Exploited in the wild Windows patch-tuesday Microsoft Office Microsoft zero-day
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
CVE Tools coverage
Microsoft has released its September 2026 security updates to address a record high of 966 vulnerabilities across products including Windows, Microsoft Office, Exchange Server, and SharePoint. This release includes fixes for two zero-day vulnerabilities that are currently being exploited in the wild, both of which allow attackers to escalate privileges locally to gain SYSTEM access. One of these flaws exists in the Windows Update Stack due to improper link resolution, while the other involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem. Administrators should prioritize deploying these patches immediately to mitigate the risk of active exploitation.