Urgent.News

What's breaking now, across thousands of outlets.

Tech

Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday

Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday Microsoft's September 2026 security update was the largest on record by vulnerability count, with published tallies between roughly 966 and 997 CVEs depending on how Chromium and third-party components are counted. Two of those CVEs matter more than the rest, because Microsoft and…

Microsoft's September 2026 security update was the largest in history, releasing over 970 CVEs, many of which were already exploited. Two high-priority flaws, CVE-2026-81963 and CVE-2026-85880, were exploited by hackers before the patches were released. CVE-2026-81963 is a Windows Update Stack vulnerability allowing local privilege escalation to SYSTEM, while CVE-2026-85880 is a Windows Advanced Local Procedure Call issue with similar impact.

Both flaws affect all Windows versions and cannot be skipped. Prior to the patches, CISA added both to the Known Exploited Vulnerabilities catalog with a deadline of September 22. The update also addressed numerous other vulnerabilities, including pre-authentication remote code execution issues in various services. Microsoft estimates that around 20 of the month's fixes had wormable potential.

Security experts recommend patching the two exploited local privilege escalation flaws first, followed by internet-facing services with pre-authentication RCE issues, and other vulnerabilities based on risk. Despite the large number of patches, it is crucial to prioritize fixes to prevent attackers who already have a foothold from escalating privileges and compromising the system.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

dev.to ships its comment CSRF token as value="NOTHING". Here's what that breaks.

There's a small thing that will cost you an afternoon if you ever try to script a comment on dev.to. I'm writing it down because I lost that afternoon.

  • dev.to ships CSRF token as "NOTHING", breaking comment scripting
  • Token crucial for preventing CSRF attacks, unavailable to scripts
  • Non-JavaScript clients receive 422 error due to invalid token

I built a tiny CLI to make open-source contributions less intimidating

The frustrating part of contributing is not always the code You find an issue that looks useful. Then the questions start: Where in the codebase should I look?

  • PR Spark is a CLI tool for open-source contributors
  • Generates contribution brief from issue title and description
  • Aims to simplify first-time contributions to open-source projects

DNS Records Explained — What A, CNAME, and TXT Records Actually Point To

"Configuring a domain" usually boils down to "adding a DNS record." Setting up a subdomain, improving email deliverability, proving ownership of a domain to some external service — the goals differ…

  • A record maps a hostname to an IPv4 address for direct routing.
  • CNAME record serves as an alias, pointing to another hostname indirectly.
  • TXT record attaches text strings to domains for various machine uses.

More from Wednesday 30 September →