
Microsoft has released its September 2026 security updates, fixing two Windows elevation-of-privilege vulnerabilities that attackers are already exploiting in the wild.
The company’s broader Patch Tuesday release addresses 974 CVEs across its products, including 723 affecting Windows.
The two actively exploited flaws are tracked as CVE-2026-85880 and CVE-2026-81963. Microsoft says neither vulnerability was publicly disclosed before patches became available on September 8, but it has already detected exploitation in the wild.
CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC) and combines a heap-based buffer overflow with the use of an uninitialized resource. Microsoft says a low-privileged attacker who can execute code inside an AppContainer can exploit the flaw locally to escape the sandbox and obtain SYSTEM privileges, without requiring any user interaction. The vulnerability was credited to researchers at Volexity and Proofpoint.
Local privilege-escalation flaws are commonly chained with vulnerabilities that provide initial code execution; as a result, these bugs can be particularly valuable to attackers trying to take full control of compromised systems.
The second flaw, CVE-2026-81963, affects the Windows Update Stack and results from improper link resolution and access controls. An attacker with low-level privileges can exploit it locally to elevate to SYSTEM. Microsoft Threat Intelligence Center (MSTIC) discovered the issue.
September’s release also contains a large number of fixes outside Windows, including 111 vulnerabilities in Microsoft Office, 62 in SQL products, 22 in developer tools, 16 in SharePoint Server, 12 in Azure, and nine in Exchange Server.
For Windows 11 24H2 and 25H2, Microsoft is distributing the fixes through KB5124008, bringing systems to OS builds 26100.9445 and 26200.9445, respectively. Windows 11 26H1 receives KB5124012, updating systems to build 28000.2954.
Both cumulative updates also expand Microsoft’s deployment of replacement Secure Boot certificates, as certificates used by many Windows devices began expiring in June 2026. Microsoft says systems that have not yet received the newer certificates will continue to boot and install normal Windows updates while the rollout continues.
Users running Windows 11 24H2 Home or Pro should also note that those editions reach end of servicing on October 13, 2026. After that date, they will no longer receive monthly security updates, making an upgrade to a supported Windows release increasingly important.
Windows users should install September’s cumulative updates as soon as practical, particularly because two privilege-escalation vulnerabilities are already being exploited.
Users can install the updates through Settings > Windows Update > Download & install all.
A system restart is required to complete the update. Backing up important data is also advised to reduce the risk of data loss from installation errors or unexpected power loss.







Leave a Reply