Microsoft’s September 2026 Patch Tuesday addresses a record 974 CVEs, including two zero-days in Windows ALPC and the Windows Update Stack that can let local attackers gain SYSTEM privileges. The update also fixes major flaws in Exchange Server, SharePoint, SQL Server, Remote Desktop Services, and other Microsoft products, with several issues marked as especially urgent. #CVE-2026-85880 #CVE-2026-81963 #WindowsALPC #WindowsUpdateStack #ExchangeServer #SharePoint #SQLServer #RemoteDesktopServices
Keypoints
- Microsoft patched 974 CVEs across its products in a single Patch Tuesday release.
- CVE-2026-85880 is a zero-day heap buffer overflow in Windows ALPC that can elevate local attackers to SYSTEM.
- CVE-2026-81963 is a zero-day link-following flaw in the Windows Update Stack that also enables SYSTEM privilege escalation.
- The update includes important fixes for Exchange Server, SharePoint, SQL Server, Authenticator, and Remote Desktop Services.
- Twenty of the patched flaws are considered wormable because they allow unauthenticated remote code execution.