Exploited in the wild Windows ALPC Tenable patch-tuesday Windows Update Stack Microsoft
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
CVE Tools coverage
Microsoft released a record number of security updates this month, resolving 974 vulnerabilities across its software portfolio, including two actively exploited zero-days. The first, CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) that allows local attackers to escalate privileges to System level. The second, CVE-2026-81963, involves improper link resolution in the Windows Update Stack, also enabling privilege escalation. Additionally, the patch addresses significant remote code execution risks in Exchange Server, SharePoint, and Remote Desktop Services.