Skip to main content

September 2026 Windows print stack vulnerabilities

Microsoft's September 2026 security updates, released on 2026-09-08, fix fifteen vulnerabilities in the Windows print stack. Twelve are in the Windows Print Spooler, two are in the Windows HTTP Print Provider, and one is in the Print Workflow service. If you run ScrewDrivers, you probably want to know which of these touch components ScrewDrivers depends on, and whether there's anything beyond the Windows update itself worth looking at.

Short version: ScrewDrivers depends on the Print Spooler, so the spooler fixes matter to every ScrewDrivers deployment, and Microsoft's update is the fix. ScrewDrivers doesn't use the HTTP Print Provider or the Print Workflow service, so those three vulnerabilities are about your Windows configuration rather than your print path. This article lays out the facts and some optional hardening steps. What you do with them is your call.

About this article

This is an informational article. The vulnerabilities are in Windows, not in ScrewDrivers, and the fix for all fifteen is Microsoft's September 2026 update. The hardening options later on the page aren't Tricerat requirements or recommendations. They're changes some organizations make to reduce exposure, and each one has side effects. Test any of them in a pilot group before you roll it out, and if a change affects printing in your environment, contact Tricerat Support.

This article covers ScrewDrivers v7 on Windows session hosts (RDS, Citrix, VDI) and Windows endpoints. The Windows changes described here need local administrator rights and, in most cases, a Print Spooler restart.

The vulnerabilities at a glance​

The table lists all fifteen, grouped by component and ordered by CVSS score. Severity is Microsoft's rating. Each CVE links to Microsoft's entry, which is the authoritative source.

CVEComponentImpactCVSSSeverityHow it's reached
CVE-2026-69769HTTP Print ProviderRemote code execution9.8CriticalUnauthenticated, over the network, no user interaction
CVE-2026-69623HTTP Print ProviderRemote code execution8.0ImportantAuthenticated, over the network; user opens a crafted file
CVE-2026-85877Print SpoolerRemote code execution8.8ImportantA Windows client connects to a malicious server (Windows 11 24H2 only)
CVE-2026-69346Print SpoolerElevation to SYSTEM8.0ImportantAuthenticated, over the network; user interaction required
CVE-2026-69921Print SpoolerElevation to SYSTEM7.8ImportantLocal authenticated user
CVE-2026-68848Print SpoolerElevation to SYSTEM7.8ImportantLocal authenticated user
CVE-2026-70564Print SpoolerElevation to SYSTEM7.8ImportantLocal authenticated user
CVE-2026-69364Print SpoolerElevation to SYSTEM7.1ImportantAuthenticated, over the network; attacker must win a race condition
CVE-2026-68835Print SpoolerElevation to SYSTEM7.1ImportantAuthenticated, over the network; high attack complexity
CVE-2026-69309Print SpoolerElevation to SYSTEM7.0ImportantLocal authenticated user; attacker must win a race condition
CVE-2026-69838Print SpoolerElevation to SYSTEM7.0ImportantLocal authenticated user; attacker must win a race condition
CVE-2026-69552Print SpoolerInformation disclosure (heap memory)5.7ImportantAuthenticated, over the network; user interaction required
CVE-2026-69569Print SpoolerDenial of service5.7ImportantAuthenticated, over the network; user interaction required
CVE-2026-69344Print SpoolerInformation disclosure (heap memory)5.5ImportantLocal authenticated user
CVE-2026-69602Print Workflow serviceElevation to SYSTEM7.1ImportantAuthenticated, over the network; attacker must win a race condition

Microsoft rates three of the fifteen as "Exploitation More Likely": CVE-2026-69623, CVE-2026-69364, and CVE-2026-69921. None of the fifteen had been publicly disclosed or exploited when the updates shipped. CVE-2026-85877 affects only Windows 11 version 24H2. The rest affect supported Windows Server and Windows client releases broadly.

How ScrewDrivers relates to the affected components​

Which of these matter to you depends on which parts of the Windows print stack ScrewDrivers touches.

