Vulnerabilidades y Avisos de Seguridad: Boletín de seguridad de Microsoft: septiembre de 2026

Boletín de seguridad de Microsoft: septiembre de 2026

Recursos Afectados
  • .NET
  • .NET and Visual Studio
  • ASP.NET Core
  • Active Directory Certificate Services (AD CS)
  • Active Directory Domain Services
  • Active Directory Federation Services (AD FS)
  • Audio Video Control Transport Protocol
  • Azure AI Language
  • Azure Arc
  • Azure Cosmos DB
  • Azure CycleCloud
  • Azure HDInsights
  • BranchCache
  • Connected Devices Platform Service (Cdpsvc)
  • Copilot Studio
  • Data Sharing Service Client
  • Entra ID
  • GitHub Copilot and Visual Studio Code
  • Graphic Fonts
  • HID class driver
  • IP Helper
  • Internet Storage Name Service
  • Kernel Streaming WOW Thunk Service Driver
  • Microsoft Account
  • Microsoft Authenticator
  • Microsoft Azure Active Directory B2C
  • Microsoft Azure Attestation service and Device Health Attestation Service
  • Microsoft Azure CLI
  • Microsoft COM for Windows
  • Microsoft Discovery Studio
  • Microsoft Dynamics 365
  • Microsoft Edge (Chromium-based)
  • Microsoft Entra ID
  • Microsoft Exchange Server
  • Microsoft Fabric
  • Microsoft Graphics Component
  • Microsoft Install Service
  • Microsoft JScript
  • Microsoft Local Security Authority Server (lsasrv)
  • Microsoft Office
  • Microsoft Office Access
  • Microsoft Office Excel
  • Microsoft Office Outlook
  • Microsoft Office PowerPoint
  • Microsoft Office Publisher
  • Microsoft Office SharePoint
  • Microsoft Office Word
  • Microsoft Standard XPS
  • Microsoft Teams for Android
  • Microsoft Trace Data Helper
  • Microsoft UxTheme Library (uxtheme.dll)
  • Microsoft WDAC OLE DB provider for SQL
  • Microsoft WebP Image Extension
  • Microsoft Windows Codecs Library
  • Microsoft Windows Media Foundation
  • Microsoft Windows PDF
  • Microsoft Windows SCSI Class System File
  • Microsoft Windows Search Component
  • Microsoft Windows Speech
  • OpenSSH for Windows
  • Power Automate
  • Push Message Routing Service
  • RPC Runtime
  • Reliable Multicast Transport Driver (RMCAST)
  • Remote Desktop Client
  • Remote Desktop Gateway Service
  • Role: DNS Server
  • Role: Windows Fax Service
  • SQL Server
  • Skype for Business
  • Spring Cloud Azure
  • Storage Port Driver
  • Telnet Client
  • Virtual Hard Disk (VHD) Miniport Driver
  • Visual Studio
  • Visual Studio Code
  • Volume Manager Driver
  • Windows AF_UNIX Socket Provider
  • Windows ALPC
  • Windows Accounts Control
  • Windows Ancillary Function Driver for WinSock
  • Windows Audio Service
  • Windows Authentication Methods
  • Windows Autopilot
  • Windows Bind Filter Driver
  • Windows Biometric Service
  • Windows BitLocker
  • Windows Bluetooth Port Driver
  • Windows Bluetooth Service
  • Windows Boot Manager
  • Windows Broadcast DVR User Service
  • Windows Broker Infrastructure Service
  • Windows CD-ROM Driver
  • Windows Camera Frame Server Monitor
  • Windows Cloud Files Mini Filter Driver
  • Windows Compressed Folder
  • Windows Connected User Experiences and Telemetry
  • Windows Container Manager Service
  • Windows Core Messaging
  • Windows Credential Guard
  • Windows Credential Providers
  • Windows DCOM Server
  • Windows DHCP Client
  • Windows DHCP Server
  • Windows DNS
  • Windows DWM Core Library
  • Windows Defender Firewall Service
  • Windows Deployment Services
  • Windows Device Association Broker service
  • Windows Device Association Service
  • Windows Devices Human Interface
  • Windows Direct Show
  • Windows Display Enhancement Service
  • Windows Distributed File System (DFS)
  • Windows Embedded Mode Service
  • Windows Encrypting File System (EFS)
  • Windows Enterprise App Management
