fixes

Winsage
September 10, 2026
Microsoft's Patch Tuesday on September 8, 2026, addressed two critical Windows privilege escalation vulnerabilities: CVE-2026-85880 and CVE-2026-81963, both with a CVSS score of 7.8. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing attackers with low-privilege local access to escalate privileges to SYSTEM. CVE-2026-81963 involves improper link resolution in the Windows Update Stack, enabling similar privilege escalation. Both vulnerabilities require no user interaction and have been actively exploited prior to the patch release. CISA added them to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a remediation deadline of September 22 for U.S. federal agencies. CVE-2026-85880 affects various Windows 10 and Server versions but excludes Windows 11 and Windows Server 2025. CVE-2026-81963 impacts newer Windows platforms, including Windows 11 and Windows Server 2025. Microsoft released security updates for both vulnerabilities on September 8, 2026, and organizations are advised to prioritize these updates. Security teams should monitor for signs of privilege escalation and unusual SYSTEM-level activities related to these vulnerabilities.
AppWizard
September 9, 2026
A new hotfix for The Blood of Dawnwalker has been released, focusing on stability improvements, resolving progression blockers, and fixing controller-related frame rate drops. Key enhancements include: - Improved game stability. - Resolved tutorial progress issues with the Voracious Bite ability. - Fixed character Coen becoming trapped in buildings. - Enabled dialogue between Crake and Coen during training. - Prevented dead NPCs from initiating conversations. - Addressed blocking issues under specific conditions. - Resolved game saving problems. - Ocha will no longer attack Coen when guards are present. - Fixed a bug causing Coen to get stuck in a cave during the "Deep Down" quest. - Ensured Murohn spawns correctly. - Corrected premature ending of a solution in the "Hive and Seek" quest. - Resolved infinite loading screens in the "On the Run" quest. - Accurate display of difficulty level for "A Lone Wolf's Hunt." - Fixed a soft-lock issue after following Sara. - Investigating the rag in the "Smoke and Ashes" quest is now optional. - Resolved a blocker in "The Heart Wants What It Wants" quest. - Coen and Iorgu will drink from cups at lower graphical settings. - Removed the red pipe asset. - Fixed music stopping during the prologue. - Fixed frame rate drops from outdated GameInput software. - Torches will no longer grow uncontrollably. - Resolved issues with Quality preset mods. - Fixed VSync issues with FSR Frame Generation. The hotfix is now live on Steam.
BetaBeacon
September 9, 2026
Android Studio Emulator is the official Android SDK tooling maintained by Google for app developers to test code against specific Android API levels, screen densities, and hardware profiles.
Winsage
September 9, 2026
Microsoft addressed 974 vulnerabilities in its software suite during its recent Patch Tuesday, marking a record high. The breakdown includes 723 flaws in Windows, 111 in Office, 62 in SQL, and 22 in Developer Tools, with over 110 rated as critical. Two actively exploited vulnerabilities are CVE-2026-85880 and CVE-2026-81963, both allowing local privilege elevation. Other notable vulnerabilities include CVE-2026-55007 (8.1), CVE-2026-80097 (8.6), CVE-2026-69465 (8.8), and several with CVSS scores of 9.6 and above. Microsoft has patched a total of 2,760 security flaws this year, reflecting a trend of increasing vulnerability discoveries. Despite the extensive patching, no significant spike in active exploits has been observed.
Winsage
September 9, 2026
On September 8, 2026, Microsoft disclosed a security vulnerability identified as CVE-2026-69449, related to a heap-based buffer overflow in the Windows BitLocker component, allowing authorized attackers to execute code on compromised machines. The vulnerability is classified as CWE-122, and is assessed as “Exploitation Less Likely.” It affects Windows 10, Windows 11, and Windows Server versions from 2012 to 2025. The fixes are included in cumulative updates KB5124008, KB5124012, KB5122878, and KB5122871. No public disclosure or observed exploitation occurred before the patch's release. The flaw allows for remote code execution through in-network attacks, primarily posing a risk to insiders. Affected systems include various versions of Windows 10, Windows 11, and Windows Server, applicable to both x64 and ARM64 architectures. Administrators should verify installed build numbers to ensure updates have been applied. The advisory does not specify which BitLocker code path is affected or the nature of the input that reaches the vulnerable buffer.
Winsage
September 9, 2026
The September 2026 security cycle revealed a bifurcated approach to vulnerability management by Microsoft, focusing on cloud-side identity services with silent mitigations and traditional Patch Tuesday updates for on-premises Windows infrastructure. On September 3, Microsoft addressed nine cloud-side vulnerabilities, including two with a CVSS score of 10.0: CVE-2026-83711 (Azure AD B2C elevation of privilege) and CVE-2026-70352 (Azure AI Language Authoring missing authentication). Additionally, CVE-2026-83941 (Entra ID elevation of privilege, rated 9.9) and CVE-2026-80098 (Copilot Studio cryptographic flaw) were noted. On September 8, the Patch Tuesday update addressed 70 CVEs, including critical issues in the on-premises stack, such as CVE-2026-83939 (Windows Secure Kernel Mode elevation of privilege). CVE-2026-69414 (ShieldBreak), an elevation of privilege vulnerability in the Defender Malware Protection Engine, was patched out-of-band on September 3 after being publicly exposed for three weeks. Microsoft is shifting its Self-Service Password Reset (SSPR) enforcement to default to passkeys as of September 7, with plans to phase out SMS and voice-based authentication by February 2027. This aims to enhance security by moving away from legacy credentials.
Winsage
September 8, 2026
Windows 11's latest Patch Tuesday delivered over 650 security fixes, a six-fold increase compared to typical monthly updates. This surge is linked to advancements in artificial intelligence, which have accelerated vulnerability discovery and the urgency to address them. AI aids Microsoft's engineers in the patching process but is also exploited by malicious actors, creating an ongoing cybersecurity arms race.
Winsage
September 8, 2026
Microsoft released its September 2026 security updates, addressing two critical Windows elevation-of-privilege vulnerabilities: CVE-2026-85880 and CVE-2026-81963. Both vulnerabilities were exploited before their public disclosure on September 8. CVE-2026-85880 involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing low-privileged attackers to gain SYSTEM privileges. CVE-2026-81963 affects the Windows Update Stack due to improper link resolution and access controls, enabling similar privilege escalation. The September release also includes 974 Common Vulnerabilities and Exposures (CVEs) across various Microsoft products, with 723 affecting Windows. Users of Windows 11 24H2 and 25H2 receive updates via KB5124008, while Windows 11 26H1 receives KB5124012. Windows 11 24H2 Home or Pro editions will reach end of servicing on October 13, 2026. Users are advised to install the updates promptly and back up important data.
Winsage
September 8, 2026
Several pathways exist to expedite the official rollout of Windows updates. Users can navigate to Windows Update settings to enable the latest updates, install optional preview updates manually, join the Windows Insider Program for pre-release versions, or use ViveTool to unlock hidden features. 1. Enable the latest updates: A toggle in Windows Update settings allows users to receive new features and updates as soon as they are available. 2. Install optional updates: Preview updates are released towards the end of each month and can be installed manually through Windows Update. 3. Use Windows Insider: The Insider Program offers pre-release versions of Windows, with the Beta Channel for innovation and the Release Preview Channel for stability. 4. Enable hidden features with ViveTool: This tool unlocks features already present in Windows but not activated, requiring technical expertise. Activating the toggle in Windows Update prioritizes the device for new features while ensuring essential security updates continue.
Search