CVE-2026-85880
As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 11.0 installed on Linux .NET 11.0 installed on Mac OS .NET 11.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows ASP.NET Core 10.0 ASP.NET Core 11.0 ASP.NET Core 8.0 ASP.NET Core 9.0 Azure AI Language Authoring Azure Arc SQL Server Extension Azure Cosmos DB Azure CycleCloud Azure HDInsight HEIF Image Extension HEVC Video Extensions HEVC Video Extensions for Licensed Applications HEVC Video Extensions from Device Manufacturer Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Authentication Library (MSAL) Microsoft Authenticator for Android Microsoft Azure Active Directory B2C Microsoft Azure CLI Microsoft Copilot Studio Microsoft Discovery Studio Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Customer Engagement Microsoft Entra ID Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Fabric Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac Microsoft Office for Android Microsoft Outlook 2016 Microsoft Power Platform Microsoft PowerPoint 2016 Microsoft Publisher 2016 Microsoft SQL Server 2017 Microsoft SQL Server 2019 Microsoft SQL Server 2022 Microsoft SQL Server 2025 Microsoft SharePoint Server Subscription Edition Microsoft Teams for Android Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Microsoft Word 2016 Microsoft.AspNetCore.OData Microsoft.Diagnostics.Runtime Office Online Server Power Automate agent for virtual desktops Power Automate for Desktop Raw Image Extension Remote Desktop client for Windows Desktop SQL Server Management Studio 22 Skype for Business Server 2015 Skype for Business Server 2019 Skype for Business Server Subscription Edition CU1 Spring Cloud Azure Visual Studio Code Web Media Extensions WebP Image Extension Windows 10 Windows 11 Windows Server 2012 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025 Microsoft has indicated that CVE-2026-81963 and CVE-2026-85880 have been exploited. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81963 and CVE-2026-85880 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 11 | |
| Microsoft | Microsoft .NET Framework 4.8.1 | |
| VMware | Spring Cloud Azure | |
| Microsoft | .NET 10.0 installed on Windows | |
| Azure | Azure AI Language Authoring | |
| Microsoft | Microsoft Office LTSC 2021 | |
| HEVC | HEVC Video Extensions for Licensed Applications | |
| Microsoft | Microsoft Azure CLI | |
| Microsoft | Microsoft SharePoint Server Subscription Edition | |
| HEVC | HEVC Video Extensions | |
| Microsoft | Microsoft Exchange Server 2019 | |
| Microsoft | Microsoft Outlook 2016 | |
| Microsoft | Microsoft Teams for Android | |
| Microsoft | .NET 8.0 installed on Windows | |
| Microsoft | Microsoft Fabric | |
| Microsoft | Microsoft SQL Server 2019 | |
| Microsoft | Microsoft Authenticator for Android | |
| Microsoft | Microsoft Access 2016 | |
| Power | Power Automate for Desktop | |
| Microsoft | Microsoft.AspNetCore.OData |
…and 70 more
Timeline
- Sep 8, 2026 CISA KEV Added
- Sep 8, 2026 VulnCheck KEV Exploitation
- Sep 8, 2026 CVE Published
- Sep 9, 2026 VulnCheck KEV Exploitation
- Sep 9, 2026 Security Advisory
References
- https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-september-2026-monthly-rollup-av26-896 advisory
- https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep vendor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880 advisory