September 2026 Windows print stack vulnerabilities
Microsoft's September 2026 security updates, released on 2026-09-08, fix fifteen vulnerabilities in the Windows print stack. Twelve are in the Windows Print Spooler, two are in the Windows HTTP Print Provider, and one is in the Print Workflow service. If you run ScrewDrivers, you probably want to know which of these touch components ScrewDrivers depends on, and whether there's anything beyond the Windows update itself worth looking at.
Short version: ScrewDrivers depends on the Print Spooler, so the spooler fixes matter to every ScrewDrivers deployment, and Microsoft's update is the fix. ScrewDrivers doesn't use the HTTP Print Provider or the Print Workflow service, so those three vulnerabilities are about your Windows configuration rather than your print path. This article lays out the facts and some optional hardening steps. What you do with them is your call.
This is an informational article. The vulnerabilities are in Windows, not in ScrewDrivers, and the fix for all fifteen is Microsoft's September 2026 update. The hardening options later on the page aren't Tricerat requirements or recommendations. They're changes some organizations make to reduce exposure, and each one has side effects. Test any of them in a pilot group before you roll it out, and if a change affects printing in your environment, contact Tricerat Support.
This article covers ScrewDrivers v7 on Windows session hosts (RDS, Citrix, VDI) and Windows endpoints. The Windows changes described here need local administrator rights and, in most cases, a Print Spooler restart.
The vulnerabilities at a glance
The table lists all fifteen, grouped by component and ordered by CVSS score. Severity is Microsoft's rating. Each CVE links to Microsoft's entry, which is the authoritative source.
| CVE | Component | Impact | CVSS | Severity | How it's reached |
|---|---|---|---|---|---|
| CVE-2026-69769 | HTTP Print Provider | Remote code execution | 9.8 | Critical | Unauthenticated, over the network, no user interaction |
| CVE-2026-69623 | HTTP Print Provider | Remote code execution | 8.0 | Important | Authenticated, over the network; user opens a crafted file |
| CVE-2026-85877 | Print Spooler | Remote code execution | 8.8 | Important | A Windows client connects to a malicious server (Windows 11 24H2 only) |
| CVE-2026-69346 | Print Spooler | Elevation to SYSTEM | 8.0 | Important | Authenticated, over the network; user interaction required |
| CVE-2026-69921 | Print Spooler | Elevation to SYSTEM | 7.8 | Important | Local authenticated user |
| CVE-2026-68848 | Print Spooler | Elevation to SYSTEM | 7.8 | Important | Local authenticated user |
| CVE-2026-70564 | Print Spooler | Elevation to SYSTEM | 7.8 | Important | Local authenticated user |
| CVE-2026-69364 | Print Spooler | Elevation to SYSTEM | 7.1 | Important | Authenticated, over the network; attacker must win a race condition |
| CVE-2026-68835 | Print Spooler | Elevation to SYSTEM | 7.1 | Important | Authenticated, over the network; high attack complexity |
| CVE-2026-69309 | Print Spooler | Elevation to SYSTEM | 7.0 | Important | Local authenticated user; attacker must win a race condition |
| CVE-2026-69838 | Print Spooler | Elevation to SYSTEM | 7.0 | Important | Local authenticated user; attacker must win a race condition |
| CVE-2026-69552 | Print Spooler | Information disclosure (heap memory) | 5.7 | Important | Authenticated, over the network; user interaction required |
| CVE-2026-69569 | Print Spooler | Denial of service | 5.7 | Important | Authenticated, over the network; user interaction required |
| CVE-2026-69344 | Print Spooler | Information disclosure (heap memory) | 5.5 | Important | Local authenticated user |
| CVE-2026-69602 | Print Workflow service | Elevation to SYSTEM | 7.1 | Important | Authenticated, over the network; attacker must win a race condition |
Microsoft rates three of the fifteen as "Exploitation More Likely": CVE-2026-69623, CVE-2026-69364, and CVE-2026-69921. None of the fifteen had been publicly disclosed or exploited when the updates shipped. CVE-2026-85877 affects only Windows 11 version 24H2. The rest affect supported Windows Server and Windows client releases broadly.
How ScrewDrivers relates to the affected components
Which of these matter to you depends on which parts of the Windows print stack ScrewDrivers touches.