  • Windows Error Reporting
  • Windows Event Logging Service
  • Windows Failover Cluster
  • Windows Fast FAT Driver
  • Windows File History Service
  • Windows GDI
  • Windows GDI+
  • Windows Graphics Kernel
  • Windows Group Policy
  • Windows HTTP Print Provider
  • Windows HTTP.sys
  • Windows Hello
  • Windows Host Guardian Service
  • Windows Hyper-V
  • Windows IKE Extension
  • Windows IP Address Management (IPAM) Service
  • Windows Image Acquisition
  • Windows Imaging Component
  • Windows Installer
  • Windows Internet Connection Sharing (ICS)
  • Windows Kerberos
  • Windows Kernel
  • Windows Kernel Mode Driver
  • Windows Key Distribution Center
  • Windows LDAP – Lightweight Directory Access Protocol
  • Windows License Manager
  • Windows Link Layer Topology Discovery Protocol
  • Windows MIDI Service Module
  • Windows Management Instrumentation
  • Windows Management Services
  • Windows Media
  • Windows Media Player
  • Windows Message Queuing
  • Windows Message Queuing Queue Manager
  • Windows Microsoft DirectMusic
  • Windows Mobile Broadband
  • Windows Modern Device Management (MDM)
  • Windows Modern Execution Server
  • Windows NDIS
  • Windows NFS Portmapper
  • Windows NTFS
  • Windows Netlogon
  • Windows Network Connection Broker
  • Windows Network File System
  • Windows Notification
  • Windows OLE DB
  • Windows Online Certificate Status Protocol (OCSP)
  • Windows Overlay Filter
  • Windows Paint
  • Windows Partition Management Driver
  • Windows Performance Monitor
  • Windows Power Dependency Coordinator
  • Windows PowerShell
  • Windows Print Spooler Components
  • Windows PrintWorkflowUserSvc
  • Windows Program Compatibility Assistant Service
  • Windows Push Notifications
  • Windows RDP Client
  • Windows RNDIS
  • Windows Raw Image Extension
  • Windows Registry
  • Windows Remote Access Connection Manager
  • Windows Remote Desktop
  • Windows Remote Desktop Licensing Service
  • Windows Remote Desktop Protocol
  • Windows Remote Desktop Services
  • Windows Resilient File System (ReFS)
  • Windows Resilient File System (ReFS) Deduplication Service
  • Windows Routing and Remote Access Service (RRAS)
  • Windows SMB Client
  • Windows SMB Server
  • Windows SMB Server Network Transport Driver (srvnet.sys)
  • Windows Schannel
  • Windows Secure Boot
  • Windows Secure Kernel Mode
  • Windows Secure Socket Tunneling Protocol (SSTP)
  • Windows Security Center
  • Windows Security Health Service
  • Windows Server
  • Windows Services for NFS ONCRPC XDR Driver
  • Windows Setup Files Cleanup
  • Windows Shell
  • Windows Smart Card
  • Windows Spaceport.sys
  • Windows Storage
  • Windows Storage Management Provider
  • Windows Storage Port Driver
  • Windows Storage Spaces Controller
  • Windows TCP/IP
  • Windows Task Scheduler
  • Windows Text Shaping
  • Windows URL Moniker
  • Windows USB Audio Class driver (usbaudio.sys)
  • Windows USB Driver
  • Windows USB Hub Driver
  • Windows USB Mass Storage Class Driver
  • Windows USB Video Driver
  • Windows Universal Disk Format File System Driver (UDFS)
  • Windows Universal Plug and Play (UPnP) Device Host
  • Windows Update Stack
  • Windows VHD miniport driver
  • Windows VOLSNAP.SYS
  • Windows Virtual Trusted Platform Module
  • Windows Volume Manager Extension Driver
  • Windows Volume Shadow Copy
  • Windows Web Platform Storage
  • Windows WebClient Service
  • Windows Win32 Kernel Subsystem
  • Windows Win32K
  • Windows Wireless Networking
  • Windows Wireless Wide Area Network Service
  • Windows Work Folder Service
  • Windows Work Folders
  • Windows exFAT File System
  • Windows iSCSI
  • Windows iSCSI Target Service
  • Winsock
  • XBox Gaming Services
  • Xbox
Descripción

