VMTech
Discuss a project

Microsoft fixes 974 vulnerabilities, including two exploited Windows flaws

Microsoft fixes 974 vulnerabilities, including two exploited Windows flaws

Microsoft has released fixes for a record 974 vulnerabilities across its software portfolio, including two Windows privilege-escalation flaws that are being actively exploited. The September Patch Tuesday release covers 723 Windows issues, 111 flaws in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. With 25 non-Microsoft CVEs included, the total number of resolved vulnerabilities reaches 999.

More than 110 of the vulnerabilities carry a critical severity rating. Privilege escalation, remote code execution and information disclosure account for nearly 90% of the issues addressed in the release.

Two Windows zero-days require immediate attention

The actively exploited flaws are CVE-2026-85880 and CVE-2026-81963, both rated CVSS 7.8. CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC). An authorised local attacker can elevate privileges and obtain SYSTEM privileges.

Microsoft said an attacker able to execute code in a low-privilege AppContainer could exploit CVE-2026-85880 to escape the sandbox and elevate privileges locally, with no additional user interaction required. Volexity and Proofpoint reported the vulnerability.

CVE-2026-81963 is an improper link-resolution vulnerability in the Windows Update Stack that can also enable local privilege escalation by an authorised attacker. Rapid7's Adam Barnett said the update for all supported Windows versions presumably strengthens controls against following a malicious link and overwriting a system component with an attacker-controlled imposter. Romain Deperne of Airbus Helicopters and the Microsoft Threat Intelligence Center received credit for reporting the flaw.

Microsoft detected zero-day exploitation targeting both vulnerabilities, but did not disclose the actors involved, the scale of activity or whether attacks compromised victims. The U.S. Cybersecurity and Infrastructure Security Agency added both flaws to its Known Exploited Vulnerabilities catalog and requires Federal Civilian Executive Branch agencies to apply fixes by September 22, 2026.

Critical remote-code-execution exposure remains in the batch

Other notable updates include CVE-2026-55007, a CVSS 8.1 double-free flaw in Microsoft Exchange Server that could permit unauthorised network code execution, and CVE-2026-69465, a CVSS 8.8 missing-authorization flaw in Microsoft Office SharePoint with the same potential outcome for an authorised attacker.

Several bugs received CVSS 9.8 scores: CVE-2026-69525 in Windows Remote Desktop Services, CVE-2026-69595 in the Windows Services for NFS ONCRPC XDR Driver, CVE-2026-69730 in Windows DNS Server, CVE-2026-69829 in Windows Shell, and CVE-2026-72979 in Windows DHCP Server. Each is described as allowing unauthorised remote code execution. SQL Server's CVE-2026-65669, rated 9.6, is an injection vulnerability that could allow unauthorised network privilege elevation.

Prioritisation matters more than the headline count

Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June and 161 in May. TrendAI's Zero Day Initiative said Microsoft had patched 2,760 security flaws in 2026. Tenable noted that CVE-2026-81963 is the first Windows Update Stack zero-day and the first such issue known to be exploited in the wild since that component's privilege-escalation flaws began appearing in 2022.

For organisations, the immediate task is to identify affected Windows systems and deploy fixes for the two exploited vulnerabilities. Teams should then assess which remaining issues apply to their environment, whether they are reachable or exploitable over the internet, and sequence remediation around that exposure and exploitability context.

#cybersecurity#windowssecurity#patchmanagement#vulnerability
Open analytics
On the site 1 views
min read 4 09.09.2026
Instagram

Microsoft fixes 974 vulnerabilities, including two exploited Windows flaws

Open the post on Instagram ↗