for knowing your systems. Filter September’s vulnerabilities by Deployment Urgency, then compare the results against what is actually deployed in your environment. A Purple vulnerability on an isolated lab machine may be less urgent than the same flaw on a production server reachable across the network.

 

Start with the environment you actually manage

If you manage Look at first Why
Identity infrastructure Kerberos, Netlogon, KDC, Windows Hello, identity-related services These systems protect trust boundaries and can turn an existing foothold into deeper access.
Windows endpoints The two exploited privilege-escalation zero-days, then Office, graphics, media, and Windows Shell fixes Endpoints combine active exploitation with common user-driven attack paths.
Business servers DNS, DHCP, Hyper-V, SQL Server, NFS, failover clusters, Dynamics 365 Several vulnerabilities provide network-reachable or high-impact code-execution paths.
Third-party and edge systems Oracle, LoadMaster, SAP, VMware Cloud Foundation, Cisco and other exposed appliances Internet-facing infrastructure can provide attackers a direct entry point, and several third-party issues have exploit activity or public exploit code.

 

Finding 1: Active exploitation changes the endpoint queue

Two Windows vulnerabilities deserve immediate attention because exploitation has already been detected.

CVE-2026-85880, in Windows ALPC, can let an attacker with low-privilege local code execution escape an AppContainer and reach SYSTEM privileges. CVE-2026-81963, in the Windows Update Stack, can also let a low-privilege attacker elevate to SYSTEM. Both require an attacker to have some local access first, but that is exactly why they matter operationally: they can turn a limited compromise into full control without additional user interaction.

For sysadmins, Red deployment should therefore begin with endpoint groups where compromise would have the greatest consequence, including administrator workstations and systems with access to sensitive resources.

 

Finding 2: Reachable infrastructure deserves its own fast lane

The September release contains multiple Critical RCE vulnerabilities where authentication or user interaction is not required. The affected areas include DNS, DHCP, failover clustering, Internet Connection Sharing, HTTP Print Provider, NFS, and other Windows services.

That makes network reachability one of the most useful sorting tools this month.

Do not wait for every server to move through one identical patch ring. Identify which vulnerable services are actually enabled and reachable. A server providing DNS or DHCP to a large part of the organization carries a different operational risk than a system where the affected component is unused.

Virtualization belongs in the same discussion. CVE-2026-80083 can allow specially crafted code running in a Hyper-V guest to reach arbitrary code execution on the host. For environments that consolidate important workloads, the host can represent a much larger blast radius than a single VM.

 

Finding 3: Your September queue does not end with Microsoft

Patch Tuesday can create tunnel vision around Windows, but the third-party report shows several systems that should compete for the same maintenance windows.

Fortinet reports real-world exploitation of two FortiOS and FortiProxy authentication-bypass vulnerabilities that can provide super-admin privileges. Progress LoadMaster has a Critical unauthenticated command-injection vulnerability with public proof-of-concept exploit code. The report also highlights Critical issues across SAP, VMware Cloud Foundation, Cisco networking platforms, Linux, cPanel, Flowise, and many other products.

For administrators responsible for edge devices or management platforms, these systems should be reviewed alongside Microsoft infrastructure, not after endpoint patching is complete.

Review September third-party vulnerabilities →
Filter by application or Deployment Urgency to identify the updates relevant to your environment.

 

Deployment and verification checklist

  • Confirm which affected products, roles, and services are actually present.
  • Deploy Red updates immediately, then move Critical Purple systems through accelerated rings.
  • Prioritize reachable servers and security infrastructure before lower-exposure systems.
  • Include third-party edge, management, and infrastructure products in the same review.
  • After deployment, confirm update installation, required restarts, service health, authentication, core application access, and normal management connectivity.
  • Investigate failed or deferred systems and document anything that remains exposed.

 

Keep the queue tied to your environment

September’s volume is large, but the operational path is manageable once you sort by exploitation, reachability, privilege impact, and system role. Patch the systems that can give attackers the fastest route to control first, then work outward through the rest of the estate.

Ready to build your September deployment queue? Explore the full release in Patch Tuesday Watch

 

More September Patch Tuesday resources

Microsoft Patch Tuesday updates →
Review the full Microsoft release and filter vulnerabilities by Deployment Urgency or application.

Third-party vulnerability overview →
See this month’s vulnerabilities across security products, enterprise applications, infrastructure software, browsers, and more, with the same filtering options.

CISO recommendations →
See which vulnerabilities and infrastructure risks security leaders should prioritize for remediation.

Action1 CVE Library →
Look up affected versions, exploitability, remediation guidance, and other technical details for individual vulnerabilities.

See What You Can Do with Action1

 

Join our weekly LIVE demo “Patch Management That Just Works with Action1” to learn more

about Action1 features and use cases for your IT needs.

 

spiceworks logo
getapp logo review
software advice review
trustradius
g2 review
g2 review