Recommendations for the September 2026 Regular Security Updates for the Microsoft Product Family

Recommendations for the September 2026 Regular Security Updates for the Microsoft Product Family
  • Microsoft has released its September 2026 regular security update to address vulnerabilities found in its products.
  • This update targets packages related to Microsoft Azure, Windows, Microsoft Edge, Microsoft Office, Microsoft Dynamics, Microsoft Copilot, and Azure Linux 3.0.
  • The types of vulnerabilities addressed include privilege escalation, remote code execution, information disclosure, spoofing, and denial of service.
  • Microsoft 365 Copilot, Microsoft 365 Copilot’s Business Chat, Azure AI Language, Azure AI Foundry, Azure Arc, Azure Billing, Azure Cosmos DB, Azure Database for PostgreSQL, Azure Logic Apps, Azure Machine Learning, Azure Portal, Microsoft Azure Active Directory B2C, Microsoft Container Registry, Microsoft Discovery Studio, Microsoft Entra ID, Microsoft Edge (Chromium-based), Power Automate, Microsoft Dataverse, Microsoft Fabric, Microsoft Office Word, Microsoft Teams for Android, Microsoft Copilot Studio, Microsoft Copilot, Microsoft Graphics Component, Windows Device Association Broker Service, Windows DHCP Client, Windows DHCP Server, Windows Error Reporting, Windows MIDI Service Module, Windows Partition Management Driver, Windows Secure Kernel Mode, Windows Volume Manager Extension Driver, and others have had vulnerabilities patched.
  • Microsoft Edge (Chromium-based) also includes vulnerabilities related to the Dawn, FullScreen, and WebGL features; critical-rated privilege escalation and remote code execution vulnerabilities were identified.
  • Azure Linux 3.0 Provided security fixes for previous versions of several packages. The affected packages include curl, containerd2, coredns, kubernetes, nginx, python3, Rust, zlib, and many others.
  • Vulnerability Patches were released on September 3, September 5, September 6, September 9, September 11, September 14, September 15, and September 17.
  • Users of Windows, Microsoft Edge, and Microsoft Office should apply the latest security updates through Windows Update or Microsoft Update.
  • Users of Microsoft 365, Microsoft Copilot, Microsoft Dynamics, and Azure-based services should verify whether Microsoft has applied service-side security updates and review the recommendations for each product.
  • Azure Linux 3.0 Users must update to the latest version of the package provided by Microsoft.
  • For detailed information about security patches and affected versions, refer to the Microsoft Security Response Center and the official security update notices for each product.