MICROSOFT’S September 2026 Patch Tuesday delivers what the vendor describes as the largest ever batch of fixes, addressing 964 CVEs, with 104 rated Critical and 860 rated Important. Microsoft notes 974 CVEs in total for the release, but ten affect cloud services or are fixes it applies itself, leaving 964 vulnerabilities for customers to patch.
Among the fixes are two actively exploited zero-day vulnerabilities that enable local privilege escalation, allowing an attacker who already has access to a device to obtain SYSTEM privileges. Neither flaw by itself provides remote access, but SYSTEM-level control greatly enhances an attacker’s ability to disable protections, access sensitive data, establish persistence, or move laterally once initial access is gained.
The two zero-days are CVE-2026-81963 (Windows Update Stack EoP) with a CVSS v4 score of 7.8, and CVE-2026-85880 (heap-based buffer overflow in Windows ALPC) also rated 7.8. For CVE-2026-81963, Microsoft describes improper link resolution before file access in Windows Update Stack, allowing an authorised attacker to elevate privileges locally; active exploitation was reported prior to the patch.
CVE-2026-85880 involves a heap-based buffer overflow in ALPC, enabling a low-privilege AppContainer attacker to escape the sandbox and escalate privileges without user interaction. These local elevation flaws are significant in attack chains post-initial access, underscoring the need for applying the September updates across Windows Server and client systems, including affected components such as DNS Server, Remote Desktop Services, Exchange, SharePoint, SQL Server, and Office.