CVE Tools
Back to feed
Exploited in the wild Windows ALPC Tenable patch-tuesday Windows Update Stack Microsoft

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

SecurityWeek·By Ionut Arghire··3 min read
CVE Tools coverage

Microsoft released a record number of security updates this month, resolving 974 vulnerabilities across its software portfolio, including two actively exploited zero-days. The first, CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) that allows local attackers to escalate privileges to System level. The second, CVE-2026-81963, involves improper link resolution in the Windows Update Stack, also enabling privilege escalation. Additionally, the patch addresses significant remote code execution risks in Exchange Server, SharePoint, and Remote Desktop Services.