PT-2026-89285 · Undefined · Undefined
CVE-2026-74780
·
Published
2026-09-10
·
Updated
2026-09-10
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Today is Patch Tuesday and it's a significant one. 966 vulnerabilities patched in the official count, with another 204 fixed separately earlier in September across Azure, Entra ID, Edge, and Copilot Studio. By any count this is the biggest single security release Microsoft has ever shipped.
Two of those are actively exploited zero-days: CVE-2026-81963 in the Windows Update Stack lets a low-privilege attacker reach SYSTEM level (ZDI notes it's almost certainly being chained with a remote code execution bug since local access is needed first), and CVE-2026-74780 in Windows ALPC follows the same pattern. Both are on CISA's Known Exploited list as of today.
Here's the counterintuitive part. Dustin Childs at Zero Day Initiative, who has been analyzing Patch Tuesdays longer than most people have worked in security, says the two exploited zero-days are not where you should be looking first.
What he's actually flagging are two things: the Exchange Server RCE (CVE-2026-55007, CVSS 8.1) and 20 vulnerabilities he's classifying as wormable. On Exchange: an unauthenticated remote attacker gets code execution on an affected server just by sending a maliciously crafted email. The server receives the email, the attacker gets in. No credentials, no user interaction, nothing.
On the 20 wormable bugs: these span DNS Server, DHCP Server, Active Directory, SMB Client, Netlogon, NFS, RRAS, Message Queuing, Failover Cluster, and others. Every single one allows a remote unauthenticated attacker to execute code with no user interaction. "We haven't seen a global worm in years," Childs wrote, "but with a DNS flaw acting as the spiritual successor to SigRed, that reality could change fast."
The DNS flaw he's referring to is CVE-2026-69730 (CVSS 9.8). SigRed in 2020 was a critical Windows DNS Server flaw that sat undetected for 17 years and would have allowed worm-like propagation across enterprise networks if it had been weaponized before discovery. This one draws the same comparison.
Two more worth flagging specifically for enterprise environments: CVE-2026-69676 is a Kerberos authentication bypass where any authenticated domain user can send a crafted request and execute code on a domain controller with no further privilege needed. And Microsoft also patched a flaw in the Android Microsoft Authenticator app where a malicious app can intercept valid authentication tokens after a user completes an auth step, which has obvious implications for any environment using Authenticator for MFA.
Practical prioritization from Childs and Tenable: Exchange Server and the 20 wormable bugs first, then the actively exploited zero-days, then Kerberos. The zero-days sound scarier but require local access first. A wormable unauthenticated DNS bug or an email that lands you on Exchange is a different threat model entirely.
Sources: BleepingComputer, Help Net Security, ZDI September 2026 Patch Tuesday review, Security Affairs, TechTimes, Tenable
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined