Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1

Serial Number: AV26-896
Date: September 8, 2026

As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products:

  • .NET 10.0 installed on Linux
  • .NET 10.0 installed on Mac OS
  • .NET 10.0 installed on Windows
  • .NET 11.0 installed on Linux
  • .NET 11.0 installed on Mac OS
  • .NET 11.0 installed on Windows
  • .NET 8.0 installed on Linux
  • .NET 8.0 installed on Mac OS
  • .NET 8.0 installed on Windows
  • .NET 9.0 installed on Linux
  • .NET 9.0 installed on Mac OS
  • .NET 9.0 installed on Windows
  • ASP.NET Core 10.0
  • ASP.NET Core 11.0
  • ASP.NET Core 8.0
  • ASP.NET Core 9.0
  • Azure AI Language Authoring
  • Azure Arc SQL Server Extension
  • Azure Cosmos DB
  • Azure CycleCloud
  • Azure HDInsight
  • HEIF Image Extension
  • HEVC Video Extensions
  • HEVC Video Extensions for Licensed Applications
  • HEVC Video Extensions from Device Manufacturer
  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2
  • Microsoft .NET Framework 3.5 AND 4.7.2
  • Microsoft .NET Framework 3.5 AND 4.8
  • Microsoft .NET Framework 3.5 AND 4.8.1
  • Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
  • Microsoft .NET Framework 4.8
  • Microsoft .NET Framework 4.8.1
  • Microsoft 365 Apps for Enterprise
  • Microsoft Access 2016
  • Microsoft Authentication Library (MSAL)
  • Microsoft Authenticator for Android
  • Microsoft Azure Active Directory B2C
  • Microsoft Azure CLI
  • Microsoft Copilot Studio
  • Microsoft Discovery Studio
  • Microsoft Dynamics 365 (on-premises)
  • Microsoft Dynamics 365 Customer Engagement
  • Microsoft Entra ID
  • Microsoft Excel 2016
  • Microsoft Exchange Server 2016
  • Microsoft Exchange Server 2019
  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Fabric
  • Microsoft Office 2016
  • Microsoft Office 2019
  • Microsoft Office 365 for Mac
  • Microsoft Office LTSC 2021
  • Microsoft Office LTSC 2024
  • Microsoft Office LTSC for Mac
  • Microsoft Office for Android
  • Microsoft Outlook 2016
  • Microsoft Power Platform
  • Microsoft PowerPoint 2016
  • Microsoft Publisher 2016
  • Microsoft SQL Server 2017
  • Microsoft SQL Server 2019
  • Microsoft SQL Server 2022
  • Microsoft SQL Server 2025
  • Microsoft SharePoint Server Subscription Edition
  • Microsoft Teams for Android
  • Microsoft Visual Studio 2022
  • Microsoft Visual Studio 2026
  • Microsoft Word 2016
  • Microsoft.AspNetCore.OData
  • Microsoft.Diagnostics.Runtime
  • Office Online Server
  • Power Automate agent for virtual desktops
  • Power Automate for Desktop
  • Raw Image Extension
  • Remote Desktop client for Windows Desktop
  • SQL Server Management Studio 22
  • Skype for Business Server 2015
  • Skype for Business Server 2019
  • Skype for Business Server Subscription Edition CU1
  • Spring Cloud Azure
  • Visual Studio Code
  • Web Media Extensions
  • WebP Image Extension
  • Windows 10
  • Windows 11
  • Windows Server 2012
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022
  • Windows Server 2025

Microsoft has indicated that CVE-2026-81963 and CVE-2026-85880 have been exploited.

Update 1

On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81963 and CVE-2026-85880 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: