September 2026 Patch Tuesday: Two Windows Zero-Days Under Attack

CISA added two actively exploited Windows privilege-escalation flaws to its KEV catalog the same day Microsoft patched them in September's Patch Tuesday release.

Microsoft Security Response Center banner graphic used to illustrate Patch Tuesday security coverage
Image: Microsoft.

What happened

Microsoft's September 2026 Patch Tuesday release, published on September 8, 2026, included fixes for two Windows elevation-of-privilege flaws that were already being exploited before a patch existed. The Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerabilities (KEV) catalog the same day: CVE-2026-81963, a Windows Update Stack elevation-of-privilege bug, and CVE-2026-85880, a Windows Advanced Local Procedure Call (ALPC) elevation-of-privilege bug. Both let an attacker who already has low-level code execution on a machine escalate to SYSTEM, the highest privilege level on Windows.

Neither vulnerability lets an outsider break into a machine remotely on its own. Instead, both are the second stage of an attack: a piece of malware or a malicious script that is already running with limited rights uses the flaw to take full control of the device. That combination — no user interaction required, and a straight shot to SYSTEM — is why Microsoft rated both "Important" for severity while CISA still moved to force a fast fix across federal networks.

Key facts
  • CVE-2026-81963 — Windows Update Stack elevation of privilege, CVSS base score 7.8, exploited in the wild per Microsoft.
  • CVE-2026-85880 — Windows ALPC elevation of privilege, CVSS base score 7.8, exploited in the wild per Microsoft.
  • Both added to CISA's KEV catalog on September 8, 2026; the federal remediation deadline was September 22, 2026, which has already passed.
  • Neither flaw is remotely exploitable by itself — both require an attacker to already have some code execution on the target device.
  • Fixes shipped as part of the regular September 2026 cumulative updates; no separate out-of-band patch was required.

CVE-2026-81963: Windows Update Stack elevation of privilege

According to Microsoft's Security Update Guide entry for CVE-2026-81963, the bug is an "improper link resolution before file access," also known as a link-following flaw, in the Windows Update Stack. Microsoft's advisory states that "an authorized attacker" — meaning someone who can already log in or run code locally, even with low privileges — can abuse how the Update Stack resolves file paths to elevate privileges without any further user interaction. Microsoft's own FAQ for the vulnerability is blunt about the payoff: an attacker who successfully exploits it "could gain SYSTEM privileges."

Microsoft's data lists the flaw under two weakness categories, CWE-59 (improper link resolution before file access) and CWE-284 (improper access control), and scores it CVSS 3.1 base 7.8 with a vector of AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — local attack vector, low complexity, low privileges required, no user interaction, and high impact across confidentiality, integrity and availability. Microsoft's temporal score, which factors in that a working exploit already exists, is 7.2, and the "Exploitability" field in Microsoft's own database reads "Exploitation Detected," Microsoft's internal label for a vulnerability being actively used in attacks. The National Vulnerability Database's entry for CVE-2026-81963 mirrors Microsoft's own CVSS scoring exactly.

Per Microsoft's affected-product listing, CVE-2026-81963 hits the newest branches of Windows: Windows 11 versions 23H2, 24H2, 25H2 and 26H1 (x64 and ARM64 builds) and Windows Server 2025, including the Server Core installation option. It does not appear in Microsoft's product list for older Windows 10 or Windows Server releases, which suggests the flawed code path was introduced relatively recently in the Update Stack.

CVE-2026-85880: Windows ALPC elevation of privilege

The second zero-day sits in a much older and more central piece of Windows plumbing. Advanced Local Procedure Call (ALPC) is the internal messaging system Windows processes use to talk to each other, including communication between low-privilege sandboxed processes and higher-privilege system services. Microsoft's Security Update Guide entry for CVE-2026-85880 describes it as a heap-based buffer overflow in Windows ALPC that allows "an authorized attacker" to elevate privileges locally. The advisory's own FAQ spells out the practical attack path: someone who can already execute code inside a low-privilege AppContainer — the sandbox Windows uses for apps like those from the Microsoft Store — can use the bug to break out of that sandbox and reach SYSTEM, with no extra user interaction needed.

Microsoft classifies the flaw under CWE-122 (heap-based buffer overflow) and CWE-908 (use of uninitialized resource), and — like the Update Stack bug — scores it CVSS 3.1 base 7.8, temporal 7.2, with the identical local/low-complexity/low-privilege vector. Microsoft's database again flags it "Exploitation Detected." NVD's record for CVE-2026-85880 confirms the same scoring.

Unlike the Update Stack flaw, CVE-2026-85880's reach is enormous: Microsoft's affected-product data lists it against roughly twenty separate product editions, running from Windows Server 2012 and 2012 R2 (including Server Core) through Server 2016, 2019 and 2022, plus Windows 10 versions 1607, 1809, 21H2 and 22H2 in their 32-bit, x64 and ARM64 variants. Because ALPC is such a foundational Windows subsystem, the bug has apparently lingered across more than a decade of Windows releases before this month's fix.

DetailCVE-2026-81963CVE-2026-85880
ComponentWindows Update StackWindows ALPC
Vulnerability typeLink following / improper access controlHeap-based buffer overflow
CVSS 3.1 base score7.8 (Important)7.8 (Important)
Privileges requiredLowLow (AppContainer sandbox escape)
User interactionNoneNone
Actively exploited (Microsoft)YesYes
Added to CISA KEVSeptember 8, 2026September 8, 2026
Affected productsWindows 11 23H2/24H2/25H2/26H1, Windows Server 2025Windows Server 2012–2022, Windows 10 1607/1809/21H2/22H2
Primary fixKB5122880, KB5122871, KB5124008, KB5124012KB5122876, KB5122878, KB5122882, KB5123065, KB5123066, KB5123099

Why these zero-days matter

Neither CVE-2026-81963 nor CVE-2026-85880 is a "remote" vulnerability that lets an attacker break into a Windows machine from across the internet with no prior access. Both require some existing foothold — a phishing payload that already got code running, a malicious app that already landed in a sandbox, or a compromised low-privilege account. That is exactly why they matter so much operationally: privilege-escalation zero-days like these are the second link in almost every serious intrusion chain. An attacker who gets initial access through a phishing email, a vulnerable browser plugin, or a compromised third-party app typically starts with limited rights. Bugs like CVE-2026-81963 and CVE-2026-85880 are what turn that limited foothold into full administrative control of the machine — the step that lets an intruder disable security tools, dump credentials, and move laterally across a network.

Microsoft has not published attribution for who is exploiting these bugs or named specific campaigns, and this article does not speculate beyond what Microsoft's and CISA's own advisories state: both vulnerabilities are marked as exploited in the wild, and neither agency has disclosed the identity of the attackers or victims involved. What is clear from the federal government's own response is the urgency: CISA's Binding Operational Directive 26-04 requires U.S. federal civilian agencies to patch KEV-listed vulnerabilities by a fixed deadline, and it applied that deadline here too. It's a pattern this outlet has tracked across several vendors this year, including a previously reported actively exploited SharePoint flaw and an exploited F5 BIG-IP APM vulnerability.

CISA's KEV listing and the remediation deadline

CISA's own Known Exploited Vulnerabilities catalog lists both CVEs with a "date added" of September 8, 2026 — the same day Microsoft shipped the fixes — and a required remediation due date of September 22, 2026 for federal civilian executive branch agencies, under CISA's Binding Operational Directive 26-04. Because today's date is September 28, 2026, that federal deadline has already passed: any covered federal system that had not applied the September 2026 updates by September 22 is now out of compliance with the directive, not simply approaching a deadline.

CISA's catalog entries describe CVE-2026-81963 as a "Microsoft Windows Link Following Vulnerability" and CVE-2026-85880 as a "Microsoft Windows Heap-Based Buffer Overflow Vulnerability," and list "knownRansomwareCampaignUse" as "Unknown" for both — meaning CISA has not confirmed either flaw's use in a known ransomware operation, only that it has confirmed active exploitation generally. BOD 26-04 technically binds only federal civilian agencies, but security teams across the private sector commonly treat CISA's KEV deadlines as a practical patch-priority signal, since inclusion in the catalog means there is confirmed, not theoretical, exploitation.

What to patch

Both fixes are included in Microsoft's standard September 2026 cumulative updates — there was no separate out-of-band release for either CVE. According to Microsoft's Security Update Guide, the relevant updates are:

  • Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 (fixes CVE-2026-81963): KB5124008 and the parallel builds KB5122871, KB5122880 and KB5124012, depending on version and architecture.
  • Windows Server 2012 through Server 2022 and Windows 10 (1607–22H2) (fixes CVE-2026-85880): KB5122876, KB5122878, KB5122882, and the monthly rollups KB5123066 and KB5123065, plus KB5123099, depending on the specific OS version.

Because CVE-2026-85880 alone touches editions still supported only under Extended Security Updates (ESU), organizations running Windows Server 2012 or Windows Server 2012 R2 under an ESU agreement should confirm their ESU licensing is active before assuming the patch will download automatically — Microsoft does not push ESU-only fixes to devices without a valid ESU key. Windows 11 users tracking what else Microsoft shipped this cycle can also see our separate coverage of the September 2026 Windows 11 preview update. For every affected edition, Windows Update, WSUS, and the Microsoft Update Catalog all carry the correct package for the specific build and architecture in use, and Microsoft's own support pages for each KB number list exact prerequisites and known issues.

The rest of September's Patch Tuesday

These two zero-days were not the only serious bugs fixed this month. Microsoft's own Security Update Guide also lists two critical remote code execution flaws shipped in the same September 2026 release: CVE-2026-73009, a use-after-free in the Windows Secure Socket Tunneling Protocol (SSTP) service, and CVE-2026-72982, a stack-based buffer overflow in Windows Netlogon. Both carry a CVSS base score of 9.8 in Microsoft's own scoring, and both are rated "Critical." Unlike the two KEV zero-days, however, Microsoft's database rates exploitation of CVE-2026-73009 as "Exploitation Less Likely" and CVE-2026-72982 as "Exploitation Unlikely," and neither appears in CISA's KEV catalog as of this writing — meaning they are unpatched-and-serious, but not (yet) confirmed as actively exploited the way the two elevation-of-privilege bugs are.

On the overall size of the release, outside trackers have circulated a range of total CVE counts for September 2026 — figures anywhere from the mid-900s to over 1,100 have been reported by various outlets, which is a wide enough spread to be treated with caution rather than repeated as fact. A direct query of Microsoft's own Security Update Guide database shows 998 CVEs attributed to Microsoft's own CNA (CVE Numbering Authority) for the "2026-Sep" release, separate from several thousand additional entries covering open-source components bundled in Microsoft's Azure Linux (Mariner) images, which some trackers count and others exclude. That difference in methodology — whether Mariner/open-source advisories, revised prior-month entries, or non-Microsoft CNAs are folded into the total — is the most likely explanation for the conflicting headline numbers, and readers should treat any single round total for this Patch Tuesday with some skepticism unless the source specifies exactly what it is counting.

How to apply the updates

For most home and small-business users, the fixes arrive automatically through Windows Update: open Settings, go to Windows Update, and select "Check for updates." Devices set to receive updates automatically should already show the September 2026 cumulative update as installed or pending a restart. IT administrators managing fleets through WSUS, Microsoft Configuration Manager, or Intune should confirm the relevant KB numbers for each OS version and architecture in their environment are approved and deployed, paying particular attention to older Server editions affected by CVE-2026-85880, since those environments are both higher-value targets and more likely to be running on extended servicing agreements with different deployment rules. Because both vulnerabilities require local code execution to exploit, patching them is only one layer of defense — organizations should also review endpoint detection alerts for unusual local privilege changes and audit which applications are permitted to run with elevated rights, particularly on systems that cannot be patched immediately.

What's next

Microsoft has not indicated whether it expects to publish further advisory updates on either CVE-2026-81963 or CVE-2026-85880; both entries were last revised in mid-September 2026 with acknowledgement and CVSS-vector corrections rather than new technical detail. Given that CISA's own federal remediation deadline for both bugs has already passed, the near-term story for most organizations is less about a countdown and more about verifying that the September 2026 updates are actually installed. Security teams should also keep an eye on Microsoft's Security Update Guide for any late-arriving detection guidance or indicators of compromise, and watch CISA's KEV catalog for whether the two RCE bugs mentioned above — the SSTP and Netlogon flaws — get added if evidence of active exploitation emerges for those as well.

Frequently asked questions

What are CVE-2026-81963 and CVE-2026-85880?

They are two Windows elevation-of-privilege vulnerabilities patched in Microsoft's September 2026 Patch Tuesday release: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC (Advanced Local Procedure Call). Both let an attacker who already has some code execution on a device escalate to SYSTEM privileges, and both were confirmed by Microsoft as exploited in the wild.

Can these vulnerabilities be exploited remotely, over the internet?

No. Both are local elevation-of-privilege bugs, meaning an attacker must already have some form of code execution on the target machine, such as through malware, a malicious app, or a compromised low-privilege account, before they can use these flaws to gain full SYSTEM control.

Which Windows versions are affected?

CVE-2026-81963 affects Windows 11 versions 23H2, 24H2, 25H2 and 26H1, plus Windows Server 2025, per Microsoft's Security Update Guide. CVE-2026-85880 has a much wider footprint, affecting Windows Server 2012 through Server 2022 and Windows 10 versions 1607, 1809, 21H2 and 22H2.

Is the CISA remediation deadline for these CVEs still coming up?

No. CISA's Known Exploited Vulnerabilities catalog lists a federal civilian agency remediation deadline of September 22, 2026 for both CVEs, under Binding Operational Directive 26-04. That date has already passed.

How do I patch CVE-2026-81963 and CVE-2026-85880?

Both fixes are included in Microsoft's regular September 2026 cumulative updates, available through Windows Update, WSUS, Microsoft Configuration Manager, Intune, or the Microsoft Update Catalog. No separate out-of-band patch is required; installing the standard September 2026 security update for your specific Windows version and architecture resolves both flaws.

How many total vulnerabilities did Microsoft fix in September 2026's Patch Tuesday?

There is no single clean published figure. Outside trackers have reported wildly different totals, from the mid-900s to over 1,100. A direct query of Microsoft's own Security Update Guide shows 998 CVEs attributed to Microsoft's own CVE Numbering Authority for this release, separate from thousands of additional open-source Azure Linux (Mariner) component advisories that some trackers include and others don't.

Sources

More on Patch Tuesday →Patch TuesdayWindowsZero-DayCISA KEVMicrosoft Security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all