Microsoft Patches 966 Flaws as Two Windows Zero-Days Come Under Active Attack
Vulnerabilities

Illustrative image generated with AI

Microsoft Patches 966 Flaws as Two Windows Zero-Days Come Under Active Attack

Microsoft fixed 966 flaws in record September Patch Tuesday, including two exploited Windows privilege-escalation zero-days leading to SYSTEM access.

Text generated by artificial intelligence, published without human review. AI transparency

Microsoft released security updates for 966 vulnerabilities on September 8, 2026, including two Windows privilege-escalation zero-days already being exploited.

Both zero-days can give attackers SYSTEM privileges after they obtain an initial foothold with limited permissions. One affects the Windows Update Stack, while the other provides an escape path from a low-privilege AppContainer through Windows Advanced Local Procedure Call.

Microsoft classifies both vulnerabilities as Important rather than Critical. Each carries a CVSS 3.1 base score of 7.8, requires local access and low privileges, and needs no user interaction.

A record Patch Tuesday with inconsistent category totals

The September 2026 Patch Tuesday is described as Microsoft’s largest security release to date. Its 966 vulnerabilities include a reported 105 Critical issues, although the published Critical breakdown accounts for only 104:

  • 81 remote-code-execution vulnerabilities
  • 20 elevation-of-privilege vulnerabilities
  • Two information-disclosure vulnerabilities
  • One security-feature-bypass vulnerability

The broader category figures also do not fully reconcile with the headline total. The reported distribution includes approximately 438 privilege-escalation flaws, 258 remote-code-execution issues, 173 information-disclosure bugs, 56 denial-of-service vulnerabilities, 19 security-feature bypasses, and 16 spoofing flaws. Those numbers add up to 960.

The discrepancies mean the category figures should be treated as approximate rather than as a complete, deduplicated accounting of all 966 vulnerabilities.

The total covers vulnerabilities released on Patch Tuesday itself. It excludes another 204 flaws addressed earlier this month across services and products including Azure AI Language, Azure Cosmos DB, Copilot Studio, Entra ID, Mariner, Microsoft Azure Active Directory B2C, Microsoft Discovery Studio, Chromium-based Microsoft Edge, Microsoft Fabric, and Power Automate.

For comparison, Microsoft fixed 570 security flaws in July and 400 in August. The sharp increase has been attributed to the company’s adoption of an artificial-intelligence-powered system for finding additional defects across its software portfolio.

CVE-2026-81963 abuses link handling in Windows Update

CVE-2026-81963 is an elevation-of-privilege vulnerability in the Windows Update Stack. Microsoft published its advisory on September 8, 2026, assigning the flaw an Important rating and confirming that exploitation has been detected.

The vulnerability involves improper link resolution before file access, combined with insufficient access control. This class of weakness can arise when a privileged component follows a filesystem link without adequately verifying where it leads or whether the destination is safe to access.

Microsoft’s assessment indicates that an authorized local attacker with low privileges can exploit the defect without user interaction. Attack complexity is rated low, and successful exploitation can provide SYSTEM access.

The CVSS vector is:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

That produces a base score of 7.8. Microsoft also assigns a temporal score of 7.2, labels exploit-code maturity as functional, and reports high potential impact to confidentiality, integrity, and availability.

The vulnerability was not publicly disclosed before the advisory appeared. It was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft has not described the observed attacks, their targets, the initial-access method, or how the exploit was incorporated into a wider intrusion chain.

An official fix is available. No workaround or temporary mitigation has been disclosed.

CVE-2026-85880 enables an AppContainer escape through ALPC

The second exploited zero-day, CVE-2026-85880, affects Windows Advanced Local Procedure Call. ALPC is an operating-system mechanism used for communication between processes, making flaws in this area potentially valuable for attackers attempting to cross security boundaries.

Microsoft attributes the vulnerability to a heap-based buffer overflow and the use of an uninitialized resource. An attacker who can already execute code inside a low-privilege AppContainer can exploit it locally, escape that sandbox and elevate to SYSTEM.

No additional user interaction is required. As with CVE-2026-81963, the attack has low complexity, requires low privileges and can have high confidentiality, integrity, and availability consequences.

