Exploited in the wild Windows Update Stack patch-tuesday Windows Advanced Local Procedure Call Microsoft zero-day
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
CVE Tools coverage
Microsoft has released its September 2026 security updates, addressing a record number of flaws, including two vulnerabilities currently being exploited in the wild. The critical fixes resolve CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call, both of which allow privileged users to escalate to SYSTEM rights. Additionally, researchers have published a proof-of-concept for a bypass of the Microsoft Defender patch, highlighting ongoing risks to endpoint security.