Microsoft’s 974-Fix Security Release Forces a Triage Test for Windows Defenders

Microsoft patched 974 flaws in September, including two exploited privilege-escalation bugs and two 9.8-rated RCEs requiring urgent triage.

Microsoft’s 974-Fix Security Release Forces a Triage Test for Windows Defenders
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 11 min

A record patch volume, but two flaws demand immediate action

Microsoft’s September security release addresses at least 974 vulnerabilities across Windows and other company software, the largest single batch reported to date. Microsoft classified 113 of the flaws as Critical.

The release pushes Microsoft’s vulnerability count above 2,600 for the year. That is already more than double the previous annual record of 1,245 vulnerabilities in 2020, with three months still remaining. The previous monthly high was at least 570 vulnerabilities in July.

Raw volume, however, is not the best guide to deployment order. Two local elevation-of-privilege vulnerabilities—CVE-2026-81963 and CVE-2026-85880—are already being exploited.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 8, 2026. The remediation deadline for US federal agencies is September 22, 2026.

Neither flaw is remotely exploitable on its own. Both require an attacker to have limited access or the ability to run low-privilege code, but successful exploitation can provide SYSTEM privileges. That makes them valuable for converting an initial foothold into complete control of a Windows host.

Windows Update Stack flaw abuses link handling

CVE-2026-81963 is an elevation-of-privilege vulnerability in the Windows Update Stack. Microsoft rates it Important, while Microsoft and NVD assign it a CVSS base score of 7.8.

The vulnerability combines improper link resolution before file access, tracked as CWE-59, with improper access control under CWE-284. An authorized local attacker can exploit the flaw without further user interaction and obtain SYSTEM privileges.

The CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. It describes a local attack with low complexity, requiring low privileges but no user involvement, with high potential impact to confidentiality, integrity and availability.

Affected NVD-listed versions are:

Product Vulnerable versions
Windows 11 23H2 Below 10.0.22631.7582
Windows 11 24H2 Below 10.0.26100.9445
Windows 11 25H2 Below 10.0.26200.9445
Windows 11 26H1 Below 10.0.28000.2954
Windows Server 2025 Below 10.0.26100.33438

Microsoft released the MSRC advisory for the Update Stack vulnerability on September 8, 2026, and updated it on September 15, 2026. The company credits Zhang WangJunJie of Hillstone Networks and the Microsoft Threat Intelligence Centre.

Microsoft reports detected exploitation, confirmed reporting and functional exploit code. The vulnerability was not publicly disclosed before the advisory, and an official fix is available.

CISA requires federal agencies to apply vendor mitigations while complying with BOD 26-04, “Prioritizing Security Updates Based on Risk,” and its Forensics Triage Requirements. Agencies must evaluate each asset’s internet exposure and follow the applicable cloud-service guidance, or stop using the product if mitigations cannot be applied.

ALPC bug enables an AppContainer escape

CVE-2026-85880 affects Windows Advanced Local Procedure Call, or ALPC. It is a heap-based buffer overflow involving the use of an uninitialized resource, mapped to CWE-122 and CWE-908.

An attacker able to execute code inside a low-privilege AppContainer can exploit the vulnerability to escape that sandbox and elevate privileges on the underlying host. No additional user interaction is required, and successful exploitation can grant SYSTEM privileges.

Microsoft rates the flaw Important. Its CVSS score is 7.8, using the same base vector as CVE-2026-81963:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The affected versions listed by NVD are:

Product Vulnerable versions
Windows 10 1607 Below 10.0.14393.9512
Windows 10 1809 Below 10.0.17763.9245
Windows 10 21H2 Below 10.0.19044.7725
Windows 10 22H2 Below 10.0.19045.7725
Windows Server 2012 Affected; no build threshold specified
Windows Server 2016 Below 10.0.14393.9512
Windows Server 2019 Below 10.0.17763.9245
Windows Server 2022 Below 10.0.20348.5622

The Microsoft advisory for the ALPC flaw was released on September 8, 2026, and last updated on September 16, 2026. That revision corrected the temporal Exploit Code Maturity value in the CVSS vector and was described as informational.

