1. Home
  2. Security Advisories

Microsoft September 2026 Patch Tuesday: 2 Zero-Days Fixed

Security advisory High 5 min read

This article is also available in: TürkçeDeutsch

Microsoft September 2026 Patch Tuesday: 2 Zero-Days Fixed
CVECVE-2026-81963, CVE-2026-85880
SeverityHigh
CVSS score 7.8
StatusPatch available
Affected productsWindows 10 (ESU/LTSC), Windows 11 23H2 – 26H1, Windows Server 2012 – 2025 (before the September 2026 update)

Microsoft's record-breaking September 2026 Patch Tuesday fixes two Windows zero-days exploited in attacks (CVE-2026-81963, CVE-2026-85880). Affected systems, KB numbers and patch priorities.

Summary

Microsoft's September 2026 Patch Tuesday is the largest security release in the company's history. Published on 8 September 2026, it includes fixes for two Windows zero-day vulnerabilities that were confirmed to be exploited in attacks before patches were available. Both allow an attacker with limited access to a system to escalate to SYSTEM privileges. If you have not deployed the update yet, treat this article as your priority list.

  • Scope: 966 vulnerabilities according to BleepingComputer, 972 according to CrowdStrike (the count depends on methodology).
  • Actively exploited: CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows ALPC), both CVSS 7.8.
  • CISA KEV: Both flaws were added to the catalog on 8 September 2026; the deadline for US federal agencies was 22 September.
  • Priority KBs: KB5124008 (Windows 11 24H2/25H2), KB5122880 (Windows 11 23H2), KB5122878 (Windows 10 ESU / LTSC 2021).

Microsoft September 2026 Patch Tuesday: technical details

Microsoft's monthly security update fixes a record number of vulnerabilities. The most urgent part of the release covers two privilege escalation flaws that attackers are already using:

CVE-2026-81963 – Windows Update Stack elevation of privilege

The flaw stems from improper link resolution before file access. A low-privileged local attacker can reach SYSTEM privileges without any user interaction. Discovery is credited to Romain Deperne and the Microsoft Threat Intelligence Center (MSTIC).

CVE-2026-85880 – Windows ALPC elevation of privilege

A heap-based buffer overflow in ALPC, the Windows inter-process communication framework. According to CrowdStrike's analysis, an attacker can even escape a low-privileged AppContainer sandbox and obtain SYSTEM privileges. The flaw was reported by researchers from Volexity and Proofpoint.

Microsoft has not shared details on how either vulnerability was used in attacks.

Affected versions

ProductAffectedFixed
Windows 11 24H2 / 25H2before the September 2026 updateKB5124008 (or later, e.g. KB5129195)
Windows 11 23H2before the September 2026 updateKB5122880
Windows 10 22H2 ESU / Enterprise LTSC 2021builds before 19045.7725 / 19044.7725KB5122878
Windows Server 2012 – 2025before the September 2026 updatethe relevant September 2026 KB in the Security Update Guide

According to NVD, the scope of the two flaws is as follows:

VulnerabilityAffected systems (NVD)
CVE-2026-81963Windows 11 23H2, 24H2, 25H2, 26H1; Windows Server 2025
CVE-2026-85880Windows 10 (1607, 1809, 21H2, 22H2); Windows Server 2012, 2012 R2, 2016, 2019, 2022

NVD records may not yet be complete; use the Microsoft Security Update Guide as the authoritative source for product lists and KB numbers. In practice, the safest approach is to treat every Windows client and server without the September 2026 update as at risk.

Risk and potential impact

Neither flaw can be exploited remotely on its own; the attacker first needs to run code on the system. However, limited access gained through a phishing email, a malicious attachment or a stolen password turns into full control of the device thanks to these flaws. Ransomware operators and targeted threat groups rely on exactly this type of vulnerability to turn initial access into a persistent, fully privileged foothold.

Watch out for critical infrastructure flaws too

The same release fixes vulnerabilities that have not been reported as exploited but are extremely critical for servers. According to CrowdStrike, the following flaws carry a CVSS score of 9.8 and allow unauthenticated remote code execution:

  • Windows Netlogon – CVE-2026-72982 (directly relevant to domain controllers)
  • Windows DNS Server – CVE-2026-69730
  • Windows DHCP Server – CVE-2026-69845 and CVE-2026-72979
  • Windows SSTP (VPN) – CVE-2026-73009 (servers offering SSTP VPN via RRAS, typically exposing TCP/443 to the internet)
  • Microsoft Outlook – CVE-2026-78509 (can be triggered via the Reading Pane)

Domain controllers, DNS/DHCP servers and internet-facing VPN servers should therefore be updated first.

  1. Deploy the updates: KB5124008 for Windows 11 24H2/25H2, KB5122880 for Windows 11 23H2, KB5122878 for Windows 10 ESU and Enterprise LTSC 2021. They are available via Windows Update, WSUS and the Microsoft Update Catalog. Check the Security Update Guide for the Windows Server KBs.
  2. Prioritize: Domain controllers, DNS/DHCP and VPN (RRAS/SSTP) servers first, then internet-facing systems, and finally end-user devices.
  3. Prefer the latest package: On 14 September, Microsoft released the out-of-band update KB5129195 for Windows 11 24H2/25H2. It resolves Remote Desktop Services instability seen in some environments after the September update and fixes an additional privilege escalation flaw (CVE-2026-62721).
  4. Check the known issue: In some domain environments using Credential Guard and "Machine Identity Isolation", devices may lose their trust relationship with the domain. Microsoft states that this feature is only supported at the Windows Server 2025 domain functional level; review the workaround on the KB page before broad deployment.
  5. Review Windows 10 devices: Support for Windows 10 22H2 ended in October 2025. Devices not enrolled in the ESU program will not receive these patches; enrol them in ESU or plan the move to Windows 11.
  6. Reduce the impact: Prevent users from working with administrator rights day to day, make sure EDR/antivirus solutions are up to date, and use post-patch compliance reports to confirm the rollout is complete.

How Doğa Network can help

Our team can help you test, prioritize and deploy Windows updates via WSUS or Intune and report on patch compliance. Call us on +90 850 888 3642 or email hi@doga.network.

Sources

#Microsoft#Windows#Patch Tuesday#zero-day#privilege escalation#CVE-2026-81963
Newsletter

Hear about critical vulnerabilities first.

Get our security advisories, practical guides and announcements by email. A few emails a month, no advertising.

Which topics would you like to hear about?