Virtual Administrator’s September 2026 Patch Recommendations
We are delaying the release of Windows 11 25H2 CU KB5124008 – see “Heads Up!” below. All other patches will be approved in our patch policy.
This month Microsoft released patches for 974 vulnerabilities with 113 rated “Critical” in severity.
A whopping 974 vulnerabilities are addressed this month with two zero-day patches.
- Actively exploited CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.
- Another serious critical flaw is CVE-2026-69730 which addresses a DNS weakness in all versions of Windows workstations and servers.
- CVE-2026-69829 is a remote code execution flaw in the Windows Shell garnishing a CVSS base score of 9.8.
- CVE-2026-69590, CVE-2026-69579 and CVE-2026-69730 require no authentication or user interaction to be exploited.
- New standalone SSUs for Windows 10 1607/Server 2016 and Server 2012/2012R2.
There are some problems with the Exchange and SQL Server patches – see “Known Issues” below.
Disclosed: none
Exploited: CVE-2026-81963, CVE-2026-85880
Security Update Guide
https://msrc.microsoft.com/update-guide/en-us
Microsoft Security Advisories
ADV990001 | Latest Servicing Stack Updates (Published:3/1/2018 | Last Updated: 9/8/2026)
https://msrc.microsoft.com/update-guide/en-us/vulnerability/ADV990001
Reason for Revision: A Servicing Stack Update has been released for some versions of Windows.
NOTE: The Windows 10 Security Stack Updates are included in the monthly Cumulative Updates.
Heads Up! Delayed release for Windows 11 25H2 CU KB5124008
We will monitor Microsoft’s progress fixing these bugs and release KB5124008 as soon as they are fixed. If no fix is available by September 18th we will likely release with guidance on workarounds for affected machines.
Windows 11 KB5124008 Is Breaking Always On VPN Connections
Always On VPN fails after installing KB5124008 on Windows 11
KB5124008 Is Breaking Domain Logons on Windows 11 25H2 — What IT Admins Need to Know
https://endpointweekly.com/blog/kb5124008-machine-secure-channel-break-windows-11-25h2.html#fix
KB5124008 (26200.9445) breaks machine secure channel / domain trust — reproducible, Server 2019 DCs
Known Issues
New known issues reported by Microsoft for Exchange Server and SQL Server.
Microsoft continues to list unresolved older problems under the Known Issues for new patches. So if you have not yet experienced one of these issues it is unlikely it will occur now.
Good resource for known issues with Windows 10/11/Server patches. Find the version and click on “Known issues”.
Windows release health
https://docs.microsoft.com/en-us/windows/release-health
Known issues with Exchange Server
“Published calendar (.ics) returns HTTP 500 for calendar applications”
Affected platforms: Exchange Server 2016 CU23, 2019 CU14/CU15, Subscription Edition RTM
“Availability (free/busy) fails for delegated mailboxes in Exchange hybrid deployments using Graph API only”
Affected platforms: Exchange Server Subscription Edition RTM
Published calendar (.ics) returns HTTP 500 for calendar applications
https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5126672
Symptom: After you install the August 2026 security update (Exchange Server SE, build 15.2.2562.46), subscriptions to an anonymously published Exchange calendar stop refreshing. The subscribing application reports a server error, and the URL returns HTTP 500.
Workaround: Add one URL Rewrite rule to the Exchange Back End site in IIS. The rule appends layout=premium to .ics requests below /owa/calendar/. This action selects the supported code path, and restores the feed.
Availability (free/busy) fails for delegated mailboxes in Exchange hybrid deployments using Graph API only
https://support.microsoft.com/en-us/servicing/exchange/server/update/2026/5127092
Symptom: In a classic hybrid deployment that’s configured by using ConfigureExchangeHybridApplication.ps1 -UseGraphApiOnly, availability (free/busy) information fails when a remote mailbox user accesses a delegated on-premises mailbox and checks the availability of mailboxes that are hosted in Exchange Online.
Resolution: To work around this issue:
1) To route the calls through EWS, enable the following override:
Set-SettingOverride -Identity EnableRouteThroughMSGraphFeature -Parameters "Enabled=False"
2) To apply the changes immediately, run the following command:
Get-ExchangeDiagnosticInfo -Process Microsoft.Exchange.Directory.TopologyService -Component VariantConfiguration -Argument Refresh
Known issue with SQL Server
“Linked server queries that use MSDASQL fail with error 7416”
Affected platforms: Microsoft SQL Server 2019 (CU 32), 2022 (CU26)/(GDR), 2025 (CU8)/(GDR) and Linux SQL Server 2017 (CU31)/(GDR), 2019 (GDR)
KBs: 5122768, 5122769, 5122770, 5122771, 5122772, 5122773, 5122774, 5122775
Symptom: Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:
Msg 7416, Level 16 Access to the remote server is denied because no login-mapping exists.
A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.
Workaround: Linked server queries that use MSDASQL fail with error 7416
https://learn.microsoft.com/troubleshoot/sql/database-engine/linked-servers/msdasql-query-error-7416
Monthly Rollup/Security Only/Windows 10,11/Server 2016,2019,2022,2025 KBs
Links are https://support.microsoft.com/en-us/help/####### with the KB number only.
Security and Quality Rollup
- KB5123066 – Windows Server 2012 R2 (ESU)
- KB5123065 – Windows Server 2012 (ESU)
Cumulative Updates
Windows 10
- KB5122878 – Version 21H2 “November 2021 Update” (OS Build 19044) (ESU)
- KB5122878 – Version 22H2 “November 2022 Update” (OS Build 19045) (ESU)
(Versions 1507,1511,1607,1703,1709,1803,1809,1903,1909,2004,20H2,21H1 are no longer under support)
Windows 11
- KB5122880 – 23H2 (OS Build 22631)
- KB5124008 – 24H2 (OS Build 26100)
- KB5124008 – 25H2 (OS Build 26200)
- KB5124012 – 26H1 (OS Build 28000)
(Version 21H2,22H2 are no longer under support)
Windows Server
- KB5123099 – Server 2016 (EOS January 2027)
- KB5122876 – Server 2019 (EOS January 2029)
- KB5122882 – Server 2022 (OS Build 20348)
- KB5122871 – Server 2025 (OS Build 26100)
September 2026 updates for Microsoft Office
https://support.microsoft.com/en-us/servicing/office/5127194
Notable CVEs
CVE-2026-69590 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590
An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.
CVE-2026-69579 | Windows Message Queuing Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579
An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.
CVE-2026-69730 | Windows DNS Server Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730
An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.
CVE-2026-69829 | Windows Shell Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69829
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability (Cumulative Update)
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability (Cumulative Update/Monthly Rollup)
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.