September Patch Tuesday Fixes Two Exploited Flaws—Count Exposure, Not CVEs

Microsoft released its September security updates on September 8, fixing two Windows privilege-escalation vulnerabilities already exploited in attacks. BleepingComputer’s Patch Tuesday report identifies them as CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC); both require local access and can elevate an authorized attacker to SYSTEM.
The updates are available, but there is no single package or delivery route for Microsoft’s entire product estate. For Windows 10 ESU and the supported LTSC editions covered by KB5122878, Microsoft’s September 8 documentation lists Windows Update, Windows Update for Business, Microsoft Update Catalog and Windows Server Update Services as available channels.
The two exploited flaws lead the queue

Confirmed exploitation makes the two Windows flaws the clearest first deployment tier. CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC. An attacker who can already execute code locally can use the flaw to escape a low-privilege AppContainer and obtain higher privileges without further user interaction.
CVE-2026-81963 is an improper link-resolution flaw in the Windows Update Stack. It also requires an authorized attacker to act locally, but successful exploitation can produce SYSTEM privileges. Neither vulnerability is an unauthenticated route from the internet; each is valuable after an attacker has gained an initial foothold.
That distinction determines which endpoints belong first. Systems showing evidence of compromise should precede otherwise equivalent machines, followed by endpoints where untrusted code routinely runs in a browser, document viewer or other constrained process, and machines whose network access would make SYSTEM-level control especially damaging.
Public reporting does not disclose how either vulnerability was used, who used it or how many systems were targeted. The confirmed facts are narrower: exploitation occurred before fixes were available, both flaws enable local privilege escalation, and Microsoft shipped updates on September 8.
Reachable remote-code paths are the next exposure tier

The next tier is not every vulnerability carrying a Critical rating. It is the set of newly fixed remote-code-execution paths that an attacker can reach in the environment, particularly those requiring neither authentication nor user interaction. An exposed server can therefore warrant attention before an isolated endpoint even when the server flaw was not one of the two exploited zero-days.
SecurityWeek’s release analysis reports 974 CVEs across Microsoft products and says 20 of the resolved vulnerabilities could be considered wormable because they allow remote code execution without authentication or user interaction. It also points to RCE flaws affecting Exchange Server, SharePoint and Remote Desktop Services among the issues requiring attention.
Those product names do not establish that every version or deployment is vulnerable. Priority depends on whether the affected product and version are installed, whether the relevant service is enabled, and whether it is reachable from the internet or an untrusted internal segment. The privilege of the service and the host’s access to other systems determine the likely blast radius.
This produces a defensible order: exposed unauthenticated paths first, then the same paths reachable from less-trusted internal networks, followed by affected services with narrower access. Applicability still has to be matched to Microsoft’s product-specific advisories and packages; cloud-serviced products may also follow a different remediation path from customer-managed servers.
Deployment follows the affected product

The September release covers Windows and multiple Microsoft product families, so Windows Update alone cannot represent completion. Windows cumulative updates should move through the channel established for each supported release, while Exchange Server, SharePoint Server, Office, SQL Server, developer tools and other installed products require separate applicability, ownership and servicing checks.
- Identify supported Windows builds affected by CVE-2026-81963 or CVE-2026-85880 and accelerate the applicable cumulative update through the organization’s managed Windows channel.
- Inventory externally reachable or broadly accessible Microsoft server workloads, then match their installed versions and enabled services to the September advisories.
- Map the remaining Microsoft products actually in use to applicable updates, responsible teams and maintenance windows.
- Verify installation and any required restart. Approval, synchronization or download does not establish that a vulnerable system has been remediated.
Windows 10 requires particular care because the existence of KB5122878 does not mean every Windows 10 installation remains supported. Microsoft’s page lists Windows 10 ESU, Windows 10 Enterprise LTSC 2021 and Windows 10 IoT Enterprise LTSC 2021 under the update’s applicability, while ordinary version 22H2 reached the end of free support on October 14, 2025. Administrators must distinguish an eligible ESU or LTSC device from an unsupported installation.
The headline totals measure different scopes
The widely cited totals are not interchangeable. The Patch Tuesday-only count is 966 and explicitly excludes vulnerabilities Microsoft fixed earlier in the month; the broader cross-product report gives 974. The published descriptions do not provide a complete item-by-item reconciliation of the eight-entry difference, so presenting either figure as the one definitive denominator would imply more methodological certainty than the sources provide.
The disagreement does not affect the central deployment facts. Two vulnerabilities were exploited before their fixes arrived, other newly patched paths can permit unauthenticated remote code execution, and Microsoft distributes fixes through product- and release-specific mechanisms. Those properties say more about an organization’s immediate exposure than the size of a monthly catalog.
As of September 9, the fixes are available and the two exploited flaws remain the highest-confidence starting point, followed by reachable remote-code paths and then the rest of the applicable inventory. The scale and operators of the observed attacks remain undisclosed; later advisory revisions or threat-intelligence findings may refine which systems deserve the fastest treatment.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.