Skip to content

Microsoft just fixed two Windows flaws that attackers were already exploiting

Windows 11 Security Update Patches Two Actively Exploited Bugs

Microsoft’s September 2026 Windows 11 security update shipped on September 8, and two of the fixes were already being used by attackers before the patch existed. CVE-2026-85880 and CVE-2026-81963 are both local privilege escalation bugs, the kind that let someone who already has a foothold on a PC grab full SYSTEM control. The Cybersecurity and Infrastructure Security Agency added both to its Known Exploited Vulnerabilities catalog the same day, giving federal civilian agencies until September 22 to patch. Consumers do not get a legal deadline, but the same clock is running on every unpatched machine.

TL;DR: Microsoft’s September update fixes two Windows flaws, CVE-2026-85880 and CVE-2026-81963, that attackers were already exploiting before a patch existed. Both let someone with local access escalate to full SYSTEM privileges. CISA added both to its exploited vulnerabilities list and gave federal agencies until September 22 to patch. Windows 11 versions 23H2 through 26H1 are covered, and most home PCs install this automatically, but shared or work machines should not wait.

What this Windows 11 security update actually fixes

CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call system, the mechanism Windows uses for programs to talk to each other on the same machine. CVE-2026-81963 sits in the Windows Update stack itself and works through improper link resolution, a technique often called link following.

CVEComponentTypeCVSS
CVE-2026-85880Windows ALPCPrivilege escalation7.8
CVE-2026-81963Windows Update stackPrivilege escalation (link following)7.8

Both flaws carry a CVSS score of 7.8 and both require an attacker to already have some form of low-level access to the machine. Neither is a remote attack on its own. What they do instead is turn a minor foothold into complete control, according to Microsoft’s own September security update notes.

Local privilege escalation bugs usually sit lower on the urgency scale than flaws attackers can trigger remotely with no access at all. What changes that here is timing. Both of these were already being used in the wild before Microsoft had a fix ready, and that is a much shorter list than the hundreds of other bugs patched the same day.

Why CISA’s deadline matters even if you do not work for the government

CISA’s Known Exploited Vulnerabilities catalog only carries legal weight for federal civilian agencies, which now have until September 22 to patch both flaws under CISA’s September 8 alert. Everyone else is free to ignore that date on paper.

In practice, a KEV catalog listing is CISA’s way of saying real attackers are already using this against real machines, not just proof-of-concept code sitting in a lab. That distinction is what separates these two CVEs from most of the hundreds of other bugs patched the same day.

That gap in urgency shows up most on machines other people can also touch. A library computer, a shared family desktop, or a work laptop logged into by more than one account all give an attacker the exact starting point CVE-2026-85880 and CVE-2026-81963 need. A single-user laptop that never leaves someone’s bag is a lower priority by comparison, though still worth patching this week rather than next month.

How this fits into a record-setting patch month

Windows 10 is not exempt either. Tenable’s breakdown of the release lists Windows 10 versions 21H2 and 22H2 among the affected products for CVE-2026-85880, alongside the Windows 11 releases and several Windows Server branches. Anyone still on an older Windows 10 build should not assume this is a Windows 11 problem only.

Microsoft’s own release notes group Windows 11 versions 23H2, 24H2, 25H2, and 26H1 under Critical severity for September, with remote code execution listed as the top overall impact category across the full batch of fixes, separate from the two privilege escalation zero-days.

The exact total is harder to pin down than usual. Tenable’s count puts the release at 964 CVEs, while other trackers list figures closer to 970, a gap that comes down to how duplicate advisories across product lines get tallied. Either way, this is one of the largest single Patch Tuesday releases Microsoft has shipped.

What to actually check on your own PC

Most home Windows 11 PCs have automatic updates turned on by default, so this patch has likely already installed itself or is waiting on a restart. Go to Settings, then Windows Update, and confirm the September 8 update shows as installed rather than pending.

Machines that see the most risk are shared computers, public kiosks, and work laptops where several people or accounts have some level of access, since both bugs need that starting foothold to matter. If Windows 11 default settings still have update pauses enabled from an earlier troubleshooting session, this is a good week to turn that back off. A PC that already feels sluggish is a separate problem, usually tied to Chrome slow on Windows 11 rather than anything in this update.

Leave a Reply

Your email address will not be published. Required fields are marked *