September 2026 Patch Tuesday: Critical Windows Print Flaw Fixed
Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.
Key takeaways
- Microsoft's September 8, 2026 Patch Tuesday was the largest on record, with more than 960 CVEs fixed.
- CVE-2026-69769, a Critical (CVSS 9.8) flaw in the Windows HTTP Print Provider, can be exploited over a network with no sign-in and no user interaction.
- Microsoft says none of these print fixes were exploited when patched; the month's two zero-days, CVE-2026-81963 and CVE-2026-85880, were not print-related.
- The fixes ship in the regular cumulative updates, such as KB5124008 for Windows 11 24H2 and 25H2 and the Extended Security Update KB5122878 for Windows 10 22H2.
- Patch a test PC first, confirm printing still works, then roll the update out office-wide within days.
Last Tuesday, September 8, Microsoft released its September 2026 security updates, fixing more than 960 vulnerabilities (CVEs), according to Microsoft's release data, BleepingComputer, SecurityWeek and Tenable. BleepingComputer, SecurityWeek and Dark Reading all called it a record, making it the largest Patch Tuesday yet. The exact total depends on who counted and when, but every tally lands above 960.
For offices, one fix in that pile stands out: a Critical flaw in a Windows printing component called the HTTP Print Provider. Here's what was fixed, what wasn't exploited (this month's zero-days had nothing to do with printing), and how to roll out the update without wrecking Monday's print queue.
Which printer-related flaws did Microsoft fix in September?
The headliner is CVE-2026-69769 in the Windows HTTP Print Provider, rated Critical. Alongside it came a cluster of Windows Print Spooler Components fixes, including CVE-2026-68848 and CVE-2026-69921. Here's how the three compare, based on Microsoft's Security Update Guide and Patch Tuesday analyses from CrowdStrike, Qualys, Rapid7 and Cisco Talos:
| CVE | Component | What an attacker could do | Severity (CVSS) | Exploited when patched? | Microsoft's exploitability rating |
|---|---|---|---|---|---|
| CVE-2026-69769 | Windows HTTP Print Provider | Run code over a network, with no sign-in and no user click | Critical (9.8) | No | Exploitation Unlikely |
| CVE-2026-68848 | Windows Print Spooler Components | Raise privileges locally, starting from a signed-in account | Important (7.8) | No | Exploitation Less Likely |
| CVE-2026-69921 | Windows Print Spooler Components | Same type of flaw as CVE-2026-68848 | Important (7.8) | No | Exploitation More Likely |
All three are heap-based buffer overflows. That's a memory bug where software writes more data than the space set aside for it, which attackers can sometimes turn into running their own code or grabbing higher privileges. The exploitability labels in the last column are Microsoft's own assessments, and "Exploitation More Likely" on CVE-2026-69921 is a nudge to patch promptly.
What is the Windows HTTP Print Provider?
It's the Windows printing component named in the flaw's official title, "Windows HTTP Print Provider Remote Code Execution Vulnerability," per Microsoft's Security Update Guide. You may never have heard of it, and you don't need to know how it works to fix it.
The fix ships in the regular monthly cumulative update, so installing that update is what closes the hole, whether or not anyone in your office knowingly relies on the component.
Why is a 9.8 score such a big deal?
Because of how the attack works. Microsoft's scoring for CVE-2026-69769 says an unauthorized attacker can exploit it over a network, with low attack complexity, no privileges and no user interaction, and end up executing code, according to the Security Update Guide, CrowdStrike and Qualys.
In plain English: someone who can reach a vulnerable machine doesn't need a password and doesn't need anyone to click anything. That's why it sits near the top of the scale even though Microsoft says it wasn't being exploited when it was patched.
Were any of these printer flaws exploited?
No. Microsoft says CVE-2026-69769 was neither publicly disclosed nor exploited when it was patched, and rates it "Exploitation Unlikely," according to Microsoft's release data. Its Security Update Guide marks the two Print Spooler Components flaws in the table as not exploited, too.
