Security update

Winsage
September 10, 2026
Microsoft acknowledged an issue with the KB5120998 August 2026 preview update for Windows 11, where mouse settings related to cursor personalization were altered or reset. This problem affected non-English Windows installations, causing personalized settings to fail to load and revert to standard configurations. The issue was resolved in the subsequent KB5124008 September 2026 cumulative update, which users were encouraged to install. KB5120998 was an optional update, potentially limiting the number of affected users. Additionally, Microsoft has been addressing various mouse-related issues in recent months, including problems with the Windows Recovery Environment and disappearing mouse pointers in Outlook.
Winsage
September 10, 2026
Microsoft announced that the September 2026 Patch Tuesday updates resolved an issue affecting desktop settings on certain Windows devices, which caused desktop wallpapers to revert to a solid black background after the installation of the KB5120998 August 2026 preview update. This bug impacted Windows 11 24H2 and 25H2 systems, preventing the correct loading of desktop settings and also affecting mouse settings. Microsoft recommended users update their devices to the latest security update released on September 8, 2026 (KB5124008) to benefit from the fix.
Winsage
September 10, 2026
Microsoft's Patch Tuesday on September 8, 2026, addressed two critical Windows privilege escalation vulnerabilities: CVE-2026-85880 and CVE-2026-81963, both with a CVSS score of 7.8. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing attackers with low-privilege local access to escalate privileges to SYSTEM. CVE-2026-81963 involves improper link resolution in the Windows Update Stack, enabling similar privilege escalation. Both vulnerabilities require no user interaction and have been actively exploited prior to the patch release. CISA added them to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a remediation deadline of September 22 for U.S. federal agencies. CVE-2026-85880 affects various Windows 10 and Server versions but excludes Windows 11 and Windows Server 2025. CVE-2026-81963 impacts newer Windows platforms, including Windows 11 and Windows Server 2025. Microsoft released security updates for both vulnerabilities on September 8, 2026, and organizations are advised to prioritize these updates. Security teams should monitor for signs of privilege escalation and unusual SYSTEM-level activities related to these vulnerabilities.
Winsage
September 9, 2026
Microsoft's September Patch Tuesday update for Windows 11 introduces several enhancements, including the ability to reposition the taskbar to the top, left, or right sides of the screen. Users can adjust the taskbar's alignment, height, and icon size, though the auto-hide feature is limited to the bottom position. The Start menu now allows users to select between Small and Large sizes, with the Recommended section rebranded as Recent, and options to hide their name and profile picture. The Search window has been streamlined to focus on suggested or recent searches. The update addresses 995 security vulnerabilities, including 121 critical vulnerabilities and two zero-day flaws (CVE-2026-81963 and CVE-2026-85880), which could allow attackers to gain system-level privileges.
Winsage
September 9, 2026
Microsoft's September 2026 security update revealed 973 vulnerabilities, with 113 classified as critical. Two actively exploited vulnerabilities are CVE-2026-81963 (Windows Update Stack, elevation of privilege, CVSS 7.8) and CVE-2026-85880 (Windows ALPC, elevation of privilege, CVSS 7.8). Among the 113 critical vulnerabilities, 82 are remote code execution (RCE) vulnerabilities. Notable vulnerabilities include: - CVE-2026-69676: RCE in Windows Kerberos, CVSS 8.8, authentication bypass. - CVE-2026-69852: RCE in Windows RRAS, CVSS 7.5, heap-based buffer overflow. - CVE-2026-72957: RCE in Windows Deployment Services, CVSS 7.8. - CVE-2026-69854: Elevation of privilege in Spring Cloud Azure, CVSS 9.0, improper authentication. - CVE-2026-83501: Information disclosure in Windows VBS, CVSS 5.5. - CVE-2026-69730: RCE in Windows DNS Server, CVSS 9.8. Less likely to be exploited vulnerabilities include: - CVE-2026-69845: RCE in Windows DHCP Server, CVSS 9.8, heap-based buffer overflow. - CVE-2026-65772: Vulnerability in Microsoft Dynamics 365 On-Premises, CVSS 8.8, deserialization of untrusted data. - CVE-2026-66302: RCE in Skype for Business, CVSS 9.8. Additional critical vulnerabilities include: - CVE-2026-62916: Elevation of privilege in Microsoft Entra ID, CVSS 9.1. - CVE-2026-83941: Elevation of privilege in Entra ID, CVSS 9.9. - CVE-2026-80098: Vulnerability in Copilot Studio, CVSS 9.3, improper verification of cryptographic signatures. Talos is releasing a new Snort ruleset to detect attempts to exploit these vulnerabilities, with specific SIDs for Snort 2 and Snort 3 rule coverage.
Winsage
September 8, 2026
Microsoft released its September 2026 security updates, addressing two critical Windows elevation-of-privilege vulnerabilities: CVE-2026-85880 and CVE-2026-81963. Both vulnerabilities were exploited before their public disclosure on September 8. CVE-2026-85880 involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing low-privileged attackers to gain SYSTEM privileges. CVE-2026-81963 affects the Windows Update Stack due to improper link resolution and access controls, enabling similar privilege escalation. The September release also includes 974 Common Vulnerabilities and Exposures (CVEs) across various Microsoft products, with 723 affecting Windows. Users of Windows 11 24H2 and 25H2 receive updates via KB5124008, while Windows 11 26H1 receives KB5124012. Windows 11 24H2 Home or Pro editions will reach end of servicing on October 13, 2026. Users are advised to install the updates promptly and back up important data.
Winsage
September 5, 2026
Microsoft has updated the Power menu in Windows 11, separating the Shut down and Restart buttons from the update process. Users can now shut down their PCs without interruptions from pending updates. The update introduces four options: Shut down, Restart, Update and shut down, and Update and restart. This change aims to provide a more user-friendly experience by allowing direct shutdown or restart actions without automatic update installations. Additionally, Microsoft has minimized forced restarts due to updates, requiring users to restart their PCs only once a month, and introduced an option to pause updates for an extended period. The August 27 optional update also improved sleep behavior during updates, ensuring that manually put-to-sleep PCs return to sleep after completing an update.
Winsage
September 4, 2026
Microsoft has acknowledged an issue affecting some Windows devices after the installation of the KB5120998 preview update released on August 27, 2026. This issue primarily impacts Windows 11 versions 24H2 and 25H2, causing desktop settings, including wallpaper and themes, to reset or be lost, often resulting in a solid black background. Users are unable to manually restore their customized settings due to the issue preventing the correct loading of settings. The KB5120998 update was intended to enhance the Start menu, taskbar, and Windows search but inadvertently introduced complications, including changes to mouse settings that cannot be restored. The update is optional but installs automatically for users with the "Get the latest updates as soon as they're available" feature enabled. A similar bug occurred in February 2020 with the KB4539602 update, which disrupted desktop wallpaper functionality.
Winsage
September 1, 2026
Microsoft is changing the Windows 11 update process to consolidate various updates into a single monthly restart, starting with updates released on or after July 28, 2026. This new system combines driver updates, .NET updates, and firmware updates with the monthly security update, allowing for one restart per month instead of multiple. Updates requiring a restart will wait until the scheduled monthly security update, which is typically released on the second Tuesday of each month. Users can find combined updates under Settings > Windows Update > Available updates and can choose to restart sooner if desired. Additionally, users can pause updates for up to 35 days through Settings > Windows Update.
Search