TL;DR
Microsoft’s September 2026 Patch Tuesday fixes 996 vulnerabilities. Two of them are zero-days already exploited in the wild. Both are Windows elevation of privilege flaws that attackers can use to gain higher access.
- Product: Microsoft (2 products)
- Vulnerabilities: 2 flaws (CVE-2026-81963, CVE-2026-85880)
- Highest severity: 7.8 (High · CVSSv3)
- Worst impact: Windows Update Stack Elevation of Privilege
- Status: Exploited in the wild
- Action: Update to 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954 (+8) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-81963 | 7.8 | Windows Update Stack Elevation of Privilege | 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445 (+2) | Exploited in the wild |
| CVE-2026-85880 | 7.8 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege | 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725 (+4) | Exploited in the wild |
Why This Patch Tuesday Zero-Day Matters
Microsoft shipped one of its largest update sets this month. The September 2026 Patch Tuesday zero-day count sits at two, and both are under active attack. Attackers rarely burn working exploits on low-value bugs.
The release addresses 996 flaws in total. Among them, 119 rank as Critical and 258 allow remote code execution. Microsoft also flagged 58 vulnerabilities as more likely to be exploited soon.
Elevation of privilege bugs matter for one clear reason. They let an attacker who already has a foothold become an administrator. That step often turns a minor intrusion into a full compromise.
The Two Zero-Days Under Attack
Both exploited flaws carry a CVSS score of 7.8. Each affects a core Windows component.
CVE-2026-81963 – Windows Update Stack
CVE-2026-81963 is an elevation of privilege flaw in the Windows Update Stack. It was publicly disclosed and exploited before a fix existed. That combination meets the strict definition of a zero-day.
CVE-2026-85880 – Windows ALPC
CVE-2026-85880 affects the Windows Advanced Local Procedure Call (ALPC) subsystem. ALPC handles internal messaging between Windows processes. A flaw here gives attackers a reliable local privilege path.
How the Attacks Work
Both flaws are local privilege escalation issues. An attacker needs some existing access to the target first. They then abuse the vulnerable component to raise their permissions.
Microsoft has not published exploit details or victim counts. The advisory confirms active exploitation but withholds technical specifics. This is standard practice to slow copycat attacks.
Affected Products
The two zero-days affect supported Windows versions. The wider update also covers SQL Server, Exchange, SharePoint, Office, and Azure services. Several SQL Server flaws scored 8.8 and allow remote code execution.
One Azure AI Language flaw, CVE-2026-70352, reached the maximum 10.0 score. An Azure Active Directory B2C flaw, CVE-2026-83711, also hit 10.0.
Patch and Mitigation Steps
Apply the September 2026 updates without delay. Prioritize the two exploited zero-days first. Then patch the Critical remote code execution bugs.
Administrators should review the full list on the Microsoft Security Response Center update guide. The guide lists each CVE with its affected builds. Enable automatic updates where your environment allows it.
For the exploited elevation of privilege flaws, patching is the only reliable fix. No official workaround replaces the update. Test in a staging ring, then deploy across production quickly.
The Bottom Line
This Patch Tuesday zero-day pair proves attackers still favor privilege escalation. Fast patching remains the strongest defense. Treat both flaws as urgent and update this week.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!