966 patches. Two zero-days. And the bugs that should worry you most are neither.

Microsoft's September 2026 Patch Tuesday fixed a record 966 flaws. The two exploited zero-days are local privilege escalations. The real exposure is 20 wormable bugs in the services your whole network runs on.

WHAT ACTUALLY HAPPENED

Below the zero-day headlines sits a list of CVSS 9.8 remote code execution flaws in core Windows infrastructure:

Windows DNS Server — CVE-2026-69730 Windows Netlogon — CVE-2026-72982 DHCP Server — CVE-2026-69845 and CVE-2026-72979 SSTP VPN — CVE-2026-73009 NFS (ONCRPC XDR) — CVE-2026-69595 and CVE-2026-78445 Message Queuing — CVE-2026-69579

Every one is reachable over the network. No authentication. No user interaction. A single crafted packet sent to an exposed service is enough to run code as the service itself. ZDI counts 20 wormable bugs in this release and ranks them ahead of the zero-days.

The zero-days — CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC — need an attacker already on the machine. Serious, but step two of an intrusion, not step one.

WHY WORMABLE CHANGES THE MATH

A normal RCE compromises one host. A wormable RCE compromises one host, which then compromises the next, and the next, with no attacker at the keyboard.

That is how EternalBlue let WannaCry hit 230,000 machines in 150 countries in 2017.

Now look at where these bugs live. DNS, DHCP and Netlogon run on domain controllers and core servers: the systems every endpoint talks to by design. They are rarely rebooted, often patched last "for stability", and trusted by almost every internal firewall rule.

And a compromised domain controller is never one server lost. It is every account, every group policy and every machine joined to the domain.

The zero-day label drives patch priority. This month it points your team at the wrong servers first.

WHAT TO DO NOW

PATCH INFRASTRUCTURE FIRST — domain controllers, DNS and DHCP servers go ahead of workstations this cycle, and confirm the reboot actually happened.

KILL WHAT YOU DO NOT USE — disable MSMQ, NFS and SSTP wherever nothing depends on them, because an unused service is pure attack surface.

SEGMENT THE CORE — only the clients that genuinely need DNS, DHCP and Netlogon should reach those ports, and servers should not freely reach each other.

ALERT ON SERVICE CRASHES — an unexpected restart of the DNS or DHCP service is an early exploitation signal, so route it to your SIEM today.

Zero-day is a headline. Wormable is a blast radius.

Is your domain controller patched this week, or scheduled "after the business-critical servers"?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.