Pandorex
Security

Microsoft Patch Tuesday: Two Exploited Windows Flaws Matter More Than the Record Count

Published Pandorex Redaktion·4 min read
—

Summary: Microsoft patched two Windows vulnerabilities already exploited in the wild on September 8: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC. Both can let an attacker with local access reach SYSTEM privileges. For administrators, the headline count of almost 1,000 vulnerabilities matters less than these two confirmed attack paths.

CVE-2026-81963 is an improper link-resolution flaw in the Windows Update Stack. An already authorized low-privilege attacker can use it for local privilege escalation. CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), again allowing local elevation to SYSTEM. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on September 8 and set a September 22 remediation deadline for US federal agencies.

The record count is not a single number

Coverage puts the September Patch Tuesday total at 966, 973 or 974 vulnerabilities. This is mainly a counting-method issue rather than a dispute over whether individual patches exist: some tallies count only Microsoft CVEs newly released on Patch Tuesday, while others include additional product and release records. BleepingComputer counts 966; SecurityWeek counts 974. That gap is operationally irrelevant.

The attack chain matters more. Both zero-days require local access or existing privileges. They are therefore not unauthenticated internet-facing RCEs, but they can become valuable second-stage exploits after phishing, a browser compromise or another application exploit gives an attacker an initial foothold.

What administrators should also plan for

Windows 11 24H2 and 25H2 receive builds 26100.9445 and 26200.9445 through KB5124008. Microsoft currently lists no known issues and the update also fixes recent Teams and new Outlook crashes on Arm64 PCs. Devices enrolled in Hotpatch still need a reboot this month: Microsoft is shipping September as a regular baseline update because some security changes affect components that cannot be updated without restarting.

Pandorex Analysis: Operational priority should start with CVE-2026-81963 and CVE-2026-85880, then move to critical RCEs that are actually reachable in the local environment. The near-four-digit patch count is striking, but it is not a useful risk score for any specific network.

Sources and references

Sources used for the facts and context in this article.

  1. Microsoft Security Response Center, 08.09.2026: CVE-2026-81963msrc.microsoft.com
  2. Microsoft Security Response Center, 08.09.2026: CVE-2026-85880msrc.microsoft.com
  3. Microsoft Support, 08.09.2026: KB5124008support.microsoft.com
  4. Microsoft Support, 08.09.2026: September 2026 Hotpatch Baselinesupport.microsoft.com
  5. CISA, geprüft am 09.09.2026: Known Exploited Vulnerabilities Catalogcisa.gov
  6. BleepingComputer, 08.09.2026: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysbleepingcomputer.com
  7. SecurityWeek, 08.09.2026: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Dayssecurityweek.com

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

Google: Attackers Built an Agentic Credential Campaign in Under Six Hours

Security