Microsoft's Record September 2026 Patch Tuesday Fixes 974 CVEs, Two Already Exploited
Microsoft's September 2026 Patch Tuesday addressed 974 CVEs — its largest-ever monthly release — including two zero-day vulnerabilities already being actively exploited at the time of release. One exploited flaw, CVE-2026-81963, is a local privilege escalation in the Windows Update Stack itself, meaning the patch-delivery mechanism became an attack surface capable of elevating a low-privileged user to SYSTEM. The other, CVE-2026-85880, is a heap buffer overflow in Windows ALPC that allows a sandboxed AppContainer process to escape and reach SYSTEM-level privileges. Both flaws require existing local access and serve as escalation steps in broader attack chains rather than standalone entry points. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on 8 September 2026, setting a federal remediation deadline of 22 September 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in