Virtual Administrator’s September 2026 Patch Recommendations

Patch Recommendations

We are delaying the release of Windows 11 25H2 CU KB5124008 – see “Heads Up!” below. All other patches will be approved in our patch policy.

This month Microsoft released patches for 974 vulnerabilities with 113 rated “Critical” in severity.

A whopping 974 vulnerabilities are addressed this month with two zero-day patches.

  • Actively exploited CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.
  • Another serious critical flaw is CVE-2026-69730 which addresses a DNS weakness in all versions of Windows workstations and servers.
  • CVE-2026-69829 is a remote code execution flaw in the Windows Shell garnishing a CVSS base score of 9.8.
  • CVE-2026-69590, CVE-2026-69579 and CVE-2026-69730 require no authentication or user interaction to be exploited.
  • New standalone SSUs for Windows 10 1607/Server 2016 and Server 2012/2012R2.

There are some problems with the Exchange and SQL Server patches – see “Known Issues” below.

Disclosed: none

Exploited: CVE-2026-81963, CVE-2026-85880

Security Update Guide

https://msrc.microsoft.com/update-guide/en-us

Microsoft Security Advisories

ADV990001 | Latest Servicing Stack Updates (Published:3/1/2018 | Last Updated: 9/8/2026)

https://msrc.microsoft.com/update-guide/en-us/vulnerability/ADV990001

Reason for Revision: A Servicing Stack Update has been released for some versions of Windows.

NOTE: The Windows 10 Security Stack Updates are included in the monthly Cumulative Updates.

Heads Up! Delayed release for Windows 11 25H2 CU KB5124008

We will monitor Microsoft’s progress fixing these bugs and release KB5124008 as soon as they are fixed. If no fix is available by September 18th we will likely release with guidance on workarounds for affected machines.

Windows 11 KB5124008 Is Breaking Always On VPN Connections

https://www.msn.com/en-xl/news/other/windows-11-kb5124008-is-breaking-always-on-vpn-connections/ar-AA2c1nYS?ocid=BingNewsSerp

Always On VPN fails after installing KB5124008 on Windows 11

https://learn.microsoft.com/en-us/answers/questions/5998351/always-on-vpn-fails-after-installing-kb5124008-on

KB5124008 Is Breaking Domain Logons on Windows 11 25H2 — What IT Admins Need to Know

https://endpointweekly.com/blog/kb5124008-machine-secure-channel-break-windows-11-25h2.html#fix

KB5124008 (26200.9445) breaks machine secure channel / domain trust — reproducible, Server 2019 DCs

https://learn.microsoft.com/en-us/answers/questions/5998917/kb5124008-26200-9445-breaks-machine-secure-channel

Known Issues

New known issues reported by Microsoft for Exchange Server and SQL Server.

Microsoft continues to list unresolved older problems under the Known Issues for new patches. So if you have not yet experienced one of these issues it is unlikely it will occur now.

Good resource for known issues with Windows 10/11/Server patches. Find the version and click on “Known issues”.

Windows release health

https://docs.microsoft.com/en-us/windows/release-health

Known issues with Exchange Server

“Published calendar (.ics) returns HTTP 500 for calendar applications”

Affected platforms: Exchange Server 2016 CU23, 2019 CU14/CU15, Subscription Edition RTM

“Availability (free/busy) fails for delegated mailboxes in Exchange hybrid deployments using Graph API only”

Affected platforms: Exchange Server Subscription Edition RTM

Published calendar (.ics) returns HTTP 500 for calendar applications

https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5126672

Symptom: After you install the August 2026 security update (Exchange Server SE, build 15.2.2562.46), subscriptions to an anonymously published Exchange calendar stop refreshing. The subscribing application reports a server error, and the URL returns HTTP 500.

Workaround: Add one URL Rewrite rule to the Exchange Back End site in IIS. The rule appends layout=premium to .ics requests below /owa/calendar/. This action selects the supported code path, and restores the feed.

Availability (free/busy) fails for delegated mailboxes in Exchange hybrid deployments using Graph API only

https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5127092

Symptom: In a classic hybrid deployment that’s configured by using ConfigureExchangeHybridApplication.ps1 -UseGraphApiOnly, availability (free/busy) information fails when a remote mailbox user accesses a delegated on-premises mailbox and checks the availability of mailboxes that are hosted in Exchange Online.

Resolution: To work around this issue:

1) To route the calls through EWS, enable the following override:

Set-SettingOverride -Identity EnableRouteThroughMSGraphFeature -Parameters "Enabled=False"

2) To apply the changes immediately, run the following command:

Get-ExchangeDiagnosticInfo -Process Microsoft.Exchange.Directory.TopologyService -Component VariantConfiguration -Argument Refresh

Known issue with SQL Server

“Linked server queries that use MSDASQL fail with error 7416”

Affected platforms: Microsoft SQL Server 2019 (CU 32), 2022 (CU26)/(GDR), 2025 (CU8)/(GDR) and Linux SQL Server 2017 (CU31)/(GDR), 2019 (GDR)

KBs: 5122768, 5122769, 5122770, 5122771, 5122772, 5122773, 5122774, 5122775

Symptom: Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

Msg 7416, Level 16 Access to the remote server is denied because no login-mapping exists.

A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

Workaround: Linked server queries that use MSDASQL fail with error 7416

https://learn.microsoft.com/troubleshoot/sql/database-engine/linked-servers/msdasql-query-error-7416

Monthly Rollup/Security Only/Windows 10,11/Server 2016,2019,2022,2025 KBs

Links are https://support.microsoft.com/en-us/help/####### with the KB number only.

Security and Quality Rollup

  • KB5123066 – Windows Server 2012 R2 (ESU)
  • KB5123065 – Windows Server 2012 (ESU)

Cumulative Updates

Windows 10

  • KB5122878 – Version 21H2 “November 2021 Update” (OS Build 19044) (ESU)
  • KB5122878 – Version 22H2 “November 2022 Update” (OS Build 19045) (ESU)

(Versions 1507,1511,1607,1703,1709,1803,1809,1903,1909,2004,20H2,21H1 are no longer under support)

Windows 11

  • KB5122880 – 23H2 (OS Build 22631)
  • KB5124008 – 24H2 (OS Build 26100)
  • KB5124008 – 25H2 (OS Build 26200)
  • KB5124012 – 26H1 (OS Build 28000)

(Version 21H2,22H2 are no longer under support)

Windows Server

  • KB5123099 – Server 2016 (EOS January 2027)
  • KB5122876 – Server 2019 (EOS January 2029)
  • KB5122882 – Server 2022 (OS Build 20348)
  • KB5122871 – Server 2025 (OS Build 26100)

September 2026 updates for Microsoft Office

https://support.microsoft.com/en-us/servicing/office/5127194

Notable CVEs

CVE-2026-69590 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590

An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.

CVE-2026-69579 | Windows Message Queuing Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579

An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.

CVE-2026-69730 | Windows DNS Server Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730

An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.

CVE-2026-69829 | Windows Shell Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69829

Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability (Cumulative Update)

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963

Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability (Cumulative Update/Monthly Rollup)

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.