Microsoft credits Volexity, Proofpoint Inc. and an unnamed contributor associated with Proofpoint. Exploitation has been detected, functional exploit code is available, and Microsoft has issued an official fix.

CVE-2026-85880 entered the KEV catalog on September 8, 2026, with the same September 22 deadline and CISA response requirements as CVE-2026-81963.

Two network-reachable bugs carry 9.8 scores

The release also fixes two remote-code-execution vulnerabilities that are not identified as actively exploited but present more direct network attack paths.

CVE-2026-69730 is a use-after-free vulnerability in Windows DNS. An unauthenticated attacker can send a specially crafted packet to an affected system and potentially execute code over the network.

NVD assigns the flaw a CVSS score of 9.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The attack requires no privileges or user interaction and has low complexity.

The issue reportedly affects Windows Server 2012 onward and Windows 10. Exact affected edition and build ranges have not been disclosed in the available technical data. Microsoft reportedly considers exploitation likely.

CVE-2026-69829 is a heap-based buffer overflow in Windows Shell. It also permits unauthorized remote code execution over a network and carries a 9.8 CVSS score with the same network-accessible vector.

Its NVD-listed scope includes Windows 10 1607, 1809, 21H2 and 22H2; Windows 11 23H2, 24H2, 25H2 and 26H1; and Windows Server 2012, 2016, 2019 and 2022. The vulnerable build thresholds match those listed above for the corresponding Windows releases, including:

  • Windows 11 23H2 below 10.0.22631.7582
  • Windows 11 24H2 below 10.0.26100.9445
  • Windows 11 25H2 below 10.0.26200.9445
  • Windows 11 26H1 below 10.0.28000.2954
  • Windows Server 2022 below 10.0.20348.5622

Windows Server 2012 is listed as affected without a build threshold.

Deployment should follow exploitation and exposure

Administrators should first identify machines below the documented build thresholds and deploy fixes for the two exploited privilege-escalation vulnerabilities. Systems that may already be compromised should also undergo the forensic triage required by CISA rather than being treated solely as patching targets.

The DNS and Shell flaws deserve parallel attention on externally reachable or otherwise exposed systems. Their network attack vectors, absence of authentication requirements and 9.8 scores create a different risk profile from the locally exploited bugs.

Organizations should test updates against business-critical third-party applications, but testing should not become an open-ended reason to delay deployment. Maintenance windows, rollback plans and staffing for after-hours work may be necessary for a release of this size.

Individual users should run Windows Update and accept pending security updates. No specific compromise indicators have been disclosed for the two exploited flaws, so defenders must rely on asset inventory, patch state, endpoint telemetry and forensic review rather than a supplied list of malicious files or addresses.

Microsoft’s KEV exposure extends beyond this release

The two new KEV entries are not isolated Microsoft cases. During the preceding 90 days, CISA also added CVE-2019-1068, CVE-2026-55040, CVE-2026-33824, CVE-2026-68820, CVE-2026-50522 and CVE-2026-58644 for the same vendor.

Microsoft associates rising vulnerability counts with AI-assisted security research. Adobe, Cisco, Google, Mozilla and Oracle have also linked AI-supported research to higher discovery volumes or faster patch production, while Google reportedly moved toward security updates every two weeks.

More findings do not necessarily mean every organization is exposed to more exploitable flaws. The immediate operational problem is determining which vulnerable components are present, whether attackers can reach them, and how quickly fixes can be validated and deployed.

This release makes that distinction unavoidable: 974 fixes require planning, but two exploited vulnerabilities with a deadline today require action.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsMicrosoft Patch TuesdayWindows vulnerabilitiesCVE-2026-81963CVE-2026-85880privilege escalationCISA KEV
Back to home