La publicación de actualizaciones de seguridad de Microsoft, correspondiente a la publicación de vulnerabilidades del 8 de septiembre, consta de 974 vulnerabilidades (con CVE asignado), calificadas 46 como críticas, 682 como altas, 239 como medias y 2 como bajas.
 

Identificador
INCIBE-2026-616

Solución

Instalar la actualización de seguridad correspondiente. En la página de Microsoft se informa de los distintos métodos para llevar a cabo dichas actualizaciones.

Detalle

Las vulnerabilidades de severidad crítica publicadas tienen asignados los siguientes identificadores y descripciones:

  • CVE-2026-62916: vulnerabilidad de Elevación de Privilegios en Microsoft Entra ID
  • CVE-2026-65669: vulnerabilidad de Elevación de Privilegios en Microsoft SQL Server
  • CVE-2026-66302: vulnerabilidad de Ejecución Remota de Código en Skype for Business
  • CVE-2026-68839: vulnerabilidad de Ejecución Remota de Código en Windows USB Mass Storage Class Driver
  • CVE-2026-69276: vulnerabilidad de Ejecución Remota de Código en Microsoft UxTheme Library (uxtheme.dll)
  • CVE-2026-69356: vulnerabilidad de Suplantación en Microsoft Exchange Server
  • CVE-2026-69380: vulnerabilidad de Elevación de Privilegios en Microsoft Exchange Server
  • CVE-2026-69408: vulnerabilidad de Ejecución Remota de Código en Microsoft Windows Media Foundation
  • CVE-2026-69431: vulnerabilidad de Ejecución Remota de Código en Telnet Client
  • CVE-2026-69463: vulnerabilidad de Ejecución Remota de Código en Windows NTFS
  • CVE-2026-69491: vulnerabilidad de Ejecución Remota de Código en Microsoft DirectMusic
  • CVE-2026-69493: vulnerabilidad de Ejecución Remota de Código en Windows Event Logging Service
  • CVE-2026-69496: vulnerabilidad de Ejecución Remota de Código en Windows Compressed Folder
  • CVE-2026-69525: vulnerabilidad de Ejecución Remota de Código en Remote Desktop Services
  • CVE-2026-69579: vulnerabilidad de Ejecución Remota de Código en Windows Message Queuing
  • CVE-2026-69586: vulnerabilidad de Ejecución Remota de Código en Microsoft Windows PDF
  • CVE-2026-69590: vulnerabilidad de Ejecución Remota de Código en Windows Routing and Remote Access Service (RRAS)
  • CVE-2026-69595: vulnerabilidad de Ejecución Remota de Código en Windows Services for NFS ONCRPC XDR Driver
  • CVE-2026-69641: vulnerabilidad de Elevación de Privilegios en Microsoft Exchange Server
  • CVE-2026-69669: vulnerabilidad de Ejecución Remota de Código en Windows Kernel
  • CVE-2026-69715: vulnerabilidad de Ejecución Remota de Código en Windows Direct Show
  • CVE-2026-69730: vulnerabilidad de Ejecución Remota de Código en Windows DNS Server
  • CVE-2026-69768: vulnerabilidad de Ejecución Remota de Código en Windows RNDIS
  • CVE-2026-69769: vulnerabilidad de Ejecución Remota de Código en Windows HTTP Print Provider
  • CVE-2026-69819: vulnerabilidad de Ejecución Remota de Código en RPC Runtime Library
  • CVE-2026-69824: vulnerabilidad de Ejecución Remota de Código en Microsoft Standard XPS
  • CVE-2026-69829: vulnerabilidad de Ejecución Remota de Código en Windows Shell
  • CVE-2026-69845: vulnerabilidad de Ejecución Remota de Código en Windows DHCP Server
  • CVE-2026-69854: vulnerabilidad de Elevación de Privilegios en Spring Cloud Azure
  • CVE-2026-69910: vulnerabilidad de Ejecución Remota de Código en Windows Hyper-V
  • CVE-2026-70296: vulnerabilidad de Ejecución Remota de Código en Windows Imaging Component
  • CVE-2026-70352: vulnerabilidad de Elevación de Privilegios en Azure AI Language
  • CVE-2026-72979: vulnerabilidad de Ejecución Remota de Código en Windows DHCP Server
  • CVE-2026-72982: vulnerabilidad de Ejecución Remota de Código en Windows Netlogon
  • CVE-2026-72983: vulnerabilidad de Ejecución Remota de Código en Internet Connection Sharing (ICS)
  • CVE-2026-73009: vulnerabilidad de Ejecución Remota de Código en Windows Secure Socket Tunneling Protocol (SSTP)
  • CVE-2026-73010: vulnerabilidad de Ejecución Remota de Código en Microsoft Failover Cluster
  • CVE-2026-73025: vulnerabilidad de Omisión de Característica de Seguridad en Windows iSCSI
  • CVE-2026-77493: vulnerabilidad de Ejecución Remota de Código en Windows Graphics Component
  • CVE-2026-78445: vulnerabilidad de Ejecución Remota de Código en Windows Services for NFS ONCRPC XDR Driver
  • CVE-2026-78509: vulnerabilidad de Ejecución Remota de Código en Microsoft Office Outlook
  • CVE-2026-78510: vulnerabilidad de Ejecución Remota de Código en Microsoft Word
  • CVE-2026-80098: vulnerabilidad de Elevación de Privilegios en Copilot Studio
  • CVE-2026-81376: vulnerabilidad de Omisión de Característica de Seguridad en Visual Studio Code
  • CVE-2026-81963: vulnerabilidad de Elevación de Privilegios en Windows Update Stack (Está siendo explotada)
  • CVE-2026-83711: vulnerabilidad de Elevación de Privilegios en Microsoft Azure Active Directory B2C
  • CVE-2026-83941: vulnerabilidad de Elevación de Privilegios en Entra ID
  • CVE-2026-85880: vulnerabilidad de Elevación de Privilegios en Windows Advanced Local Procedure Call (ALPC) (Está siendo explotada)

Los códigos CVE asignados a las vulnerabilidades no críticas reportadas pueden consultarse en las referencias.

5 – Crítica
Listado de referencias

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-62916 Crítica No Microsoft
CVE-2026-65669 Crítica No Microsoft
CVE-2026-66302 Crítica No Microsoft
CVE-2026-68839 Crítica No Microsoft
CVE-2026-69276 Crítica No Microsoft
CVE-2026-69356 Crítica No Microsoft
CVE-2026-69380 Crítica No Microsoft
CVE-2026-69408 Crítica No Microsoft
CVE-2026-69431 Crítica No Microsoft
CVE-2026-69463 Crítica No Microsoft
CVE-2026-69491 Crítica No Microsoft
CVE-2026-69493 Crítica No Microsoft
CVE-2026-69496 Crítica No Microsoft
CVE-2026-69525 Crítica No Microsoft
CVE-2026-69579 Crítica No Microsoft
CVE-2026-69586 Crítica No Microsoft
CVE-2026-69590 Crítica No Microsoft
CVE-2026-69595 Crítica No Microsoft
CVE-2026-69641 Crítica No Microsoft
CVE-2026-69669 Crítica No Microsoft
CVE-2026-69715 Crítica No Microsoft
CVE-2026-69730 Crítica No Microsoft
CVE-2026-69768 Crítica No Microsoft
CVE-2026-69769 Crítica No Microsoft
CVE-2026-69819 Crítica No Microsoft
CVE-2026-69824 Crítica No Microsoft
CVE-2026-69829 Crítica No Microsoft
CVE-2026-69845 Crítica No Microsoft
CVE-2026-69854 Crítica No Microsoft
CVE-2026-69910 Crítica No Microsoft
CVE-2026-70296 Crítica No Microsoft
CVE-2026-70352 Crítica No Microsoft
CVE-2026-72979 Crítica No Microsoft
CVE-2026-72982 Crítica No Microsoft
CVE-2026-72983 Crítica No Microsoft
CVE-2026-73009 Crítica No Microsoft
CVE-2026-73010 Crítica No Microsoft
CVE-2026-73025 Crítica No Microsoft
CVE-2026-77493 Crítica No Microsoft
CVE-2026-78445 Crítica No Microsoft
CVE-2026-78509 Crítica No Microsoft
CVE-2026-78510 Crítica No Microsoft
CVE-2026-80098 Crítica No Microsoft
CVE-2026-81376 Crítica No Microsoft
CVE-2026-81963 Alta Microsoft
CVE-2026-83711 Crítica No Microsoft
CVE-2026-83941 Crítica No Microsoft
CVE-2026-85880 Alta Microsoft

Fuente: link

Aviso: Esta noticia / aviso es únicamente informativa y su veracidad está supeditada a la fuente origen.

TechConsulting muestra este contenido por creer en su fuente y como servicio para facilitar a usuarios y empresas la obtención de dicho contenido. Agradecemos a la fuente el esfuerzo por distribuir este tipo de noticias y avisos sobre Ciberseguridad.

Para más información o dudas en Ciberseguridad aplicada a la empresa, puede ver nuestro catálogo de productos en Servicios TechConsulting o puede contactar con nosotros para resolver cualquier cuestión que pueda tener.

mobil chat sitesi Maltepe oto çekici Ucuz Uçak Bileti