Microsoft's Patch Tuesday on September 8, 2026, addressed two critical Windows privilege escalation vulnerabilities: CVE-2026-85880 and CVE-2026-81963, both with a CVSS score of 7.8. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing attackers with low-privilege local access to escalate privileges to SYSTEM. CVE-2026-81963 involves improper link resolution in the Windows Update Stack, enabling similar privilege escalation. Both vulnerabilities require no user interaction and have been actively exploited prior to the patch release. CISA added them to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a remediation deadline of September 22 for U.S. federal agencies.
CVE-2026-85880 affects various Windows 10 and Server versions but excludes Windows 11 and Windows Server 2025. CVE-2026-81963 impacts newer Windows platforms, including Windows 11 and Windows Server 2025. Microsoft released security updates for both vulnerabilities on September 8, 2026, and organizations are advised to prioritize these updates. Security teams should monitor for signs of privilege escalation and unusual SYSTEM-level activities related to these vulnerabilities.
Microsoft is offering Windows 11 Pro for .97, reduced from its standard retail price of 9. This promotional offer is valid until September 27 and provides a lifetime license for a single compatible PC, with no recurring subscription fees. Windows 11 Pro includes features such as BitLocker for full-disk encryption, Hyper-V for running virtual machines, and Windows Sandbox for secure application testing. It supports Azure AD for identity management, offers Snap layouts for multitasking, and includes DirectX 12 Ultimate for enhanced gaming performance. The license is non-transferable, tied to the original PC, and is a digital purchase with no physical product shipped. Users should verify compatibility with Microsoft's PC Health Check app before purchasing.
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days.
The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include:
- APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone.
- UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor.
- UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary.
- UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly.
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Microsoft addressed 974 vulnerabilities in its software suite during its recent Patch Tuesday, marking a record high. The breakdown includes 723 flaws in Windows, 111 in Office, 62 in SQL, and 22 in Developer Tools, with over 110 rated as critical. Two actively exploited vulnerabilities are CVE-2026-85880 and CVE-2026-81963, both allowing local privilege elevation. Other notable vulnerabilities include CVE-2026-55007 (8.1), CVE-2026-80097 (8.6), CVE-2026-69465 (8.8), and several with CVSS scores of 9.6 and above. Microsoft has patched a total of 2,760 security flaws this year, reflecting a trend of increasing vulnerability discoveries. Despite the extensive patching, no significant spike in active exploits has been observed.
Windows 11 Pro is currently on sale for .97, down from its regular price of 9. It includes features such as BitLocker encryption, Hyper-V and Windows Sandbox for virtual machines, and Azure AD for business connectivity. Additional enhancements include Snap layouts, DirectX 12 Ultimate for gaming, TPM 2.0 for secure logins, and Copilot for assistance. The license is only compatible with PCs that meet Windows 11's minimum specifications, which can be checked using Microsoft's free PC Health Check app.
GrapheneOS is an open-source Android-based operating system focused on security and user privacy, appealing to privacy-conscious users. It features an enhanced app sandbox, a privacy-first design for managing app permissions, and regular security updates. The operating system has gained attention on social media platforms like X and Mastodon, where users share tips and experiences, fostering a supportive community. This engagement allows for real-time feedback, collaborative problem-solving, and increased awareness of privacy and security topics.
Microsoft released its September 2026 security updates, addressing two critical Windows elevation-of-privilege vulnerabilities: CVE-2026-85880 and CVE-2026-81963. Both vulnerabilities were exploited before their public disclosure on September 8. CVE-2026-85880 involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing low-privileged attackers to gain SYSTEM privileges. CVE-2026-81963 affects the Windows Update Stack due to improper link resolution and access controls, enabling similar privilege escalation. The September release also includes 974 Common Vulnerabilities and Exposures (CVEs) across various Microsoft products, with 723 affecting Windows. Users of Windows 11 24H2 and 25H2 receive updates via KB5124008, while Windows 11 26H1 receives KB5124012. Windows 11 24H2 Home or Pro editions will reach end of servicing on October 13, 2026. Users are advised to install the updates promptly and back up important data.
Snail, Inc. has launched a new science-fiction survival sandbox game called Honeycomb: The World Beyond, developed by Frozen Way Studio. The game is available on Steam, the Epic Games Store, PlayStation 5, and Xbox Series X|S. Key features include exploration of diverse alien biomes, a bioengineering system for creating new life forms, base building, laboratory research, resource discovery, and survival gameplay. The game incorporates advanced technologies from NVIDIA, such as RTXDI and DLSS 4.5, to enhance visual quality and performance. Frozen Way Games, based in Cracow, Poland, consists of over 80 team members dedicated to game development. Players can access the game through its official website and various social media platforms.
Windows 11 Pro is available for a limited-time offer of A, down from its regular price of A8, until September 27. Key features include Windows Copilot, remote desktop access, TPM 2.0, Smart App Control, biometric login options, BitLocker encryption, Azure AD integration, Hyper-V, and Windows Sandbox. The minimum system requirements are a processor speed of at least 1GHz, 4GB of RAM, and 64GB of hard disk space. The offer is sourced from a reputable Microsoft partner.