← All hunts high TLP:CLEAR

Microsoft Patch Tuesday September 2026 Exposure

An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.

Based on research by Cisco Talos 2026-09-28 8 steps · 3 queries T1068 T1190 T1203 T1572

Brief

The September 2026 Patch Cycle

The September 2026 Microsoft Patch Tuesday includes critical fixes for infrastructure services and zero-day flaws in the Windows Update Stack. A recent report by Talos (https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/) highlights nearly 1,000 vulnerabilities, making manual auditing of every endpoint impossible. This hunt prioritizes the most dangerous remote code execution and privilege escalation bugs recorded this month.

How the Hunt Flows

The hunt begins by scoping the estate using vulnerability telemetry. The first query identifies hosts where high-priority CVEs, such as CVE-2026-81963 and CVE-2026-69730, remain unpatched according to existing vulnerability management logs. This narrows the investigation to the most exposed assets, prioritizing Domain Controllers, SQL servers, and workstations with unpatched Office applications.

Next, the analyst establishes a process baseline on these exposed hosts. This step filters for rare process executions—binaries or command lines seen on only one or two machines—over the last 14 days. This helps identify custom payloads or staging tools that an adversary might deploy immediately after a successful exploit triggered a remote shell.

The final phase looks for specific behavioral indicators of exploitation. It monitors for common shell interpreters like PowerShell or cmd.exe spawning directly from vulnerable service parents. Specifically, it searches for child processes of dns.exe, sqlservr.exe, and the Windows Update service. This pattern provides high-confidence evidence that an exploit successfully triggered a remote command or local privilege escalation.

Why This is a Hunt

We designed this as a hunt rather than a simple detection because a detection rule often only alerts on a single CVE hit or a generic shell spawn. This hunt pivots between disparate data surfaces, asking if the specific hosts known to be vulnerable are also the ones exhibiting rare process behaviors. This multi-stage approach reduces noise and focuses analyst attention on confirmed exposure windows where patches were not yet applied.

Blind Spots

This hunt relies on existing vulnerability scanning coverage. If a system is unmanaged and does not report to the vulnerability telemetry surface, it will fall outside the initial scoping query. Additionally, short-lived exploit processes that execute and exit between snapshot intervals may not appear in the process activity logs if the environment lacks continuous process event logging.

Steps

  1. Vulnerability scope for September CVEs

    Query · scoping

    Identify which hosts have been flagged with the high-priority CVEs from the September 2026 advisory.

    reads hb_vulnerability_findingsql
    SELECT device_uid, cve_uid, affected_package_name, affected_package_version, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0

    What a hit looks like. A list of vulnerable devices. Silence indicates no scanned assets currently match the high-priority CVE list.

  2. Rare process baseline on exposed hosts

    Query · baseline

    Identify unusual process executions on hosts currently known to be vulnerable, which may indicate payload delivery.

    reads hb_process_activitysql
    SELECT process_path, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_path, process_cmd_line HAVING host_count <= 2 ORDER BY host_count ASC

    What a hit looks like. A list of processes seen on only one or two hosts. Silence suggests a consistent software baseline across unpatched systems.

  3. Exploitation behaviour from vulnerable services

    Query · detection candidate

    Find behavioural evidence of RCE or EoP where high-privilege service processes or Office apps spawn interpreters.

    reads hb_process_activitysql
    SELECT device_hostname, parent_process_name, process_name, process_cmd_line, user_name, integrity_level, time FROM hb_process_activity WHERE (instr(',' || '{{vulnerable_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 OR (LOWER(parent_process_name) = 'svchost.exe' AND LOWER(parent_process_cmd_line) LIKE '%rras%')) AND instr(',' || '{{shell_interpreters}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Rows showing a shell spawned from a vulnerable parent process like dns.exe or outlook.exe. This is high-confidence evidence of exploitation.

  4. Triage exposure and behaviour

    Agent triage

    Evaluate whether the identified vulnerable hosts show signs of exploitation based on rare processes or suspicious child activity.

  5. Route on evidence of exploitation

    Decision

    Route to remediation review if exploitation is likely, otherwise close out the exposure hunt.

