Microsoft released the September 2026 security updates today, which include numerous fixes affecting Always On VPN deployments. This month’s edition addresses vulnerabilities in Windows Server Routing and Remote Access (RRAS), VPN protocols such as Secure Socket Tunneling Protocol (SSTP) and Internet Key Exchange version 2 (IKEv2). The updates also include Active Directory Certificate Services (AD CS), a crucial supporting infrastructure service for Always On VPN.
RRAS
September 2026 Microsoft security updates include 8 CVEs for RRAS. Four are rated Critical, the most severe having a CVSS rating of 9.8.
RCEs
The following four CVEs are Remote Code Execution vulnerabilities. All are rated critical.
Privilege Escalation
The following two CVEs are RRAS privilege escalation vulnerabilities. All are rated Important.
Denial of Service
Finally, the last CVE addresses a denial-of-service vulnerability in RRAS.
VPN Protocols
The following section outlines vulnerabilities addressed in the September 2026 security updates affecting commonly used VPN protocols.
SSTP
The following four CVEs cover vulnerabilities in SSTP. One is rated critical with a CVSS score of 9.8. The rest are rated Important.
- CVE-2026-73009 (CVSS 9.8)
- CVE-2026-71332
- CVE-2026-72930
- CVE-2026-72931
IKEv2
The following CVEs address vulnerabilities in the IKEv2 VPN protocol. All are rated important.
AD CS
Microsoft AD CS is commonly deployed to issue and manage certificates used for encryption and user and device authentication in Always On VPN deployments. The following four CVEs address vulnerabilities disclosed in AD CS. The first two are privilege escalation vulnerabilities, the third covers information disclosure, and the last addresses a tampering vulnerability. All are rated Important.
Summary
The September 2026 Microsoft security updates address several critical vulnerabilities affecting organizations that have deployed Microsoft Always On VPN. Administrators are encouraged to update their systems as soon as possible.
