Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22

Microsoft's September 8, 2026 Patch Tuesday closed two Windows flaws that attackers were exploiting before a fix existed. How large the batch was depends on who counted: Tenable logged 964 CVEs, BleepingComputer 966, CybersecurityNews 973 and SecurityWeek 974, which called the total a record. BleepingComputer explains its own boundary, saying the 966 figure excludes 204 flaws Microsoft shipped earlier in the month as well as Chromium-based Edge fixes that are listed separately. The updates span Windows, Office, SharePoint and Exchange.
CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which Microsoft scores 7.8. Microsoft's advisory says "an attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," adds that no additional user interaction is required, and states that a successful attack yields SYSTEM privileges. Microsoft credits Volexity together with Proofpoint researchers Mark Kelly, David Galazin and Jeremy Hedges. Tenable says it is the first ALPC bug to appear in a Patch Tuesday since April 2023 and the second exploited as a zero-day since January 2023.
CVE-2026-81963, also scored 7.8 by Microsoft, is a link-following flaw in the Windows Update Stack that lifts a local account to SYSTEM. Microsoft's advisory credits Romain Deperne and its own Threat Intelligence Centre, and a September 11 revision added Zhang WangJunJie of Hillstone Networks. Tenable counts seven Update Stack privilege-escalation bugs patched since 2022 and says this is the first known to have been exploited. Microsoft has not said who is attacking either flaw or how widely, and CISA records ransomware use for both as unknown.
CISA added the two CVEs to its Known Exploited Vulnerabilities catalog on September 8, the day the patches shipped, under Binding Operational Directive 26-04. That gives U.S. federal civilian agencies until September 22 to apply the updates or stop using the affected products. Neither bug is a remote entry point: an attacker needs code execution on the machine first, which makes both second-stage tools for an intruder who already has a foothold.
Outside that federal deadline, the size of the batch is the harder problem. SecurityWeek quotes Dustin Childs of the Zero Day Initiative as flagging 20 of the fixed bugs as potentially wormable, meaning remote code execution with no authentication and no user interaction. Tenable's Satnam Narang, quoted by CyberScoop, said "AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn't finding more needles," and argued that organizations should establish which flaws actually apply to them and are reachable and exploitable before prioritizing. Still unresolved: who ran the two campaigns, how long they ran before the patches, and whether any of the 20 wormable bugs gets exploited now that the fixes are public. September 22 is the next fixed date on the calendar.
Sources
- Microsoft Security Update Guide - CVE-2026-85880Primary source
- Microsoft Security Update Guide - CVE-2026-81963Primary source
- CISA Known Exploited Vulnerabilities CatalogPrimary source
- CISA Binding Operational Directive 26-04Primary source
- Tenable - September 2026 Microsoft Patch TuesdaySecondary
- SecurityWeekSecondary
Related
Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
CISA Adds 5 Exploited Flaws; ScreenConnect Rated CVSS 9.9
GitLab CVSS 10.0 Flaw Exploited; CISA Deadline Is September 14
Chrome 153 Fixes 7th Exploited Zero-Day of 2026: CVE-2026-87491
Sandworm, Qilin Exploit Cisco Firewall Flaw Rated CVSS 10.0
IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
MikroTik SSH Chain Hit Routers a Day Before Sept. 3 Patch
Trending now
- VW Mission Efficiency Sets 0.158 Cd World Record
- Marvel's Wolverine Lands on PS5 With a 77 Metascore
- Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
- Saudi Pipeline Repairs to Take Weeks as Brent Tops $107
- US Diesel Sets Record $6.23 a Gallon, AAA Figures Show
- Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
- DeepMind AGI Safety Researcher Quits, Turns Down Anthropic, OpenAI
- Apple Ships iOS 27 With Siri AI, but Not for EU iPhones
Comments
No comments yet. Be the first.