  6. Remediation and vulnerability review

    Analyst task

    Review findings for hosts showing potential exploitation and coordinate patching and verification.

  7. Close out exposure hunt

    Analyst task

    Finalize the hunt results and document the overall exposure level for the September updates.

Coverage

Scenario coverage

StageCoveredHow, or why not
Exploitation of Remote Network Services
T1190 · T1572
Yes vuln-finding-scoping, service-child-behaviour
Client-Side Exploitation via Office and Media
T1203
Yes vuln-finding-scoping, service-child-behaviour
Local Privilege Escalation and Zero-Day Exploitation
T1068
Yes vuln-finding-scoping, rare-process-baseline
Cloud Infrastructure and Database Bypass
T1190
Not visible Azure Cosmos DB and Spring Cloud Azure exploitation require cloud control-plane telemetry not listed as a source.

Blind spots

  • Needs Complete coverage of vulnerability scanning agents. Unmanaged systems could serve as a beachhead without being scoped by the initial query. It would answer Which unmanaged systems remain vulnerable but are not reporting to hb_vulnerability_finding?.
  • Needs Continuous process event logs (Sysmon) rather than snapshots. Short-lived elevation of privilege payloads might be missed if they complete their task before the next process inventory collection. It would answer Did an exploit process run and exit between snapshot intervals?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Optional list of hostnames to focus the hunt on; if empty, examines the full estate.
shell_interpreterslist[string]cmd.exe, powershell.exe, pwsh.exe, scrcons.exe, wscript.exe, cscript.exeCommon shell and script interpreters used in post-exploitation.
target_cveslist[string]CVE-2026-81963, CVE-2026-85880, CVE-2026-69730, CVE-2026-67631, CVE-2026-69852, CVE-2026-72957Critical and exploited-in-the-wild CVEs from the September advisory.
vulnerable_parentslist[string]dns.exe, sqlservr.exe, winword.exe, excel.exe, outlook.exe, skype.exe, wmplayer.exeProcesses associated with the September vulnerabilities that might spawn child shells.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple detection rule flags a single CVE hit. This hunt pivots between
  vulnerability findings and a host-behavioural baseline, asking whether exposed hosts
  exhibit the specific child-shell patterns and rare process deployments that follow
  successful exploitation of these flaws.
blind_spots:
- id: incomplete-vuln-telemetry
  question: Which unmanaged systems remain vulnerable but are not reporting to hb_vulnerability_finding?
  requires: Complete coverage of vulnerability scanning agents
  risk: Unmanaged systems could serve as a beachhead without being scoped by the initial
    query.
  stage: initial-access-remote-services
- id: short-lived-processes
  question: Did an exploit process run and exit between snapshot intervals?
  requires: Continuous process event logs (Sysmon) rather than snapshots
  risk: Short-lived elevation of privilege payloads might be missed if they complete
    their task before the next process inventory collection.
  stage: privilege-escalation-zero-day
coverage:
- stage: initial-access-remote-services
  status: covered
  steps:
  - vuln-finding-scoping
  - service-child-behaviour
- stage: execution-malicious-media-and-office
  status: covered
  steps:
  - vuln-finding-scoping
  - service-child-behaviour
- stage: privilege-escalation-zero-day
  status: covered
  steps:
  - vuln-finding-scoping
  - rare-process-baseline
- reason: Azure Cosmos DB and Spring Cloud Azure exploitation require cloud control-plane
    telemetry not listed as a source.
  stage: initial-access-cloud-and-database
  status: not_visible
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: The September 2026 Patch Tuesday involves nearly 1,000 vulnerabilities,
    including two zero-day elevation of privilege flaws. Verifying that these have
    not been exploited before the patch cycle completes is critical for ensuring environmental
    integrity.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is exploiting September 2026 zero-day or critical remote
  code execution vulnerabilities, such as those in DNS Server or the Windows Update
  Stack, to establish initial access or escalate privileges on unpatched systems.
labels:
- hunt
- attack.t1190
- attack.t1572
- attack.t1068
- attack.t1203
name: Microsoft Patch Tuesday September 2026 Exposure
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the hunt on; if empty, examines
      the full estate.
    type: list[host]
  shell_interpreters:
    default:
    - cmd.exe
    - powershell.exe
    - pwsh.exe
    - scrcons.exe
    - wscript.exe
    - cscript.exe
    description: Common shell and script interpreters used in post-exploitation.
    from:
      kind: manual
      observed: '2026-09-08'
      ref: Common post-exploitation tools
    type: list[string]
  target_cves:
    default:
    - CVE-2026-81963
    - CVE-2026-85880
    - CVE-2026-69730
    - CVE-2026-67631
    - CVE-2026-69852
    - CVE-2026-72957
    description: Critical and exploited-in-the-wild CVEs from the September advisory.
    from:
      kind: article
      observed: '2026-09-08'
      ref: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/
    type: list[string]
  vulnerable_parents:
    default:
    - dns.exe
    - sqlservr.exe
    - winword.exe
    - excel.exe
    - outlook.exe
    - skype.exe
    - wmplayer.exe
    description: Processes associated with the September vulnerabilities that might
      spawn child shells.
    from:
      kind: manual
      observed: '2026-09-08'
      ref: September 2026 Vulnerability List
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: The hunt starts with wide coverage using hb_vulnerability_finding for critical
  CVEs. It prioritizes Domain Controllers (DNS), SQL Servers, and workstations with
  unpatched Office applications. The results populate a list of hosts for more expensive
  behavioural analysis.
references:
- name: "Talos \u2014 Microsoft Patch Tuesday for September 2026"
  url: https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/
related:
- hunt: azure-cosmos-db-spoofing-bypass
  reason: Exploitation of Azure Cosmos DB (CVE-2026-69857) requires Azure-native activity
    logs, which were not in scope for this endpoint-focused hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Exploitation of Remote Network Services
    observables:
    - DNS Server (port 53)
    - Routing and Remote Access Service (RRAS)
    - Secure Socket Tunneling Protocol (SSTP) (port 443)
    - Windows Kerberos (port 88)
    - DHCP Server (ports 67, 68)
    - Reliable Multicast Transport Driver (RMCAST)
    - CVE-2026-69730
    - CVE-2026-69676
    - CVE-2026-73009
    - CVE-2026-69852
    slug: initial-access-remote-services
    tactic: initial-access
    techniques:
    - T1190
    - T1572
  - name: Client-Side Exploitation via Office and Media
    observables:
    - excel.exe
    - winword.exe
    - outlook.exe
    - skype.exe
    - wmplayer.exe
    - Microsoft Excel (CVE-2026-81948)
    - Microsoft Word (CVE-2026-81952)
    - Microsoft Office Outlook (CVE-2026-78525)
    - Windows Media Player (CVE-2026-70203)
    slug: execution-malicious-media-and-office
    tactic: execution
    techniques:
    - T1203
  - name: Local Privilege Escalation and Zero-Day Exploitation
    observables:
    - Windows Update Stack (CVE-2026-81963)
    - Advanced Local Procedure Call (ALPC) (CVE-2026-85880)
    - Windows Hello (CVE-2026-81354)
    - Secure Kernel Mode (CVE-2026-69501)
    - Windows Virtualization-Based Security (VBS) (CVE-2026-83501)
    slug: privilege-escalation-zero-day
    tactic: privilege-escalation
    techniques:
    - T1068
  - name: Cloud Infrastructure and Database Bypass
    observables:
    - Azure Cosmos DB (CVE-2026-69857)
    - Spring Cloud Azure (CVE-2026-69854)
    - Microsoft SQL Server (CVE-2026-67631)
    - Microsoft Dynamics 365 On-Premises (CVE-2026-65772)
    slug: initial-access-cloud-and-database
    tactic: initial-access
    techniques:
    - T1190
  summary: The September 2026 Microsoft Patch Tuesday includes nearly 1,000 vulnerabilities,
    featuring zero-day privilege escalation flaws in the Windows Update Stack and
    ALPC alongside critical remote code execution risks in DNS, Kerberos, and RRAS.
    These vulnerabilities provide multiple paths for attackers to gain initial access
    via remote services or malicious media before escalating to system-level privileges.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Microsoft Patch Tuesday September 2026 Exposure

This hunt identifies exposure and potential exploitation following the September 2026 Microsoft Patch Tuesday. It focuses on the zero-day elevation of privilege in the Windows Update Stack (CVE-2026-81963) and critical remote code execution flaws in infrastructure services like DNS (CVE-2026-69730) and SQL Server (CVE-2026-67631). The hunt scopes the estate using vulnerability telemetry, establishes a process baseline to identify rare binaries on exposed hosts, and hunts for behavioural indicators like shell execution from high-privilege service parents.

## vuln-finding-scoping
<!-- Vulnerability scope for September CVEs -->
Identify which hosts have been flagged with the high-priority CVEs from the September 2026 advisory.

```sqlite target=endpoint role=scoping params=(target_cves=target_cves)
~~~yaml
expected: A list of vulnerable devices. Silence indicates no scanned assets currently
  match the high-priority CVE list.
reads:
- device_uid
- cve_uid
- affected_package_name
- affected_package_version
- severity
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_uid, cve_uid, affected_package_name, affected_package_version, severity FROM hb_vulnerability_finding WHERE instr(',' || '{{target_cves}}' || ',', ',' || cve_uid || ',') > 0
```

## rare-process-baseline
<!-- Rare process baseline on exposed hosts -->
Identify unusual process executions on hosts currently known to be vulnerable, which may indicate payload delivery.

```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A list of processes seen on only one or two hosts. Silence suggests a consistent
  software baseline across unpatched systems.
prevalence:
  by: device_hostname
  key:
  - process_path
  rare_below: 3
reads:
- process_path
- process_cmd_line
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT process_path, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_path, process_cmd_line HAVING host_count <= 2 ORDER BY host_count ASC
```

## service-child-behaviour
<!-- Exploitation behaviour from vulnerable services -->
Find behavioural evidence of RCE or EoP where high-privilege service processes or Office apps spawn interpreters.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days, vulnerable_parents=vulnerable_parents, shell_interpreters=shell_interpreters)
~~~yaml
expected: Rows showing a shell spawned from a vulnerable parent process like dns.exe
  or outlook.exe. This is high-confidence evidence of exploitation.
reads:
- device_hostname
- parent_process_name
- process_name
- process_cmd_line
- user_name
- integrity_level
- time
silence: evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, parent_process_name, process_name, process_cmd_line, user_name, integrity_level, time FROM hb_process_activity WHERE (instr(',' || '{{vulnerable_parents}}' || ',', ',' || LOWER(parent_process_name) || ',') > 0 OR (LOWER(parent_process_name) = 'svchost.exe' AND LOWER(parent_process_cmd_line) LIKE '%rras%')) AND instr(',' || '{{shell_interpreters}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## exposure-triage
<!-- Triage exposure and behaviour -->
```agent target=hunter
cite: required
context:
- vuln-finding-scoping
- rare-process-baseline
- service-child-behaviour
max_iterations: 3
objective: Determine if any host flagged with critical September 2026 vulnerabilities
  exhibits suspicious process activity, citing rows from the baseline and behaviour
  queries.
success_criteria: A per-host verdict of exposed-benign | exposed-suspicious | potentially-exploited.
tools:
- endpoint
```

## exploitation-decision
<!-- Route on evidence of exploitation -->
if~: "the triage verdict identifies potentially-exploited or exposed-suspicious activity on at least one host" (confidence: high, judge=hunter)
then: → remediation-task
indeterminate: → remediation-task
unavailable: → remediation-task (blind_spot: incomplete-vuln-telemetry)
else: → close-out-task

## remediation-task
<!-- Remediation and vulnerability review -->
```manual target=analyst
Review the agent's findings for the identified hosts. Confirm with the vulnerability management team whether the September 2026 patches have been applied. If the rare process activity or child-shell findings are verified as malicious, escalate to the incident response team and follow the standard isolation playbook. Document any findings that represent authorized administrative tools to tune future runs.
```
→ close-out-task

## close-out-task
<!-- Close out exposure hunt -->
```manual target=analyst
Summarize the total count of vulnerable hosts versus those showing suspicious behaviour. Record any gaps in vulnerability scanning coverage identified during the hunt. Submit a final report to the patch management team to verify the closure of critical exposure windows.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.