The month did include two actively exploited zero-days, but neither involves printing: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, both elevation-of-privilege flaws, per Microsoft and coverage from Tenable, BleepingComputer and Belgium's Centre for Cybersecurity. If you saw "zero-days" and "critical printing flaw" in the same week's headlines, those are two separate stories. If you read that the printing flaw was exploited in the wild, that isn't what Microsoft's data says.
Not exploited yet isn't the same as safe to ignore, though. Once a patch is public, attackers can study what it changed, so the gap between "patch available" and "patch installed" is worth keeping short.
Which updates contain the fixes?
The regular September 8 cumulative updates. There's no separate printer patch to hunt for. Examples, per Microsoft's Security Update Guide, Pureinfotech, Windows Latest and BleepingComputer:
- Windows 11 24H2 and 25H2: KB5124008 (builds 26100.9445 and 26200.9445).
- Windows 10 22H2: KB5122878 (build 19045.7725), an Extended Security Update (ESU) release.
For other Windows versions, including Windows Server, look up CVE-2026-69769 in Microsoft's Security Update Guide to find the matching update.
What if we still have Windows 10 PCs?
Because KB5122878 is an ESU release, it's meant for Windows 10 PCs enrolled in Microsoft's Extended Security Updates program. If you still run Windows 10, check each PC's update history for KB5122878. If it isn't there, find out whether that PC is enrolled, or plan its move to Windows 11.
What this means for San Fernando Valley offices
There's nothing Valley-specific about this bug, but picture a typical small-office setup: a server in a closet shares the printers, an older Windows 10 PC runs the label printer or the practice-management app, and updates get postponed because "the last one broke printing."
That worry isn't irrational. Just last week we covered how an August .NET Framework update broke printing and PDF export in some business apps. But the answer is a quick test-then-deploy routine, not a skip. A Critical, no-click, network-reachable flaw is exactly the kind you don't want sitting unpatched for months.
Whether you're a law office, a medical practice or a production company anywhere in the San Fernando Valley communities we serve, the priorities are the same: print servers and PCs that share printers first, Windows 10 stragglers second, and a documented way to roll back if a driver misbehaves. Our printer driver management guide covers that last part, and our post on pass-back attacks covers another way printers can expose Windows accounts.
What to do now
- Install the September cumulative update on every Windows PC and server, starting with print servers and any PC that shares a printer.
- Confirm it landed: look for KB5124008 on Windows 11 24H2 or 25H2 and KB5122878 on Windows 10 22H2, and check the Security Update Guide for other versions.
- Pilot first, but fast: patch one or two PCs, print a test page from each department's main app and printer, then roll out within days, not weeks.
- Inventory your Windows 10 PCs and confirm each one is either enrolled in ESU or scheduled for replacement.
- Shrink the attack surface: turn off printer sharing where it isn't needed, and disable the Print Spooler on servers that don't print, such as domain controllers. The update is still the fix; these steps just reduce exposure.
- Keep printer drivers current and write down a rollback plan before each monthly update.
- Put Patch Tuesday on the office calendar so updates get tested and installed every month, not whenever someone remembers.
Want a second set of eyes on your print server and printer-sharing settings? Book a free virtual consultation and we'll walk through them with you.
Update (September 30, 2026)
After this post was published, administrators reported that the September update for Windows Server 2022, KB5122882, stopped several Type 3 (user-mode) printer drivers from working on Remote Desktop Session Host servers, with printer-sharing problems also reported, according to Neowin, Windows Report and Borncity. Drivers named in those reports include HP Universal Printing PCL 6, Adobe PDF Converter and the DYMO LabelWriter 450 Turbo driver.
Microsoft's September 14 out-of-band update for Server 2022, KB5129237, fixed Remote Desktop Services instability, but the same outlets report that it did not fix the printing failure. As of September 30, Microsoft had not acknowledged the printer-driver problem on its Windows Server 2022 release health page. If you run Server 2022 as a print or Remote Desktop server, test printing with your real drivers before rolling the update out, which is exactly the pilot step above.
Frequently asked questions
- What is CVE-2026-69769?
- CVE-2026-69769 is a remote code execution flaw in the Windows HTTP Print Provider, fixed on September 8, 2026. It's a heap-based buffer overflow that Microsoft rates Critical with a CVSS score of 9.8, because an attacker can exploit it over a network with no sign-in and no user interaction. Microsoft says it wasn't exploited when patched.
- Was the September 2026 Windows printing flaw exploited in the wild?
- No. Microsoft says CVE-2026-69769 was neither publicly disclosed nor exploited when it was patched on September 8, 2026, and rates it "Exploitation Unlikely." The month's two actively exploited zero-days, CVE-2026-81963 and CVE-2026-85880, were Windows elevation-of-privilege flaws unrelated to printing. Install the September update promptly anyway.
- Which Windows update fixes the HTTP Print Provider vulnerability?
- The fix ships in the regular September 8, 2026 cumulative updates, so no separate patch is needed. On Windows 11 24H2 and 25H2 it's KB5124008, and on Windows 10 22H2 it's KB5122878, an Extended Security Update release. For other Windows versions, check Microsoft's Security Update Guide entry for CVE-2026-69769.
- Do Windows 10 PCs get the September 2026 printer security fixes?
- Windows 10 22H2 gets them through KB5122878, which is an Extended Security Update (ESU) release, meaning it's aimed at PCs enrolled in Microsoft's ESU program. If your office still runs Windows 10, confirm each PC's ESU enrollment and look for KB5122878 in its update history, or plan the move to Windows 11.
Sources
Fact-checked : figures and claims in this article were cross-checked against at least three independent published sources. Where a vendor's own documentation is the only authoritative source, the article attributes the claim to that vendor. The main sources are listed below.
- September 2026 Security Updates (release document) — Microsoft Security Response Center, 2026-09-08
- CVE-2026-69769: Windows HTTP Print Provider Remote Code Execution Vulnerability — Microsoft Security Response Center, 2026-09-08
- CVE-2026-68848: Windows Print Spooler Components Elevation of Privilege Vulnerability — Microsoft Security Response Center, 2026-09-08
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days — BleepingComputer, 2026-09
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days — SecurityWeek, 2026-09
- Patch Tuesday Sets Another Record With 974 CVEs — Dark Reading, 2026-09
- Microsoft's September 2026 Patch Tuesday Addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880) — Tenable, 2026-09
- Microsoft Plugs Nearly 1,000 Security Holes — KrebsOnSecurity, 2026-09
- Patch Tuesday Analysis: September 2026 — CrowdStrike, 2026-09
- Microsoft Patch Tuesday, September 2026 Security Update Review — Qualys, 2026-09-08
- Microsoft Patch Tuesday, September 2026 Security Update Review (ThreatPROTECT) — Qualys, 2026-09-09
- Microsoft Patch Tuesday for September 2026 — Cisco Talos, 2026-09
- Warning: Microsoft Patch Tuesday September 2026 patches 964 vulnerabilities, 104 critical — Centre for Cybersecurity Belgium
- KB5124008 Windows 11 September 2026 update — Pureinfotech, 2026-09
- I tested the Windows 11 September 2026 update: everything new, improved and fixed — Windows Latest, 2026-09-08
- Microsoft releases Windows 10 KB5122878 extended security update — BleepingComputer, 2026-09
- Latest Windows September 2026 update apparently breaks printing, again — Neowin, 2026-09-18
- Report: Windows Server 2022 Users Hit by Printing Issues After September 2026 Update — Windows Report
- Gibt es Probleme mit Windows-Druckerfreigaben (evtl. Sept. 2026-Updates)? — Borncity, 2026-09-18
- September 14, 2026—KB5129237 (OS Build 20348.5631) Out-of-band — Microsoft Support, 2026-09-14
- Windows Server 2022 known issues and notifications — Microsoft Learn (Windows release health), 2026-09-30
About Valley Printer Pros Team
Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.
Get Expert AdviceServing San Fernando Valley Businesses
We provide on-site printer consulting, setup, and lease escape support across the Valley:
Related Articles
On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.
On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.
On July 31, Sharp and Toshiba Tec disclosed three flaws in their office MFPs, and NIST's vulnerability database published them August 3. The most practical one: affected models built for markets outside Japan, including the US, shipped with user authentication turned off. Turn it on, and ask your dealer for the firmware that fixes the other two.
Need Help with Your Printer Decisions?
Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.