Microsoft Patch Tuesday Fixes Two Actively Exploited Windows Zero-Days
The September 2026 Patch Tuesday from Microsoft addressed two Windows privilege escalation vulnerabilities that have already been exploited in the wild. CVE-2026-85880 and CVE-2026-81963 are both rated High with a CVSS score of 7.8, allowing attackers to escalate privileges to SYSTEM.
CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC), while CVE-2026-81963 resides in the Windows Update Stack. Both vulnerabilities have low attack complexity and require no user interaction, but can enable attackers with initial local access to elevate their privileges.
The affected systems include various versions of Windows 10 and Windows Server, including some newer releases like Windows 11 and Windows Server 2025. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026, setting September 22 as the remediation deadline for US federal civilian agencies.