The Print Spooler​

ScrewDrivers is built on the Windows Print Spooler. On a session host, the spooler loads ScrewDrivers components at startup, and every ScrewDrivers printer in a user's session is a real Windows printer that the spooler manages, using the ScrewDrivers universal print driver. On a Windows endpoint, the ScrewDrivers client hands finished jobs to the local spooler for output to the physical printer. Stopping the Print Spooler stops ScrewDrivers printing, the same as it stops any other printing.

That means the twelve spooler vulnerabilities apply to a ScrewDrivers session host or endpoint the same way they apply to any Windows machine that prints, and Microsoft's update is the fix. The local elevation-of-privilege bugs are worth a second look on multi-user session hosts, because every logged-on user there is a local authenticated user sharing one spooler.

The HTTP Print Provider​

The HTTP Print Provider is the Windows component behind the Internet Printing Client optional feature. It lets Windows connect to printers over HTTP and IPP URLs. ScrewDrivers carries print jobs over its own virtual channel inside your ICA or RDP session, or, in Enterprise deployments with the TCP/IP client, over its own transport to the ScrewDrivers Gateway. ScrewDrivers doesn't use the HTTP Print Provider, so the two HTTP Print Provider vulnerabilities are a question of whether the feature is installed on your machines, not of how ScrewDrivers prints.

The Print Workflow service​

The Print Workflow service (PrintWorkflowUserSvc) supports print workflow apps, which are Microsoft Store apps that can modify a print job before it's spooled. ScrewDrivers doesn't use it. Microsoft's update is the fix for CVE-2026-69602.

Manufacturer drivers and Point and Print​

None of the fifteen September vulnerabilities are driver-installation bugs, so this batch is different from PrintNightmare. It's still worth knowing that a session host running ScrewDrivers uses the single ScrewDrivers universal driver rather than manufacturer drivers, which keeps the driver surface on the host small.

What to do​

Apply the September 2026 Windows updates​

Apply the updates to session hosts, Print Servers, and endpoints. It's the fix for all fifteen vulnerabilities, and the only fix for the twelve in the Print Spooler. These updates patch Windows components, not ScrewDrivers, so treat them like any other Windows update: roll them out to a pilot group first, confirm printing works as expected, then deploy broadly. If you see a printing change after the update, contact Tricerat Support.

Optional hardening you can evaluate​

The steps below go beyond the update. Some organizations use them to reduce how much of the print stack is reachable. Each has side effects, and none is required for ScrewDrivers. If you decide to try one, test it in a pilot group in your own environment before you deploy it widely.

Option: Remove the Internet Printing Client feature​

If nothing in your environment prints to http:// or https:// printer URLs, the Internet Printing Client feature may have nothing to do. Removing it removes the HTTP Print Provider, which takes CVE-2026-69769 and CVE-2026-69623 off the table for that machine regardless of patch state.

Check first. Any printer whose port is an HTTP or HTTPS URL, on any machine, depends on this feature. So does any application that connects to printers by URL.

On Windows Server, from an elevated PowerShell prompt:

Uninstall-WindowsFeature -Name Internet-Print-Client
Restart-Service Spooler

On Windows 10 and 11 endpoints:

Disable-WindowsOptionalFeature -Online -FeatureName Printing-Foundation-InternetPrinting-Client
Restart-Service Spooler

Option: Block remote client connections to the spooler on session hosts​

Several of the spooler vulnerabilities are reachable over the network by an authenticated user. Windows has a Group Policy setting that stops the spooler from accepting connections from other computers. ScrewDrivers on a session host works with the local spooler and reaches the endpoint through the session's virtual channel, so it isn't designed to depend on inbound connections to the session host's spooler.

The setting is Computer Configuration > Administrative Templates > Printers > Allow Print Spooler to accept client connections. Setting it to Disabled and restarting the Print Spooler on each host blocks remote print and management requests to that spooler.

Scope this carefully

Don't apply this policy to Print Servers or to any machine that shares printers with other computers. It blocks other machines from printing to or managing that spooler. Because this changes how the host's spooler behaves, validate ScrewDrivers printing and any other printing on a pilot host before you apply it to a group.

Not an option: Disabling the Print Spooler​

Disabling the Print Spooler service does eliminate the spooler vulnerabilities on that machine. It also stops all printing, ScrewDrivers included, just as it did during PrintNightmare. The update is the fix.