Windows Patch Tuesday September 2026: 974 CVEs, RDP RCE – update now
Back
Short version: On 8 September 2026 Microsoft shipped the largest Patch Tuesday so far – about 974 CVEs, including two actively exploited zero-days and several critical bugs in Remote Desktop (RDP). If you run a Windows V-Server or root server, update today and reboot. Not “sometime this week”.
The count is this high because Microsoft and researchers now find bugs with AI at scale. Only a few are exploited in the wild – and those sit in places a rented Windows server often exposes: RDP, the update stack, local privilege.
What actually matters for you
You do not need every CVE by heart. Three points cover most hosting customers:
- RDP, CVE-2026-69525 (CVSS 9.8): use-after-free in Remote Desktop Services. An attacker on the network can run code without logging in. Microsoft says “in-network” – in practice, anyone who puts port 3389 on the internet is in scope. That is how a lot of Windows root servers are set up.
- Zero-day CVE-2026-85880: bug in Windows ALPC. Local, but already exploited. If someone already has a foothold (weak RDP password, old panel, leaked key), this is how they get SYSTEM.
- Zero-day CVE-2026-81963: flaw in the Windows Update stack, also exploited, also privilege escalation. CISA put both in the Known Exploited catalog; US agencies have until 22 September. You do not wait until the 22nd.
On top of that sit about 20 wormable bugs – remote, no click, in services such as DNS, DHCP, NFS, SMB. On a single root server without Active Directory that is less ugly than in a company. Still: install the update, do not triage it for a week.
If you self-host Exchange you have extra work (including CVE-2026-55007, RCE via crafted Visio mail). Most NexoraHost customers do not. Almost every Windows customer uses RDP.
What to do now
- Windows Update, then reboot. Settings → Windows Update → Check for updates. On Server Core:
sconfig, option 6. Without a reboot the patch is often only downloaded, not live. - Do not leave RDP naked on 3389. Firewall in the customer area: your IPs only. Network Level Authentication on. Do not log in as “Administrator”; use a long password or, better, VPN / allowlist. The update closes the hole – you should still shut the door.
- Pick a window. Warn your services, then reboot. An unpatched RDP port overnight costs more than five minutes of downtime.
- Check afterwards. RDP still works? Services back? Windows Update says you are current? If the box loops on updates after reboot: open a ticket instead of poking it for three hours.
Linux customers
This Patch Tuesday is Windows. Ubuntu and Debian shipped their own kernel updates in early September – different packages, same rule: install, reboot, do not postpone. SSH with keys and no root login still beats a Windows server with open RDP.
What we do at NexoraHost
Windows V-Servers and root servers (Ryzen included) come with RDP. That is convenient – and that is why scanners hit it first. Arbor stops DDoS, not an unpatched RDP service. You apply guest OS updates yourselves; we do not silently patch your VM, because that would kill your services.
If the reboot sticks or RDP is dead after the patch: ticket. If you want a clean Windows reinstall, that is in the panel.
Windows root servers → V-Servers · Ryzen root servers · KVM security warning
More blog articles
We are excited to expand our gameserver portfolio. Five new games are now available: Enshrouded Soulmask Nightingale HumanitZ The Front Necesse Windrose Foundry All titles are ready to book and benefit...
Hetzner is raising prices – but your gameplay doesn't have to suffer Hetzner has announced price adjustments. For many customers, this is annoying – but for gamers who rely on stable, high-performance game servers, it's a real wake-up call. When your c...
First Hetzner, now OVH: Game server hosting prices are skyrocketing. For gamers, it's time to consider alternatives. The Price Spiral Is Turning OVH founder Octave Klaba recently confirmed: Prices for RAM, CPUs, and storage have exploded. OVH is now paying s...