Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday
Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday Microsoft's September 2026 security update was the largest on record by vulnerability count, with published tallies between roughly 966 and 997 CVEs depending on how Chromium and third-party components are counted. Two of those CVEs matter more than the rest, because Microsoft and…
Microsoft's September 2026 security update was the largest in history, releasing over 970 CVEs, many of which were already exploited. Two high-priority flaws, CVE-2026-81963 and CVE-2026-85880, were exploited by hackers before the patches were released. CVE-2026-81963 is a Windows Update Stack vulnerability allowing local privilege escalation to SYSTEM, while CVE-2026-85880 is a Windows Advanced Local Procedure Call issue with similar impact.
Both flaws affect all Windows versions and cannot be skipped. Prior to the patches, CISA added both to the Known Exploited Vulnerabilities catalog with a deadline of September 22. The update also addressed numerous other vulnerabilities, including pre-authentication remote code execution issues in various services. Microsoft estimates that around 20 of the month's fixes had wormable potential.
Security experts recommend patching the two exploited local privilege escalation flaws first, followed by internet-facing services with pre-authentication RCE issues, and other vulnerabilities based on risk. Despite the large number of patches, it is crucial to prioritize fixes to prevent attackers who already have a foothold from escalating privileges and compromising the system.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.