Microsoft patches 966 vulnerabilities: Two Windows zero-days actively exploited

A significant update from Microsoft has emerged, marking a pivotal moment in cybersecurity. On September 8, 2026, the tech giant released a staggering 966 security updates, addressing a wide array of vulnerabilities that have raised eyebrows across the industry. Among these, 105 issues were classified as critical, including two zero-day vulnerabilities that had already been exploited in the wild prior to the patch release. The vulnerabilities in question, CVE-2026-81963 and CVE-2026-85880, are particularly alarming as they allow authorized local attackers to escalate their privileges to SYSTEM level, a highly privileged context within the Windows operating system.

Details of the Vulnerabilities

According to BleepingComputer, this release represents Microsoft’s largest Patch Tuesday to date. The breakdown of the vulnerabilities reveals that 438 were related to privilege escalation, followed by 258 concerning remote code execution (RCE), and 173 involving information disclosures. However, it is crucial to note that not all RCE vulnerabilities can be exploited remotely without user interaction; the conditions and pathways for exploitation vary significantly.

Of the 105 critical vulnerabilities, the majority—81—are associated with remote code execution, while 20 pertain to privilege escalation, two involve information disclosure, and one addresses the bypassing of a security feature. It’s important to clarify that the total of 966 vulnerabilities includes only those published on this particular Patch Tuesday, excluding earlier fixes for Azure and other cloud products.

Focusing on CVE-2026-81963, this vulnerability is found within the Windows Update Stack, where Microsoft describes the issue as stemming from an incorrect resolution of links prior to file access. An attacker with local access can exploit this flaw to elevate their privileges to the SYSTEM level, which is among the highest privilege contexts in Windows. This vulnerability was credited to Romain Deperne and Microsoft’s Threat Intelligence Center, yet details regarding its real-world exploitation remain undisclosed.

The second zero-day vulnerability, CVE-2026-85880, affects the Windows Advanced Local Procedure Call (ALPC), a critical component for inter-process communication within the operating system. Microsoft has identified this issue as a heap-based buffer overflow, again allowing an authorized local attacker to escalate privileges to SYSTEM. The discovery of this vulnerability involved collaboration between Volexity and researchers from Proofpoint, including Mark Kelly, David Galazin, and Jeremy Hedges.

Implications and Recommendations

While the sheer number of vulnerabilities—966—might initially seem daunting, it is essential to differentiate between the total count and the actual number of actively exploited vulnerabilities. Only two zero-days have been confirmed as actively exploited during this Patch Tuesday, while many others are either newly discovered or reported by security researchers without documented exploitation in the wild.

In recent months, Microsoft has ramped up its internal vulnerability search efforts, increasingly leveraging automated and AI-assisted systems to analyze its code. This approach may lead to a higher number of published CVEs, but it does not necessarily indicate a decline in the overall security of Windows. Nevertheless, the message for users is clear: supported Windows systems should prioritize the installation of the September updates, especially given the potential for the two actively exploited privilege escalations to be part of ongoing attack chains.

In summary, while the record number of vulnerabilities is noteworthy, the critical nature of the two confirmed zero-days, along with their deep integration within the operating system, underscores the urgency for users to act swiftly. The implications of these vulnerabilities extend beyond mere numbers; they represent potential gateways for attackers to gain significant control once initial access has been established.

Winsage
Microsoft patches 966 vulnerabilities: Two Windows zero-days actively exploited