Microsoft releases Windows security update addressing 723 flaws

Microsoft has unveiled its September 2026 security updates, addressing two critical Windows elevation-of-privilege vulnerabilities that are currently being exploited in the wild.

Patch Tuesday Overview

The latest Patch Tuesday release encompasses a staggering 974 Common Vulnerabilities and Exposures (CVEs) across various Microsoft products, with 723 of these affecting the Windows operating system.

The two vulnerabilities of particular concern are identified as CVE-2026-85880 and CVE-2026-81963. Notably, Microsoft reports that neither flaw was publicly disclosed prior to the release of patches on September 8, yet exploitation has already been detected.

  • CVE-2026-85880: This vulnerability impacts the Windows Advanced Local Procedure Call (ALPC) and is characterized by a heap-based buffer overflow combined with the use of an uninitialized resource. A low-privileged attacker capable of executing code within an AppContainer can exploit this flaw locally, allowing them to escape the sandbox and gain SYSTEM privileges without any user interaction. Credit for this discovery goes to researchers from Volexity and Proofpoint.
  • CVE-2026-81963: This second flaw affects the Windows Update Stack and arises from improper link resolution and access controls. Similar to the first, a low-privileged attacker can exploit it locally to elevate their privileges to SYSTEM. The Microsoft Threat Intelligence Center (MSTIC) was instrumental in identifying this issue.

Local privilege-escalation vulnerabilities are often linked with other flaws that facilitate initial code execution, making them particularly attractive to attackers aiming for comprehensive control over compromised systems.

Beyond Windows, September’s release also addresses a significant number of vulnerabilities across other Microsoft products, including:

  • 111 vulnerabilities in Microsoft Office
  • 62 in SQL products
  • 22 in developer tools
  • 16 in SharePoint Server
  • 12 in Azure
  • 9 in Exchange Server

For users of Windows 11 24H2 and 25H2, the fixes are being distributed via KB5124008, updating systems to OS builds 26100.9445 and 26200.9445, respectively. Meanwhile, Windows 11 26H1 will receive KB5124012, which updates systems to build 28000.2954.

These cumulative updates also expand Microsoft’s deployment of replacement Secure Boot certificates, as many certificates utilized by Windows devices began expiring in June 2026. Microsoft assures that systems yet to receive the newer certificates will continue to boot and install regular Windows updates during this rollout.

[embedded content]

It’s important for users operating Windows 11 24H2 Home or Pro to be aware that these editions will reach their end of servicing on October 13, 2026. Post this date, they will no longer receive monthly security updates, underscoring the necessity of upgrading to a supported Windows release.

Windows users are strongly encouraged to install the September cumulative updates at their earliest convenience, especially given the active exploitation of the two privilege-escalation vulnerabilities.

To install the updates, navigate to Settings > Windows Update > Download & install all. A system restart will be required to finalize the update process. Additionally, backing up important data is advisable to mitigate the risk of data loss due to installation errors or unexpected power interruptions.

If you found this article informative, consider following us on X/Twitter and LinkedIn for more exclusive content.

Winsage
Microsoft releases Windows security update addressing 723 flaws