AIO APEX

Microsoft's September Patch Tuesday fixes 973 flaws and two actively exploited Windows zero-days

CyberSecurityNews
Share:
Microsoft's September Patch Tuesday fixes 973 flaws and two actively exploited Windows zero-days

Microsoft released its September 2026 Patch Tuesday update on Wednesday, addressing 973 security vulnerabilities across its software portfolio — including two Windows zero-days already being exploited in active attacks.

Two Zero-Days Under Active Attack

The first zero-day, CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) service. Exploiting it gives a local attacker System-level privileges — the highest level of access on a Windows machine. CISA added it to its Known Exploited Vulnerabilities catalog the same day patches shipped.

The second, CVE-2026-81963, targets the Windows Update Stack through an improper link-resolution vulnerability. Attackers with a foothold on a machine can use it to escalate privileges and deepen control — making it a classic post-exploitation tool. It too landed immediately on CISA's KEV list.

Both are classified as Important rather than Critical. The active-exploitation status makes them urgent patches regardless of severity rating.

Scale of the Release

September 2026 is one of the heaviest Patch Tuesdays on record. Of the 973 flaws fixed, 438 are elevation-of-privilege issues and 258 are remote code execution vulnerabilities. Three vulnerabilities earned Critical classifications: CVE-2026-83939, CVE-2026-83498, and CVE-2026-83501, spanning Remote Desktop Client, Windows Message Queuing, and Print Spooler.

Notable Office RCE vulnerabilities were also patched, including issues in Excel (CVE-2026-81959, CVE-2026-81953) and Word (CVE-2026-81952) — common enterprise targets in phishing campaigns.

What to Do Now

Security teams should treat CVE-2026-85880 and CVE-2026-81963 as immediate priorities: both are confirmed exploited in the wild, and privilege-escalation zero-days are typically bundled with other exploits in multi-stage attacks. Organizations running Windows Update in a managed environment should verify deployment is complete before end of day.

Source: CyberSecurityNews, SecurityWeek

Originally reported by CyberSecurityNews. Read the original article for additional details.

View original source
Share: