Microsoft has released its September 2026 security updates, including fixes for two vulnerabilities it says are already being exploited. The update affects supported Windows and Microsoft products and should be treated as a priority rather than left until the next convenient maintenance window.
For most UK SMEs, the practical action is straightforward: confirm that Windows Update or your managed patching system has installed the September updates, restart devices where required and investigate any computers that remain behind.
What changed in Microsoft’s September 2026 security update?
Microsoft released the September security updates on 8 September 2026. The release covers Windows, Microsoft 365 Apps, Office, Entra ID, Exchange Server and a wide range of related Microsoft products.
The headline is not simply the unusually large number of vulnerabilities addressed. Microsoft has marked CVE-2026-81963 and CVE-2026-85880 as exploited, which means attacks have already been observed rather than being only theoretical possibilities.
Microsoft’s individual advisories are available through the Security Update Guide for CVE-2026-81963 and the Security Update Guide for CVE-2026-85880.
Why do the two actively exploited vulnerabilities matter?
An actively exploited vulnerability carries more urgency because attackers are already using it in real incidents. A computer does not become infected simply because it has not yet installed the update, but the longer it remains unpatched, the longer it stays exposed to a known attack route.
CVE-2026-85880 is a Windows privilege-escalation vulnerability. It could allow an attacker who has already gained limited access to move beyond those restrictions and obtain much greater control of the computer.
The second exploited issue, CVE-2026-81963, is also included in Microsoft’s September release. Businesses do not need to diagnose each vulnerability individually before acting: the supported and safest response is to deploy the relevant Microsoft updates and verify that installation completed successfully.
Who is affected?
Businesses using supported Windows PCs or other affected Microsoft software should check their update status. The precise patches offered depend on the Windows version, edition and Microsoft products installed on each device.
- Windows 11 desktops and laptops used by staff.
- Windows servers managed internally or by an IT provider.
- Computers running supported Microsoft Office or Microsoft 365 desktop applications.
- Remote and rarely used laptops that may not have connected long enough to complete updates.
- Devices held as spares or used only for occasional specialist work.
This does not mean every listed vulnerability affects every Microsoft 365 customer. Cloud services are maintained by Microsoft, while Windows computers and locally installed applications still need updates to reach each device.
What will users notice?
Most users should see a normal Windows update followed by a request to restart. Managed devices may install the update automatically according to their organisation’s patching policy.
The September Windows 11 update also contains quality fixes. Microsoft says the Windows 11 23H2 release includes a fix for Remote Desktop audio redirection and continues the rollout of updated Secure Boot certificates.
Microsoft has documented a known issue affecting some applications that share Windows host folders with Linux virtual machines using Plan9. This can affect specialised environments such as Windows Subsystem for Linux and Claude Cowork, but it is unlikely to affect an ordinary office PC.
What should businesses do now?
Confirm the update has installed across every managed computer, with particular attention to devices that are often switched off or used away from the office.
- Check patch reports. Review your RMM, Intune or Windows Update for Business reporting rather than assuming every device updated.
- Restart pending computers. A downloaded update may not provide full protection until installation and restart have completed.
- Find missing devices. Check laptops, spare machines and computers that have not reported into management recently.
- Prioritise exposed and important systems. Deal first with servers, administrator workstations and devices used to access sensitive business or financial information.
- Monitor failures. Investigate repeated update errors, low disk space and devices stuck on unsupported Windows versions.
- Keep endpoint protection active. Patching and endpoint detection protect against different parts of an attack and should be used together.
Our guide to unsupported Windows 10 computers explains why an operating system that no longer receives routine security fixes requires a separate upgrade or replacement plan.
What happens if you do nothing?
Unpatched devices remain exposed to vulnerabilities for which fixes and public identifiers now exist. Attackers can study released updates and use the differences to develop or improve exploits, so the risk does not disappear after Patch Tuesday.
A missed update may also create problems with cyber-insurance declarations, customer security questionnaires and compliance requirements if a business claims to apply critical security patches promptly.
Waiting can be reasonable for a short testing period on business-critical systems, but that should be a deliberate, monitored decision with a defined deployment date—not an update being ignored indefinitely.
Why this matters to a UK SME
Small firms rely on the same Windows and Microsoft applications as much larger organisations, but often have fewer people checking whether updates actually succeeded. One forgotten laptop or failed server patch can sit outside the normal process for weeks.
The important lesson is not the size of Microsoft’s monthly vulnerability count. It is that two of the issues were already being exploited when the fixes arrived. A reliable patching process should show which devices are protected, which need a restart and which require intervention.
Our managed IT support provides ongoing device monitoring and patch oversight for businesses that need reliable visibility across their Windows estate.
Microsoft 365 guidance
Patching is only one part of Microsoft 365 security
Concerned about your Microsoft 365 security or configuration? Talk to KES about your current setup and the areas you would like help with. We will discuss your requirements and recommend an appropriate next step.
Prefer a quick starting point? Complete the free Microsoft 365 Security Assessment →
Microsoft and security sources
- Microsoft Security Response Center: September 2026 security updates.
- Microsoft Security Update Guide: CVE-2026-85880.
- Microsoft Security Update Guide: CVE-2026-81963.
- Microsoft Support: September 2026 Windows 11 24H2 and 25H2 update.
- Canadian Centre for Cyber Security: September 2026 Microsoft security advisory.
Security guidance and known issues can change as Microsoft investigates new information. Check the live Microsoft release-health and Security Update Guide pages before making deployment decisions for specialist systems.
The important point
Microsoft’s September 2026 security update includes fixes for two vulnerabilities already being exploited. Check that supported Windows devices have installed the update, complete any required restarts and investigate computers that remain behind.
If you do not have reliable visibility across every business computer, contact KES and we can help you check the estate and close any patching gaps.