bleeping-computer · Crawled Sep 9, 2026

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Read original article ↗

AI Summary

Microsoft's September 2026 Patch Tuesday addresses 966 security vulnerabilities, including two actively exploited zero-day flaws. The first, CVE-2026-81963, is an elevation of privilege vulnerability in the Windows Update Stack that allows attackers to gain SYSTEM privileges through improper link resolution. The second, CVE-2026-85880, is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC) that enables local privilege escalation to SYSTEM. Both vulnerabilities were actively exploited in the wild before patches were released, though technical details on exploitation are not disclosed. The update marks Microsoft's largest Patch Tuesday to date, attributed to the use of AI-powered vulnerability discovery.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.