Cybersecurity

Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22

Published 2 min readBy NewUJ Editorial Desk

Updated factual errors corrected

Microsoft Fixes 2 Exploited Windows Zero-Days; CISA Sets Sept. 22
0 0
XWhatsAppTelegramLinkedIn

Microsoft's September 8, 2026 Patch Tuesday closed two Windows flaws that attackers were exploiting before a fix existed. How large the batch was depends on who counted: Tenable logged 964 CVEs, BleepingComputer 966, CybersecurityNews 973 and SecurityWeek 974, which called the total a record. BleepingComputer explains its own boundary, saying the 966 figure excludes 204 flaws Microsoft shipped earlier in the month as well as Chromium-based Edge fixes that are listed separately. The updates span Windows, Office, SharePoint and Exchange.

CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), which Microsoft scores 7.8. Microsoft's advisory says "an attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," adds that no additional user interaction is required, and states that a successful attack yields SYSTEM privileges. Microsoft credits Volexity together with Proofpoint researchers Mark Kelly, David Galazin and Jeremy Hedges. Tenable says it is the first ALPC bug to appear in a Patch Tuesday since April 2023 and the second exploited as a zero-day since January 2023.

CVE-2026-81963, also scored 7.8 by Microsoft, is a link-following flaw in the Windows Update Stack that lifts a local account to SYSTEM. Microsoft's advisory credits Romain Deperne and its own Threat Intelligence Centre, and a September 11 revision added Zhang WangJunJie of Hillstone Networks. Tenable counts seven Update Stack privilege-escalation bugs patched since 2022 and says this is the first known to have been exploited. Microsoft has not said who is attacking either flaw or how widely, and CISA records ransomware use for both as unknown.

CISA added the two CVEs to its Known Exploited Vulnerabilities catalog on September 8, the day the patches shipped, under Binding Operational Directive 26-04. That gives U.S. federal civilian agencies until September 22 to apply the updates or stop using the affected products. Neither bug is a remote entry point: an attacker needs code execution on the machine first, which makes both second-stage tools for an intruder who already has a foothold.

Outside that federal deadline, the size of the batch is the harder problem. SecurityWeek quotes Dustin Childs of the Zero Day Initiative as flagging 20 of the fixed bugs as potentially wormable, meaning remote code execution with no authentication and no user interaction. Tenable's Satnam Narang, quoted by CyberScoop, said "AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn't finding more needles," and argued that organizations should establish which flaws actually apply to them and are reachable and exploitable before prioritizing. Still unresolved: who ran the two campaigns, how long they ran before the patches, and whether any of the 20 wormable bugs gets exploited now that the fixes are public. September 22 is the next fixed date on the calendar.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.