Its CVSS vector is identical:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The base score is 7.8, while Microsoft’s temporal score is 6.8. The advisory marks exploitation as detected but describes exploit-code maturity as unproven. Microsoft has not disclosed the mechanics of the attacks or identified affected organizations.

Volexity and Proofpoint received acknowledgements for the discovery. Researchers Mark Kelly, David Galazin, and Jeremy Hedges were also associated with the finding in reporting about the release.

An official patch is available, but Microsoft has provided no workaround, compromise indicators, detection signatures, or detailed attack-chain information.

Exposure extends across Windows, identity and development systems

The two actively exploited vulnerabilities are local privilege-escalation bugs rather than initial-access flaws. An attacker must already have some ability to run code on the target. They can nevertheless turn a restricted compromise into complete operating-system control.

CVE-2026-85880 is especially relevant where untrusted or potentially hostile applications execute inside AppContainer isolation. CVE-2026-81963 warrants attention on Windows endpoints where low-privilege users or compromised processes could interact with privileged update operations.

The exact affected Windows editions, builds and servicing configurations have not been disclosed in the available information. Administrators should therefore use Microsoft’s product-specific update catalogue and their endpoint-management platforms to determine applicability rather than relying on a narrow version list.

The wider release covers a broad range of enterprise components. The inventory includes flaws in:

  • .NET and Visual Studio
  • Active Directory Certificate Services, Domain Services and Federation Services
  • ASP.NET Core
  • Azure Arc SQL Server Extension, Azure CycleCloud and Azure HDInsight Ambari
  • GitHub Copilot and Visual Studio Code
  • Windows drivers, font handling, IP Helper and kernel-streaming components
  • Mariner packages and kernel subsystems

Notable Critical entries include remote-code-execution bugs in Windows Graphic Fonts and IP Helper. Active Directory Domain Services also received fixes for remote-code-execution, denial-of-service and privilege-escalation vulnerabilities.

Several development-platform issues carry substantial scores even without a Critical label. CVE-2026-69439, affecting .NET and Visual Studio, has a CVSS score of 8.8 and a network-based vector requiring user interaction. CVE-2026-69805 in .NET scores 7.5, while CVE-2026-69806 scores 7.0.

KEV status remains unconfirmed for the two new zero-days

There is no confirmed information that CVE-2026-81963 or CVE-2026-85880 has been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue. Consequently, no KEV addition date or federal remediation deadline is known for either flaw.

Microsoft has, however, had several other vulnerabilities enter the catalogue during the previous 90 days:

  • CVE-2019-1068 on August 26, 2026
  • CVE-2026-55040 and CVE-2026-33824 on August 18, 2026
  • CVE-2026-68820 on August 11, 2026
  • CVE-2026-50522 on July 22, 2026
  • CVE-2026-58644 on July 16, 2026

The absence of a confirmed KEV listing does not reduce the immediate risk from the September zero-days. Microsoft has independently marked both as exploited in real attacks.

Patching should focus first on systems exposed to untrusted code

Organizations should deploy the applicable September 2026 Windows updates as their first defensive measure. There are no published workarounds for either exploited vulnerability.

Priority should go to endpoints and servers where low-privilege users, sandboxed applications or potentially untrusted code can execute. Security teams should also verify that installations completed successfully and that systems were restarted when required.

Because no specific indicators of compromise are available, defenders cannot rely on a simple hash, filename or event identifier. Investigations should instead combine endpoint telemetry with behavioral evidence of unexpected privilege transitions, AppContainer escapes, suspicious ALPC-related activity and anomalous operations involving Windows Update components.

The practical response is straightforward:

  1. Apply the official fixes for CVE-2026-81963 and CVE-2026-85880 immediately.
  2. Confirm update applicability through Microsoft’s catalogue because exact affected versions are not provided here.
  3. Validate installation and restart status across managed Windows assets.
  4. Review endpoint telemetry for low-privilege processes unexpectedly spawning or controlling SYSTEM-level activity.
  5. Deploy the separate updates issued earlier this month for Microsoft cloud, identity, browser and automation products.

The scale of this release will make testing and deployment difficult for large environments. The two exploited Windows flaws should not wait behind the rest of the 966-item patch queue.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsMicrosoft Patch TuesdayWindows zero-dayCVE-2026-81963CVE-2026-85880privilege escalationWindows security update
Back to home