The Print Spooler
ScrewDrivers is built on the Windows Print Spooler. On a session host, the spooler loads ScrewDrivers components at startup, and every ScrewDrivers printer in a user's session is a real Windows printer that the spooler manages, using the ScrewDrivers universal print driver. On a Windows endpoint, the ScrewDrivers client hands finished jobs to the local spooler for output to the physical printer. Stopping the Print Spooler stops ScrewDrivers printing, the same as it stops any other printing.
That means the twelve spooler vulnerabilities apply to a ScrewDrivers session host or endpoint the same way they apply to any Windows machine that prints, and Microsoft's update is the fix. The local elevation-of-privilege bugs are worth a second look on multi-user session hosts, because every logged-on user there is a local authenticated user sharing one spooler.
The HTTP Print Provider
The HTTP Print Provider is the Windows component behind the Internet Printing Client optional feature. It lets Windows connect to printers over HTTP and IPP URLs. ScrewDrivers carries print jobs over its own virtual channel inside your ICA or RDP session, or, in Enterprise deployments with the TCP/IP client, over its own transport to the ScrewDrivers Gateway. ScrewDrivers doesn't use the HTTP Print Provider, so the two HTTP Print Provider vulnerabilities are a question of whether the feature is installed on your machines, not of how ScrewDrivers prints.
The Print Workflow service
The Print Workflow service (PrintWorkflowUserSvc) supports print workflow apps, which are Microsoft Store apps that can modify a print job before it's spooled. ScrewDrivers doesn't use it. Microsoft's update is the fix for CVE-2026-69602.
Manufacturer drivers and Point and Print
None of the fifteen September vulnerabilities are driver-installation bugs, so this batch is different from PrintNightmare. It's still worth knowing that a session host running ScrewDrivers uses the single ScrewDrivers universal driver rather than manufacturer drivers, which keeps the driver surface on the host small.
What to do
Apply the September 2026 Windows updates
Apply the updates to session hosts, Print Servers, and endpoints. It's the fix for all fifteen vulnerabilities, and the only fix for the twelve in the Print Spooler. These updates patch Windows components, not ScrewDrivers, so treat them like any other Windows update: roll them out to a pilot group first, confirm printing works as expected, then deploy broadly. If you see a printing change after the update, contact Tricerat Support.
Optional hardening you can evaluate
The steps below go beyond the update. Some organizations use them to reduce how much of the print stack is reachable. Each has side effects, and none is required for ScrewDrivers. If you decide to try one, test it in a pilot group in your own environment before you deploy it widely.
Option: Remove the Internet Printing Client feature
If nothing in your environment prints to http:// or https:// printer URLs, the Internet Printing Client feature may have nothing to do. Removing it removes the HTTP Print Provider, which takes CVE-2026-69769 and CVE-2026-69623 off the table for that machine regardless of patch state.
Check first. Any printer whose port is an HTTP or HTTPS URL, on any machine, depends on this feature. So does any application that connects to printers by URL.
On Windows Server, from an elevated PowerShell prompt:
Uninstall-WindowsFeature -Name Internet-Print-Client
Restart-Service Spooler
On Windows 10 and 11 endpoints:
Disable-WindowsOptionalFeature -Online -FeatureName Printing-Foundation-InternetPrinting-Client
Restart-Service Spooler
Option: Block remote client connections to the spooler on session hosts
Several of the spooler vulnerabilities are reachable over the network by an authenticated user. Windows has a Group Policy setting that stops the spooler from accepting connections from other computers. ScrewDrivers on a session host works with the local spooler and reaches the endpoint through the session's virtual channel, so it isn't designed to depend on inbound connections to the session host's spooler.
The setting is Computer Configuration > Administrative Templates > Printers > Allow Print Spooler to accept client connections. Setting it to Disabled and restarting the Print Spooler on each host blocks remote print and management requests to that spooler.
Don't apply this policy to Print Servers or to any machine that shares printers with other computers. It blocks other machines from printing to or managing that spooler. Because this changes how the host's spooler behaves, validate ScrewDrivers printing and any other printing on a pilot host before you apply it to a group.
Not an option: Disabling the Print Spooler
Disabling the Print Spooler service does eliminate the spooler vulnerabilities on that machine. It also stops all printing, ScrewDrivers included, just as it did during PrintNightmare. The update is the fix.
Related articles
- Security Advisories is the registry entry for this batch (SA-003).
- PrintNightmare (CVE-2021-34527) Compatibility covers the 2021 spooler vulnerability and its workarounds.
- ScrewDrivers Security maps every security topic in this knowledge base.
- Microsoft Security Update Guide has the authoritative details for each CVE.