Serial Number: AV26-896
Date: September 8, 2026
As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products:
- .NET 10.0 installed on Linux
- .NET 10.0 installed on Mac OS
- .NET 10.0 installed on Windows
- .NET 11.0 installed on Linux
- .NET 11.0 installed on Mac OS
- .NET 11.0 installed on Windows
- .NET 8.0 installed on Linux
- .NET 8.0 installed on Mac OS
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Linux
- .NET 9.0 installed on Mac OS
- .NET 9.0 installed on Windows
- ASP.NET Core 10.0
- ASP.NET Core 11.0
- ASP.NET Core 8.0
- ASP.NET Core 9.0
- Azure AI Language Authoring
- Azure Arc SQL Server Extension
- Azure Cosmos DB
- Azure CycleCloud
- Azure HDInsight
- HEIF Image Extension
- HEVC Video Extensions
- HEVC Video Extensions for Licensed Applications
- HEVC Video Extensions from Device Manufacturer
- Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2
- Microsoft .NET Framework 3.5 AND 4.7.2
- Microsoft .NET Framework 3.5 AND 4.8
- Microsoft .NET Framework 3.5 AND 4.8.1
- Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
- Microsoft .NET Framework 4.8
- Microsoft .NET Framework 4.8.1
- Microsoft 365 Apps for Enterprise
- Microsoft Access 2016
- Microsoft Authentication Library (MSAL)
- Microsoft Authenticator for Android
- Microsoft Azure Active Directory B2C
- Microsoft Azure CLI
- Microsoft Copilot Studio
- Microsoft Discovery Studio
- Microsoft Dynamics 365 (on-premises)
- Microsoft Dynamics 365 Customer Engagement
- Microsoft Entra ID
- Microsoft Excel 2016
- Microsoft Exchange Server 2016
- Microsoft Exchange Server 2019
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Fabric
- Microsoft Office 2016
- Microsoft Office 2019
- Microsoft Office 365 for Mac
- Microsoft Office LTSC 2021
- Microsoft Office LTSC 2024
- Microsoft Office LTSC for Mac
- Microsoft Office for Android
- Microsoft Outlook 2016
- Microsoft Power Platform
- Microsoft PowerPoint 2016
- Microsoft Publisher 2016
- Microsoft SQL Server 2017
- Microsoft SQL Server 2019
- Microsoft SQL Server 2022
- Microsoft SQL Server 2025
- Microsoft SharePoint Server Subscription Edition
- Microsoft Teams for Android
- Microsoft Visual Studio 2022
- Microsoft Visual Studio 2026
- Microsoft Word 2016
- Microsoft.AspNetCore.OData
- Microsoft.Diagnostics.Runtime
- Office Online Server
- Power Automate agent for virtual desktops
- Power Automate for Desktop
- Raw Image Extension
- Remote Desktop client for Windows Desktop
- SQL Server Management Studio 22
- Skype for Business Server 2015
- Skype for Business Server 2019
- Skype for Business Server Subscription Edition CU1
- Spring Cloud Azure
- Visual Studio Code
- Web Media Extensions
- WebP Image Extension
- Windows 10
- Windows 11
- Windows Server 2012
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- Windows Server 2025
Microsoft has indicated that CVE-2026-81963 and CVE-2026-85880 have been exploited.
Update 1
On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81963 and CVE-2026-85880 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.