Skip to content
Back to Guavy Wire
Stocks

Microsoft Patch Tuesday Fixes Two Actively Exploited Windows Zero-Days

Instruments
MSFT
Share

The September 2026 Patch Tuesday from Microsoft addressed two Windows privilege escalation vulnerabilities that have already been exploited in the wild. CVE-2026-85880 and CVE-2026-81963 are both rated High with a CVSS score of 7.8, allowing attackers to escalate privileges to SYSTEM.

CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC), while CVE-2026-81963 resides in the Windows Update Stack. Both vulnerabilities have low attack complexity and require no user interaction, but can enable attackers with initial local access to elevate their privileges.

The affected systems include various versions of Windows 10 and Windows Server, including some newer releases like Windows 11 and Windows Server 2025. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026, setting September 22 as the remediation deadline for US federal civilian agencies.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc