September 2026 Patch TuesdayMSRC-2026-09-other-https-learn-microsoft-com-en-us-azure-azure-linux-tutorial-azure-linux-upgradeNormal patch window

Microsoft · MSRC-2026-09-other-https-learn-microsoft-com-en-us-azure-azure-linux-tutorial-azure-linux-upgrade

Linked CVE review

Deploy Microsoft Other update for 21495-17084

Linked CVEs
6
Confirmed exploited
0
PoC or lab evidence
2
Maximum CVSS
6.9
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
6 of 6 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-86137 PoC or lab evidence
In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

2.9 · CVSS 3.1 · LowSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.EPSS: 0.19% · 8.4th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interactionWithin 7 daysLow technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
CVE-2026-86143 PoC or lab evidence
xmlsoft libxml2: Integer Coercion Error

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

6.9 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.EPSS: 0.19% · 8.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interactionWithin 7 daysMedium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
CVE-2026-86144 Scheduled assessment
xmlsoft libxml2: Incorrect Resource Transfer Between Spheres

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

5.6 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.19% · 7.6th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
CVE-2026-86139 Scheduled assessment
In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

6.9 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.17% · 5.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
CVE-2026-86141 Scheduled assessment
xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

2.9 · CVSS 3.1 · LowSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.17% · 5.3th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interactionScheduledLow technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
CVE-2026-86138 Scheduled assessment
In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

6.9 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.13% · 2.4th percentileForecast date: 2026-10-08LOCAL · HIGH complexity · NONE privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258