Windows Patch Tuesday September 2026: 974 CVEs, RDP RCE – update now

Back

Short version: On 8 September 2026 Microsoft shipped the largest Patch Tuesday so far – about 974 CVEs, including two actively exploited zero-days and several critical bugs in Remote Desktop (RDP). If you run a Windows V-Server or root server, update today and reboot. Not “sometime this week”.

The count is this high because Microsoft and researchers now find bugs with AI at scale. Only a few are exploited in the wild – and those sit in places a rented Windows server often exposes: RDP, the update stack, local privilege.

What actually matters for you

You do not need every CVE by heart. Three points cover most hosting customers:

  • RDP, CVE-2026-69525 (CVSS 9.8): use-after-free in Remote Desktop Services. An attacker on the network can run code without logging in. Microsoft says “in-network” – in practice, anyone who puts port 3389 on the internet is in scope. That is how a lot of Windows root servers are set up.
  • Zero-day CVE-2026-85880: bug in Windows ALPC. Local, but already exploited. If someone already has a foothold (weak RDP password, old panel, leaked key), this is how they get SYSTEM.
  • Zero-day CVE-2026-81963: flaw in the Windows Update stack, also exploited, also privilege escalation. CISA put both in the Known Exploited catalog; US agencies have until 22 September. You do not wait until the 22nd.

On top of that sit about 20 wormable bugs – remote, no click, in services such as DNS, DHCP, NFS, SMB. On a single root server without Active Directory that is less ugly than in a company. Still: install the update, do not triage it for a week.

If you self-host Exchange you have extra work (including CVE-2026-55007, RCE via crafted Visio mail). Most NexoraHost customers do not. Almost every Windows customer uses RDP.

What to do now

  1. Windows Update, then reboot. Settings → Windows Update → Check for updates. On Server Core: sconfig, option 6. Without a reboot the patch is often only downloaded, not live.
  2. Do not leave RDP naked on 3389. Firewall in the customer area: your IPs only. Network Level Authentication on. Do not log in as “Administrator”; use a long password or, better, VPN / allowlist. The update closes the hole – you should still shut the door.
  3. Pick a window. Warn your services, then reboot. An unpatched RDP port overnight costs more than five minutes of downtime.
  4. Check afterwards. RDP still works? Services back? Windows Update says you are current? If the box loops on updates after reboot: open a ticket instead of poking it for three hours.

Linux customers

This Patch Tuesday is Windows. Ubuntu and Debian shipped their own kernel updates in early September – different packages, same rule: install, reboot, do not postpone. SSH with keys and no root login still beats a Windows server with open RDP.

What we do at NexoraHost

Windows V-Servers and root servers (Ryzen included) come with RDP. That is convenient – and that is why scanners hit it first. Arbor stops DDoS, not an unpatched RDP service. You apply guest OS updates yourselves; we do not silently patch your VM, because that would kill your services.

If the reboot sticks or RDP is dead after the patch: ticket. If you want a clean Windows reinstall, that is in the panel.

Windows root servers → V-Servers · Ryzen root servers · KVM security warning

More blog articles

We are excited to expand our gameserver portfolio. Five new games are now available: Enshrouded Soulmask Nightingale HumanitZ The Front Necesse Windrose Foundry All titles are ready to book and benefit...

Hetzner is raising prices – but your gameplay doesn't have to suffer Hetzner has announced price adjustments. For many customers, this is annoying – but for gamers who rely on stable, high-performance game servers, it's a real wake-up call. When your c...

First Hetzner, now OVH: Game server hosting prices are skyrocketing. For gamers, it's time to consider alternatives. The Price Spiral Is Turning OVH founder Octave Klaba recently confirmed: Prices for RAM, CPUs, and storage have exploded. OVH is now paying s...