Microsoft released September 2026 security updates on September 8 that patch two actively exploited Windows zero-day flaws, CVE-2026-81963 and CVE-2026-85880. Both vulnerabilities allow a local attacker to elevate privileges to SYSTEM, making them priority fixes for organizations managing Windows endpoints and servers. Microsoft has not disclosed who used the flaws, which targets were affected, or how broadly the attacks occurred.

The two zero-days arrived in an exceptionally large Patch Tuesday release. BleepingComputer counted 966 vulnerabilities issued by Microsoft on September 8, including 105 rated critical, while excluding 204 flaws fixed earlier in the month. SecurityWeek reported a different total under its methodology, but likewise identified the release as a record and confirmed that the two exploited vulnerabilities are privilege-escalation defects.

CVE-2026-81963 affects the Windows Update Stack. According to Microsoft information reported by BleepingComputer, improper link resolution before file access allows an authorized local attacker to elevate privileges. Successful exploitation can provide SYSTEM-level access, but Microsoft has not published details of the observed attacks. Romain Deperne and the Microsoft Threat Intelligence Center received credit for reporting the issue.

CVE-2026-85880 affects Windows Advanced Local Procedure Call, or ALPC. SecurityWeek described it as a heap-buffer-overflow vulnerability through which code running with low privileges in an AppContainer can escape that boundary and obtain SYSTEM privileges. The flaw is local rather than remotely exploitable by itself, so an attacker would first need the ability to run code on a vulnerable Windows system.

Beyond the exploited flaws, BleepingComputer classified 258 vulnerabilities in the release as remote code execution issues and 438 as elevation-of-privilege issues. Its count also included 19 security-feature bypasses, 173 information-disclosure flaws, 56 denial-of-service issues and 16 spoofing vulnerabilities. The outlet said 81 of the 105 critical vulnerabilities could enable remote code execution.

JPCERT/CC separately alerted organizations on September 9 that Microsoft had identified both CVEs as exploited and advised users to apply the updates through Microsoft Update or Windows Update. Defenders should prioritize the two zero-days, test and deploy the September updates under normal change controls, and monitor affected systems for suspicious privilege escalation. Because public reporting contains no attack indicators, attribution or exploit-chain details, patching and endpoint telemetry remain the principal defensive measures.