CiberLATAMbywhalemate

Microsoft fixes 974 flaws, including two zero-days

Microsoft’s September 2026 Patch Tuesday fixed 974 vulnerabilities, including two actively exploited Windows zero-days.

Whalemate Labs · AI-assisted researchPublished:3 min read

Microsoft released its September 2026 Patch Tuesday with 974 vulnerabilities fixed, according to counts cited by several firms. Among them are two actively exploited zero-days, CVE-2026-81963 and CVE-2026-85880, both tied to privilege escalation in Windows and already in CISA’s KEV catalog.

Microsoft rolled out its September 2026 Patch Tuesday with 974 vulnerabilities fixed, according to Microsoft’s count cited by SecurityWeek, The Record, CyberScoop and other cycle analyses. Among the flaws are two actively exploited Windows zero-days, tracked as CVE-2026-81963 and CVE-2026-85880, which CISA has already added to its Known Exploited Vulnerabilities catalog.

What did Microsoft fix in this cycle?

Microsoft closed an unusually large batch of flaws that different vendors place between 964 and 974 CVEs, depending on the methodology used by each one. Tenable counted 964 vulnerabilities, including 104 critical and 860 important issues, while Qualys and tbreak.com reported 974. Other outlets, including Cybersecurity News, The Record and SecurityWeek, cited 973 or 974 based on Microsoft release notes and official guidance.

KrebsOnSecurity described the package as Microsoft’s largest patch set to date. Windows Latest said that for Windows 11, the rollout arrived as cumulative update KB5124008, with builds 26200.9445 and 26100.9445, and called it the biggest update of the year by volume of changes and fixes.

Which are the two most sensitive vulnerabilities?

The two most closely watched flaws are CVE-2026-81963 and CVE-2026-85880, both confirmed as actively exploited by Microsoft and CISA. According to SecurityWeek, The Record, The Hacker News, CrowdStrike, WindowsForum and other analyses, they allow local privilege escalation to SYSTEM in Windows Update Stack and Windows ALPC, respectively.

In the case of CVE-2026-81963, NIST’s NVD describes it as an improper link resolution before file access issue in Windows Update Stack that lets an authorized attacker raise privileges locally. NIST says it affects Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025, including Server Core installations. Cisco Talos said the flaw combines incorrect link resolution before file access with weak access controls, allowing update-process writes to be redirected to attacker-controlled paths.

AZ Pentest, Lansweeper and Windows Latest agree that Microsoft confirmed active exploitation and that the redirection can end in SYSTEM privileges. The Hacker News also reported a CVSS score of 7.8 for this CVE, and Zero Day Initiative classified it as Important in its internal technical table.

What is known about CVE-2026-85880?

CVE-2026-85880 appears in NVD as a Microsoft Windows Heap-Based Buffer Overflow Vulnerability and, according to ThreatClaw.ai, Feedly CVE Tracker, Cisco Talos, CrowdStrike and The Hacker News, affects the Windows ALPC messaging layer. The official source described by The Hacker News says that an attacker running code inside a low-privilege AppContainer can use it to escape the sandbox and elevate privileges on the affected system.

CrowdStrike added that the heap overflow in ALPC can lead to code execution with elevated privileges, while Cisco Talos linked it to use of uninitialized resources. Feedly CVE Tracker noted that no functional public exploits were found among the analyzed URLs, but exploitation in the wild was confirmed by official sources, which raises its operational risk.

What did CISA and response teams say?

CISA added CVE-2026-81963 and CVE-2026-85880 to its Known Exploited Vulnerabilities Catalog and set Sept. 22, 2026, as the deadline for U.S. federal agencies to apply patches, according to Qualys and The Record. WindowsForum added that the warning was also picked up by the Canadian Centre for Cyber Security, aligning its stance with CISA’s.

Splashtop warned that, although both CVEs are listed as Important rather than Critical, real-world exploitation makes them a high patching priority compared with other flaws that may have a higher nominal severity but no known exploitation. S-EDV, for its part, said both issues carry a CVSS score of 7.8 and are the most relevant vulnerabilities in September 2026 Patch Tuesday for Windows administrators.

Sources

View all