Microsoft issues 974 patches, fixes two exploited zero-days
Microsoft released 974 fixes on Tuesday, including two exploited zero-days: ALPC heap overflow CVE-2026-85880 and Windows Update link-following CVE-2026-81963.
Microsoft released fixes for 974 security flaws on Tuesday, including two vulnerabilities already exploited in the wild. The first, CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) that can let a local attacker gain System privileges. Microsoft’s advisory says an attacker who can run code in a low-privilege AppContainer could exploit the bug to escape the sandbox and elevate privileges without additional user interaction.
The second exploited defect, CVE-2026-81963, is an improper link resolution before file access in the Windows Update stack. The flaw can allow local attackers to escalate privileges to System. Security engineers report this is the first Update Stack weakness flagged as a zero-day among seven fixes in that component over the last five years.
The September Patch Tuesday bundle includes 723 Windows fixes and 222 Office patches, 111 of them for Office 2016. Microsoft also addressed vulnerabilities in other products: 62 in SQL Server, 22 in Developer Tools, 16 in SharePoint Server, 12 in Azure, 10 in Skype for Business and nine in Exchange Server. Critical servicing stack updates were published for Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016.
Tenable senior staff research engineer Satnam Narang pointed out that Microsoft had not fixed an ALPC issue since April 2023 and that CVE-2026-85880 is the second zero-day resolved in that component in nearly four years.
Other notable fixes include CVE-2026-55007, a remote code execution bug in Exchange Server; CVE-2026-80097, an elevation-of-privilege issue in Microsoft Authenticator; CVE-2026-69465, remote code execution in SharePoint; CVE-2026-65669, elevation of privilege in SQL Server; and CVE-2026-69525, remote code execution in Remote Desktop Services. Dustin Childs of the Zero Day Initiative estimated about 20 of the patched vulnerabilities could be considered wormable because they enable remote code execution without authentication or user interaction.
Narang warned that AI-assisted vulnerability discovery in 2026 is increasing the volume of reported flaws and advised organizations to focus on which vulnerabilities actually apply to their systems, whether they are reachable and exploitable, and to prioritize remediation accordingly.
Tyler Reguly, associate director at Fortra, said vendors appear to be addressing long-standing, hard-to-find flaws and recommended that IT teams prioritize patches and plan resources to handle the larger update workload.
Microsoft’s advisory urges administrators to identify which fixes apply to their environments and to prioritize updates for vulnerabilities that are reachable and exploitable. Organizations with exposed update services, Remote Desktop Services, Exchange servers or legacy Windows Server and Windows 10 installations are advised to apply the relevant fixes promptly.








