← Back to blog
Security

Patch Tuesday September 2026: 974 CVEs, two zero-days and Administrator Protection as a new security model

By Zarioh Digital Solutions6 min read
Share
Patch Tuesday September 2026: 974 CVEs, two zero-days and Administrator Protection as a new security model

Microsoft closed September with a record round: 974 vulnerabilities patched, including two actively exploited zero-days in Windows Update Stack and ALPC. The same update also introduces Administrator Protection — a fundamentally new model for admin rights through just-in-time elevation. Here is what you need to do this week.

On 8 September 2026, Microsoft released its Patch Tuesday for September — and it was a record round. Almost 974 vulnerabilities were patched, spread across Windows, Office, Azure, Exchange, SQL Server, and dozens of other products. Among them are two zero-days that were already being actively exploited in attacks at the time of release. For IT teams, this means there is no time to waste.

But the urgency of the patches shares attention with a second novelty that shipped in the same update cycle: Administrator Protection. This new Windows 11 feature fundamentally rethinks how admin rights work on the endpoint. Organisations that patch now can simultaneously activate an important new security model.

The two zero-days: what you need to know

Both actively exploited vulnerabilities carry a CVSS score of 7.8 and fall in the elevation of privilege category — the attack class where an attacker who has already gained a foothold within a system escalates to SYSTEM privileges. That is precisely the mechanism used by ransomware groups and APT actors after an initial infection has taken hold.

CVE-2026-81963 affects the Windows Update Stack, the subsystem responsible for retrieving and installing updates. An improper handling of symbolic links makes it possible to redirect file operations to protected locations. CVE-2026-85880 resides in the Windows Advanced Local Procedure Call mechanism, a core component for inter-process communication. A heap buffer overflow in that channel gives a local attacker the ability to obtain SYSTEM privileges.

Both vulnerabilities require local presence — they cannot be exploited directly from the internet. That makes them ideal as a second step: a phishing email provides the initial foothold, the zero-day handles the escalation. Together, both CVEs make a full system takeover realistic, even on well-secured machines.

No hotpatch this month: restart required

Organisations that have relied on Windows Autopatch or Hotpatch to install updates without a restart will need to plan differently this month. The September 2026 update contains changes to core Windows components that cannot be delivered via hotpatching. The update requires a full restart.

For environments with high availability requirements — think call centres, production planning, or 24/7 services — this requires coordination. Hotpatch months and standard months alternate; September is a standard month. Schedule restarts within the next seven days, preferably outside peak hours. Microsoft reports no known issues with this update.

Deploying via Intune: Update Rings as the best approach

For organisations using Intune, there are two deployment paths. Update Rings are the traditional method: you define per ring a deferral period, a deadline, and a grace period for restarts. A typical setup is a pilot ring of five to ten devices with no deferral, an early adopter ring with a two-day deferral, and a production ring with a five-day deferral and a deadline of seven days after that deferral period.

The second option is Windows Autopatch, which automatically manages a phased rollout based on device groups. For organisations that have already configured Autopatch, the rollout proceeds largely automatically; however, verify that the Test and First rings have received the update and that no issues are reported via the Autopatch dashboard.

Both deployment paths lead to the same outcome: devices receive KB5124008 (Windows 11 24H2) or KB5122880 (Windows 11 23H2) and restart within the configured window. After the rollout, use the Intune compliance report to identify devices that have not yet received the update; pay special attention to devices that have been offline for an extended period.

Administrator Protection: just-in-time admin rights for Windows 11

The second novelty in the September update is less urgent but at least as significant in the longer term: Administrator Protection. This feature addresses a structural problem that has existed in Windows for decades. On a standard Windows device, users work with an account that has admin rights via the familiar UAC system. When an application requests elevated privileges, a single click on 'Yes' is enough to grant them.

Administrator Protection replaces that model with a just-in-time approach. When an action requires admin rights, Windows temporarily creates an isolated management environment, performs the operation with the necessary privileges, and then cleans up the environment. The privileges are never permanently present in the user process. Malware running in the user context can no longer bypass the UAC prompt using well-known techniques such as DLL hijacking or COM elevation.

The feature is off by default and must be explicitly enabled. That is a deliberate choice by Microsoft: the impact on applications that assume admin rights are continuously available can vary. Rolling it out without preparation in a production environment is not recommended.

Enabling Administrator Protection via Intune

There are two ways to activate Administrator Protection via Intune. The first is via an OMA-URI configuration profile. Create a new device configuration policy, select Custom as the profile type, and add the URI for the CSP setting that enables Administrator Protection. Assign this profile to a pilot group of devices, preferably with well-informed users who can flag any application issues.

The second method is via the Endpoint Security section in Intune, under the Security Catalog. Here you will find a configuration item specifically for Administrator Protection that you can include in an existing or new security policy. Both methods are functionally equivalent; the Security Catalog approach is preferred because it is less error-prone than manually entering an OMA-URI path.

Start the rollout on a small group of devices, monitor for one to two weeks whether users report applications freezing or failing unexpectedly, then expand gradually. Applications that demand admin access in ways that fall outside certified channels will be blocked. That can be surprising, but is in most cases a security win: those applications were doing something they should not have been.

What is on your action list this week?

Three priorities for the next seven days. First: release the September update in Intune to the pilot ring today. The two zero-days are being actively exploited and every day of delay widens the attack window. A phased rollout of ten devices as a pilot is sufficient to detect any issues before the broad production rollout.

Second: identify devices that have been offline for more than two weeks and contact their users. Devices that do not receive the update because they are offline remain vulnerable. For critical devices, a rollout day outside office hours with a forced restart is the only reliable approach.

Third: evaluate whether Administrator Protection is suitable for a pilot role in your organisation. Start small, document which applications cause issues, and recognise that the feature represents a fundamental step forward for endpoint security. Organisations that start the pilot now will be able to roll the feature out broadly while the rest of the market is still evaluating whether it works.

Need help configuring Update Rings, deploying Administrator Protection via Intune, or setting up a patch strategy that limits restart impact? Zarioh helps organisations translate Microsoft updates into concrete steps. Contact us for a no-obligation conversation.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share