securityonline.info 8 Sept 2026, 18:08 UTC

Microsoft Patches Two Windows Zero Days Exploited in Attacks

Microsoft Patches Two Windows Zero Days Exploited in Attacks
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT’S September 2026 Patch Tuesday fixes 996 vulnerabilities, but two zero-day flaws had already been exploited in the wild. Both are Windows elevation-of-privilege issues that allow attackers to gain higher access after already compromising a foothold. The affected CVEs are CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows ALPC). Each carries a CVSS v3 score of 7.8 and is listed as exploited in the wild, underscoring the urgency of patching. Evidence in the article notes active exploitation but withholds technical exploit details, a standard practice to slow copycat attacks.

The flaws are local privilege-escalation vulnerabilities; attackers must already have some access to the targeted system and can use the affected components to raise their privileges. Microsoft has not disclosed full exploit details or victim counts, but the advisory confirms active exploitation. The impact is heightened by the fact that privilege escalation can turn a minor intrusion into a full compromise, so addressing these two flaws takes priority in the September 2026 updates.

In terms of remediation, organisations should apply the updates immediately, prioritising the two exploited zero-days before addressing other critical RCE flaws. The article lists affected builds for Windows updates and notes broader coverage for SQL Server, Exchange, SharePoint, Office, and Azure services. Patching should be tested in a staging environment and deployed rapidly across production. If immediate mitigation is not possible, enabling automatic updates where feasible is advised.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline