Skip to content
LIVE

Microsoft's September Patch Fixes Two Windows Flaws Already Under Attack

Both zero-days let attackers escalate to full SYSTEM control, and both were being exploited before Microsoft had a fix ready. Update now.

Meridians Money Desk

Published 9 September 2026 · Updated 9 September 2026 · 4 min read

Microsoft's September Patch Fixes Two Windows Flaws Already Under AttackSoftware
Photo: Photo by cottonbro studio / Pexels (Pexels License — free to use, no attribution legally required (credited above as good practice).)

The short answer

  • Microsoft's September 8, 2026 Patch Tuesday fixed two zero-day vulnerabilities that attackers were already exploiting before a patch existed.
  • CVE-2026-81963 is a Windows Update Stack flaw that lets a local attacker escalate to SYSTEM privileges; CVE-2026-85880 is a Windows ALPC flaw that lets code in a low-privilege sandbox escape it.
  • The update covers roughly 970 vulnerabilities total, with just over 100 rated Critical, though outlets differ slightly on the exact count.
  • Microsoft attributed the high vulnerability volume in part to a new AI-assisted internal discovery system.

Microsoft's September 2026 security update, released September 8, fixes two vulnerabilities that attackers were already using before a patch existed. Both let an attacker who already has some foothold on a Windows machine take full control of it. If Windows Update isn't set to install automatically, do it manually today.

The two zero-days

  • CVE-2026-81963 — a flaw in the Windows Update Stack caused by improper link resolution before a file is accessed. It lets a local attacker escalate to SYSTEM-level privileges, the highest level of access on a Windows machine. Microsoft credits its own Threat Intelligence Center and researcher Romain Deperne with finding it.
  • CVE-2026-85880 — a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) mechanism. Per the advisory language, an attacker who can already run code inside a low-privilege AppContainer sandbox can use the flaw to escape it and gain higher-level access. Volexity and Proofpoint researchers are credited with finding it.

A patch with an unusually high vulnerability count

The two outlets that track Patch Tuesday in detail count this update differently: SecurityWeek puts the total at 974 fixed vulnerabilities, BleepingComputer at 966 (plus 204 more Microsoft had already fixed earlier in September outside its usual monthly cycle). BleepingComputer counts 105 of the flaws as Critical — 81 that allow remote code execution, 20 that allow privilege escalation, two that allow information disclosure and one that bypasses a security feature — and flags 20 as 'wormable,' meaning they could in principle spread machine to machine without anyone clicking anything. Microsoft told BleepingComputer the unusually high count partly reflects a new AI-assisted internal vulnerability-discovery system. Tenable's Satnam Narang offered a more skeptical read to SecurityWeek: AI-assisted discovery is finding a bigger haystack of vulnerabilities, not necessarily more attacker-relevant needles in it.

What to do

Windows installs September's update automatically if automatic updates are turned on. To check manually: Settings > Windows Update > Check for updates. Because one of the two zero-days involves sandbox escape, security teams running AppContainer-based tools should treat this month's update as time-sensitive rather than routine.

Sources

Every factual claim above is traceable to these documents. Check them — that is why they are here.

About this byline

Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.

Sponsored

Paid placement · not editorial

Related reading

The Meridians Brief

One considered email a week

What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.

Sign-up opens with our launch issue. Nothing is sent or stored yet.