轉發國家資通安全研究院
內容說明:
微軟釋出115年9月份安全性更新,共修補978個漏洞,其中包含193個高風險漏洞與2個已遭利用之漏洞,請儘速確認並進行修補。
影響平台:
【具高風險漏洞之產品】
.NET and Visual Studio
CVE-2026-69439
Azure AI Language
CVE-2026-70352
Azure Arc
CVE-2026-62895
Copilot Studio
CVE-2026-80098
Entra ID
CVE-2026-83941
Graphic Fonts
CVE-2026-72986, CVE-2026-73018
Microsoft Azure Active Directory B2C
CVE-2026-83711
Microsoft Dynamics 365
CVE-2026-65772, CVE-2026-77908
Microsoft Edge (Chromium-based)
CVE-2026-69486, CVE-2026-85893
Microsoft Entra ID
CVE-2026-62916
Microsoft Exchange Server
CVE-2026-69355, CVE-2026-69356, CVE-2026-69641
Microsoft Graphics Component
CVE-2026-73006, CVE-2026-73016, CVE-2026-77493, CVE-2026-78439, CVE-2026-81955
Microsoft Office
CVE-2026-69285, CVE-2026-69442, CVE-2026-69632, CVE-2026-78505, CVE-2026-78524
Microsoft Office Access
CVE-2026-69529, CVE-2026-69614, CVE-2026-69778
Microsoft Office Excel
CVE-2026-78518
Microsoft Office Outlook
CVE-2026-69629, CVE-2026-78509, CVE-2026-78519, CVE-2026-78525
Microsoft Office PowerPoint
CVE-2026-69678, CVE-2026-69767, CVE-2026-69797, CVE-2026-80081
Microsoft Office Publisher
CVE-2026-69742, CVE-2026-81385
Microsoft Office SharePoint
CVE-2026-69268, CVE-2026-69273, CVE-2026-69282, CVE-2026-69464, CVE-2026-69465,
CVE-2026-69716, CVE-2026-69724
Microsoft Office Word
CVE-2026-69360, CVE-2026-69556, CVE-2026-69671, CVE-2026-69686, CVE-2026-69722,
CVE-2026-69759, CVE-2026-69764, CVE-2026-72972, CVE-2026-72973, CVE-2026-77504,
CVE-2026-77901, CVE-2026-78504, CVE-2026-78507, CVE-2026-78510, CVE-2026-78511,
CVE-2026-78512, CVE-2026-78514, CVE-2026-78517, CVE-2026-78521, CVE-2026-78526,
CVE-2026-80080, CVE-2026-80085, CVE-2026-81952
Microsoft Standard XPS
CVE-2026-69824
Microsoft UxTheme Library (uxtheme.dll)
CVE-2026-69276
Microsoft WDAC OLE DB provider for SQL
CVE-2026-72933
Microsoft WebP Image Extension
CVE-2026-70351
Microsoft Windows Codecs Library
CVE-2026-81352
Microsoft Windows Media Foundation
CVE-2026-62706, CVE-2026-62744, CVE-2026-69386, CVE-2026-69408, CVE-2026-69511,
CVE-2026-69601
Microsoft Windows PDF
CVE-2026-69586
Remote Desktop Client
CVE-2026-68828, CVE-2026-69485, CVE-2026-78463, CVE-2026-80074, CVE-2026-80077,
CVE-2026-83998
RPC Runtime
CVE-2026-69819
Skype for Business
CVE-2026-66302
Spring Cloud Azure
CVE-2026-69854
SQL Server
CVE-2026-65669, CVE-2026-66814, CVE-2026-66818, CVE-2026-66819, CVE-2026-66820,
CVE-2026-67368, CVE-2026-67370, CVE-2026-67373, CVE-2026-67378, CVE-2026-67380,
CVE-2026-67381, CVE-2026-67384, CVE-2026-67385, CVE-2026-67388, CVE-2026-67631,
CVE-2026-67638, CVE-2026-67639, CVE-2026-67642, CVE-2026-67643, CVE-2026-68775,
CVE-2026-68786, CVE-2026-73028, CVE-2026-77480, CVE-2026-77481, CVE-2026-77482,
CVE-2026-77483, CVE-2026-77484, CVE-2026-77486, CVE-2026-77487, CVE-2026-78456
Telnet Client
CVE-2026-69431
Visual Studio
CVE-2026-69522, CVE-2026-71328, CVE-2026-77906, CVE-2026-77907
Visual Studio Code
CVE-2026-78462, CVE-2026-81376
Windows Compressed Folder
CVE-2026-69496
Windows Credential Providers
CVE-2026-69729
Windows DHCP Server
CVE-2026-69266, CVE-2026-69547, CVE-2026-69845, CVE-2026-72979
Windows Direct Show
CVE-2026-69715
Windows DNS
CVE-2026-69551, CVE-2026-69730
Windows Error Reporting
CVE-2026-83996
Windows Event Logging Service
CVE-2026-69493, CVE-2026-69494, CVE-2026-69495
Windows Failover Cluster
CVE-2026-73010
Windows Hello
CVE-2026-69740, CVE-2026-69784
Windows HTTP Print Provider
CVE-2026-69769
Windows Hyper-V
CVE-2026-69603, CVE-2026-69910, CVE-2026-80083
Windows Imaging Component
CVE-2026-69499, CVE-2026-69860, CVE-2026-70296, CVE-2026-73013, CVE-2026-73023,
CVE-2026-77495, CVE-2026-83992
Windows Internet Connection Sharing (ICS)
CVE-2026-72983
Windows iSCSI
CVE-2026-69598, CVE-2026-69628, CVE-2026-73025
Windows Kerberos
CVE-2026-69676
Windows Kernel
CVE-2026-69669
Windows Key Distribution Center
CVE-2026-69712
Windows Management Services
CVE-2026-73012
Windows Media Player
CVE-2026-70203, CVE-2026-72960
Windows Message Queuing
CVE-2026-69579
Windows Microsoft DirectMusic
CVE-2026-69491
Windows Netlogon
CVE-2026-72982
Windows Network File System
CVE-2026-69772
Windows NTFS
CVE-2026-69461, CVE-2026-69463
Windows OLE DB
CVE-2026-78442
Windows Paint
CVE-2026-70586
Windows Print Spooler Components
CVE-2026-85877
Windows Raw Image Extension
CVE-2026-69649
Windows Remote Access Connection Manager
CVE-2026-71352
Windows Remote Desktop
CVE-2026-69518
Windows Remote Desktop Services
CVE-2026-69525, CVE-2026-80096
Windows RNDIS
CVE-2026-69768
Windows Routing and Remote Access Service (RRAS)
CVE-2026-69590, CVE-2026-72950, CVE-2026-72959
Windows Schannel
CVE-2026-72940
Windows Secure Socket Tunneling Protocol (SSTP)
CVE-2026-73009
Windows Services for NFS ONCRPC XDR Driver
CVE-2026-69595, CVE-2026-78445
Windows Shell
CVE-2026-69829
Windows URL Moniker
CVE-2026-69434
Windows USB Mass Storage Class Driver
CVE-2026-68839
Windows Volume Manager Extension Driver
CVE-2026-69291, CVE-2026-69334
Windows Work Folder Service
CVE-2026-71336
【已遭利用之產品】
Windows ALPC
CVE-2026-85880
Windows Update Stack
CVE-2026-81963
解決辦法:
目前微軟官方已針對弱點釋出修復版本,請各機關可聯絡系統維護廠商或參考以下連結:
https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep