Summary
- CVE-2026-81963 and CVE-2026-85880 were exploited before fixes became available and can lead to SYSTEM privileges.
- Tenable counts 964 September Patch Tuesday CVEs, while BleepingComputer counts 966 under a different methodology.
- The scale of the release turns patching into a prioritisation exercise across Windows and a broad range of enterprise products.
Microsoft has fixed two Windows privilege-escalation vulnerabilities already exploited in attacks as part of an exceptionally large September Patch Tuesday release covering hundreds of flaws across its enterprise software portfolio.
Microsoft issued the updates on 8 September. Independent counts differ slightly according to methodology: Tenable records 964 CVEs in the Patch Tuesday release, including 104 rated critical, while BleepingComputer counts 966 vulnerabilities and 105 critical issues.
The small difference is less consequential than the scale. Both assessments describe September as the largest Microsoft Patch Tuesday release they have recorded, spanning Windows, Office, Exchange, Azure, Active Directory-related products, SQL Server, Visual Studio, Remote Desktop, Hyper-V, and numerous other components.
Two vulnerabilities were exploited before patches became available. CVE-2026-81963 affects the Windows Update Stack and involves improper link handling. An attacker with local access can exploit it to elevate privileges to SYSTEM.
CVE-2026-85880 affects Windows Advanced Local Procedure Call and is a heap-based buffer-overflow vulnerability. Successful exploitation can also result in SYSTEM-level privileges.
Microsoft has not publicly detailed the attacks in which the two vulnerabilities were used. Both require local access, so they are more likely to form part of a wider intrusion chain than provide an initial remote entry point on their own.
That makes the surrounding estate relevant to prioritisation. A privilege-escalation flaw becomes more consequential where an attacker has already obtained a lower-privileged account through phishing, credential theft, an exposed service, or another vulnerability.
The broader September release also contains high-impact remote-code-execution issues. Tenable highlights, among others, a Windows DNS Server flaw rated 9.8 that Microsoft assesses as more likely to be exploited, together with vulnerabilities across Remote Desktop Services, Kerberos, Exchange, and other enterprise components.
No organisation can sensibly treat more than 900 vulnerabilities as equal emergencies. Exploitation status, internet exposure, required privileges, affected asset criticality, reachable attack paths, and the business function of individual systems determine the order in which remediation can proceed.
The volume also distributes responsibility across different teams. Endpoint administrators may own Windows updates while application teams assess Office and server products, identity teams examine directory-related issues, and cloud owners work through Azure and development-service exposure.
That division can create gaps where patch governance is organised by technology rather than by attack path. A compromised endpoint, privileged identity, directory service, and exposed server can form one intrusion chain while being managed by separate operational groups.
The September cycle therefore places additional weight on accurate asset inventory. Successful deployment to centrally managed Windows devices does not establish that old servers, development systems, cloud workloads, or unmanaged endpoints have received the relevant fixes.
The differing public vulnerability counts are also a reminder that Patch Tuesday totals are constructed from disclosure data rather than issued as a single risk score by Microsoft. The safest editorial and operational interpretation is not that one exact number defines the month, but that the release is unusually large and contains two flaws already demonstrated in real attacks.
Those two zero-days provide the clearest first priority. The harder work follows behind them: identifying which of the hundreds of remaining vulnerabilities intersect with systems whose exposure and business role justify accelerating remediation beyond the normal maintenance cycle.




