Microsoft addresses 974 flaws, including two actively exploited zero-days via September 2026 Patch Tuesday

09 Sep 2026

Microsoft Patch Tuesday September 2026

The September edition of the Patch Tuesday update addresses 974 vulnerabilities, including 2 zero-day vulnerabilities.

 

The following vulnerabilities were addressed through the update that threat actors exploited to orchestrate attacks:

Number 

Type of 
vulnerabilities 

430 

Privilege elevation 

173 

Information  
disclosure 

56 

Denial of Service 

16 

Spoofing 

19 

Security feature 
bypass 

258 

Remote code 
execution 

 

Through this blog, we will understand the vulnerabilities that require immediate attention and what organizations need to prioritize while remediating across their Microsoft environments.

2 actively exploited zero-day vulnerabilities addressed

CVE-2026-85880 – Windows Advanced Local Procedure Call (ALPC) – Elevation of Privilege

Among the two actively exploited zero-days that were addressed, was an elevation of privilege vulnerability in the Windows Advanced Local Procedure Call mechanism, which is tracked as CVE-2026-85880.

 

It is a heap-based buffer overflow in Windows ALPC that an attacker with local access to a vulnerable system can exploit to elevate privileges and obtain SYSTEM-level access. Microsoft has rated the vulnerability as Important and assigned it a CVSS score of 7.8.

 

ALPC is a Windows Inter-process communication mechanism used by Windows components and services.

 

An attacker can exploit the vulnerability to:

 

  • Escalate privileges from a low-privileged local account to SYSTEM-level access
  • Gain extensive control over Windows endpoints and servers
  • Execute a malicious code with elevated privileges
  • Access sensitive files, credentials, tokens, and system information
  • Modify security sensitive system configuration
  • Disable or tamper with security controls
  • Establish persistence on compromised systems
  • Deploy additional malware or ransomware
  • Move laterally across the network after compromising a system
  • Use the access to conduct further malicious activity on compromised systems

CVE-2026-81963 – Windows Update Stack – Elevation of Privilege

Microsoft has also addressed another actively exploited elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM-level privileges. The vulnerability, tracked as CVE-2026-81963, has been rated as important and is also assigned the CVSS score of 7.8.

 

Since Windows Update components operate with high levels of system privilege, a successful exploitation can allow an attacker with access to increase their control of the system.

 

An attacker can exploit the vulnerability to:

 

  • Escalate privileges and obtain elevated or SYSTEM-level access.
  • Execute arbitrary code within privileged contexts.
  • Bypass security protections.
  • Access sensitive information.
  • Establish persistence or facilitate further compromise.
  • Impact the confidentiality, integrity, or availability of affected systems.

Official Mitigation Guidance

Microsoft recommends applying the applicable September 2026 security updates to affected products.

 

Organizations that cannot immediately deploy the updates should follow any applicable Microsoft-provided mitigations and maintain increased monitoring of affected systems until patching is completed.

SharkStriker’s Recommendations

  • Immediately prioritize CVE-2026-85880 and CVE-2026-81963 because Microsoft has confirmed exploitation activity.
  • Deploy the September 2026 security updates across all applicable Windows endpoints, servers, and other Microsoft products.
  • Prioritize internet-facing, business-critical, privileged, and high-value systems during remediation.
  • Review endpoint telemetry for unexpected privilege escalation, SYSTEM-level process execution, and suspicious activity involving affected Windows components on unpatched systems.
  • Where immediate patching is not possible, implement applicable Microsoft mitigations and maintain heightened monitoring until remediation is completed.

SharkStriker’s Actions

SharkStriker has reviewed the September 2026 Microsoft security release and is prioritizing the vulnerabilities with confirmed exploitation activity for threat intelligence validation, detection coverage assessment, and customer impact analysis.

 

Our SOC teams will continue to monitor relevant telemetry and detection opportunities associated with these vulnerabilities to help identify potential exploitation activity across monitored environments.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE