Microsoft Patches Two Actively Exploited Windows Privilege Escalation Flaws in Record Update
Microsoft's September 2026 Patch Tuesday addressed between 966 and 997 CVEs, making it the largest security update on record. Two vulnerabilities — CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows ALPC mechanism — were confirmed exploited in the wild before patches were released, both carrying a CVSS score of 7.8. Both flaws allow local attackers to escalate privileges to SYSTEM level, and CISA added them to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a federal remediation deadline of September 22. The update also includes multiple pre-authentication remote code execution vulnerabilities rated CVSS 9.8, affecting components such as Windows DNS Server, Remote Desktop Services, and Exchange Server. Security researchers have attributed the record-breaking vulnerability volume in part to AI-assisted research, raising concerns that traditional patch-everything approaches are no longer operationally viable.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in