{
  "id": 10816643,
  "title": "Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday",
  "url": "https://urgent.news/2026/09/30/windows-update-stack-and-alpc-two-exploited-local-privilege",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T00:40:19.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jeffreyciend/windows-update-stack-and-alpc-two-exploited-local-privilege-escalation-flaws-in-the-september-2026-22n9"
  },
  "original_language": "en",
  "account": "Microsoft's September 2026 security update was the largest in history, releasing over 970 CVEs, many of which were already exploited. Two high-priority flaws, CVE-2026-81963 and CVE-2026-85880, were exploited by hackers before the patches were released. CVE-2026-81963 is a Windows Update Stack vulnerability allowing local privilege escalation to SYSTEM, while CVE-2026-85880 is a Windows Advanced Local Procedure Call issue with similar impact. Both flaws affect all Windows versions and cannot be skipped. Prior to the patches, CISA added both to the Known Exploited Vulnerabilities catalog with a deadline of September 22. The update also addressed numerous other vulnerabilities, including pre-authentication remote code execution issues in various services. Microsoft estimates that around 20 of the month's fixes had wormable potential. Security experts recommend patching the two exploited local privilege escalation flaws first, followed by internet-facing services with pre-authentication RCE issues, and other vulnerabilities based on risk. Despite the large number of patches, it is crucial to prioritize fixes to prevent attackers who already have a foothold from escalating privileges and compromising the system.",
  "summary": "Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday Microsoft's September 2026 security update was the largest on record by vulnerability count, with published tallies between roughly 966 and 997 CVEs depending on how Chromium and third-party components are counted. Two of those CVEs matter more than the rest, because Microsoft and…",
  "key_points": [
    "Two high-priority flaws CVE-2026-81963 and CVE-2026-85880 exploited before patches",
    "Both vulnerabilities allow local privilege escalation to SYSTEM on all Windows versions",
    "CISA added both to Known Exploited Vulnerabilities catalog with September 22 deadline"
  ],
  "editors_take": "This massive update forces administrators to prioritize patching to prevent attackers from escalating privileges and compromising systems, particularly for the two already exploited local privilege escalation flaws.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}