Microsoft Products Hit by Critical Vulnerabilities in September 2026 Security Update Review
A recent security update review by The ZDI has revealed several critical vulnerabilities in various Microsoft products. Among them are Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability, Azure AI Language Elevation of Privilege Vulnerability, and Copilot Studio Elevation of Privilege Vulnerability. These vulnerabilities allow attackers to gain elevated privileges on affected systems, potentially leading to data breaches or system compromise.
According to the review, the most severe vulnerability is CVE-2026-70352, which has a CVSS score of 10. This means that an attacker could exploit this vulnerability with high confidence and obtain significant control over the affected system.
The review also highlights several other critical vulnerabilities in Microsoft products, including Azure Cosmos DB Spoofing Vulnerability, DirectWrite Remote Code Execution Vulnerability, and Windows DHCP Server Remote Code Execution Vulnerability. While these vulnerabilities are not as severe as CVE-2026-70352, they still pose a significant risk to affected systems.
It is essential for users of Microsoft products to apply the latest security updates to mitigate these vulnerabilities. Failure to do so may leave their systems vulnerable to attacks.