Skip to content

Security14 publishers3 min readPublished

Two exploited privilege-escalation bugs set the clock in Microsoft's 974-CVE September

CISA's clock covers two local privilege-escalation bugs out of 974. Everything else in Microsoft's largest release has to be ranked in-house, starting from vendor counts that disagree on how many CVEs even shipped.

The Watch · Security desk

What happened

  • Microsoft resolved 974 of its own CVEs plus 25 non-Microsoft ones in September, 999 in total, and by a wide margin the most CVEs the company has ever published in a single day.
  • CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call rated CVSS 7.8, is under active exploitation and lets an authorized local attacker reach SYSTEM privileges.
  • CISA added both flaws to its Known Exploited Vulnerabilities catalog, giving Federal Civilian Executive Branch agencies until September 22, 2026 to apply the fixes.
  • Twenty of the month's fixes close wormable flaws in components including DHCP Server, Active Directory, DNS, SMB Client and Netlogon, with the DNS bug CVE-2026-69730 scored at 9.8.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Two CVEs, roughly 0.2 percent of the month, carry an enforceable date. The rest have to be ranked against each organisation's own inventory, which makes analyst time the limiting resource rather than deployment windows.
  • contradiction Security Affairs rates the Exchange double free as more pressing than either KEV entry, and no Exchange fix is on CISA's clock, so anyone running internet-facing Exchange is working two different priority orders this month.
  • exposure Teams that build their exposure register from vendor advisories rather than release notes have an exploited V8 zero-day missing from it, because Edge shipped the fix and the advisory never appeared.
  • precedent ZDI credits AI-assisted discovery for the volume and records no matching rise in exploitation, so October arrives with a comparable list and the same thin exploited fraction, and the triage bill recurs monthly.

Both exploited flaws need a foothold before they matter. CVE-2026-85880 is a heap overflow in Windows Advanced Local Procedure Call, and Microsoft's advisory says code running in a low-privilege AppContainer can use it to escape the sandbox and elevate, with no additional user interaction [10]. CVE-2026-81963 reaches SYSTEM through improper link resolution in the Windows Update Stack, and Rapid7's Adam Barnett reads the fix as stopping the Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter [12]. Security Affairs notes both require local access and user-level privileges, which places them after initial access in a real intrusion [18]. Cyber Daily's op-ed makes the operational point: no serious attacker builds an intricate one-shot RCE when low-privileged local access plus an elevation bug gets to the same place [13].

Volexity and Proofpoint reported the ALPC bug; Romain Deperne of Airbus Helicopters and Microsoft's own threat intelligence centre reported the Update Stack bug [14]. Microsoft confirmed zero-day exploitation and published nothing about the operators, the volume of attempts, or whether any victim was breached [15]. Tenable counts seven Update Stack privilege escalation flaws since 2022 and says CVE-2026-81963 is the first exploited in the wild, while the ALPC bug is the second ALPC zero-day weaponised since CVE-2023-21674 in January 2023 [16]. One point in defenders' favor: neither Windows 11 nor Server 2025 gets a patch for CVE-2026-85880, which Cyber Daily's op-ed reads as evidence that Microsoft's Rust rewrites of kernel components are holding [19].

The size of the list depends on who is counting. The Hacker News reports 974 Microsoft CVEs [1]. Cisco Talos counts 973, with 113 critical and 82 of those remote code execution [6]. ZDI counts 972 [7]. Security Affairs puts the range at 966 to 997 depending on the treatment of external and Chromium bugs, and adds 204 fixes Microsoft shipped earlier in September across Azure, Entra ID and Edge [8], which makes the month 1,178 [33]. Windows alone accounts for 723, Office 111 and SQL 62, and privilege escalation, RCE and information disclosure cover close to 90 percent of the total [2][4]. The volume is not new: 161 in May, 220 in June, 663 in July, 457 in August [5], so September runs about six times the May figure [34].

Exploitation signal is the scarce input. Microsoft rates 58 further CVEs as more likely to be exploited [26]; with the two confirmed, 60 of 974, or 6.2 percent, carry any signal at all, leaving 914 to be ranked against local inventory [32]. Action1's Jack Bicer frames the work as separating what demands immediate action from what can follow the normal deployment cycle [27].

Exchange is where the ranking gets contested. CVE-2026-55007 (CVSS 8.1) is an unauthenticated RCE reached by mailing a crafted Visio attachment that the server processes during content indexing [20][21]. Microsoft's advisory says reliable exploitation needs sustained memory pressure that is uncommon in normal operation [21]. Security Affairs' answer is that an attacker retrying only has to land once, and it pairs the bug with CVE-2026-69380 (CVSS 8.1), which lets a low-privileged authenticated user impersonate anyone in the organisation and reach every mailbox [22][23]. Remote Desktop Services adds CVE-2026-69525 at CVSS 9.8, unauthenticated code execution that Microsoft qualifies as in-network [24].

Then the advisory gap. Microsoft published no desktop browser advisories before Patch Tuesday for the second month running, per Cyber Daily; Edge stable took the fix for CVE-2026-85046, an exploited V8 zero-day, on September 2, a day ahead of Chrome, and nearly a week later Microsoft's advisory URL still returned a 404 [28]. Eleven other Chrome fixes from that release have no confirmed Edge status [29]. October 14 brings its own queue: Windows 11 24H2 Home and Pro leave servicing, Server 2022 moves to extended support, and paid ESU ends for Server 2012 and 2012 R2 [30].

What to watch

  • Whether Microsoft publishes an advisory for CVE-2026-85046 and confirms which of the other 11 Chrome fixes reached Edge.
  • Any attribution detail from Volexity, Proofpoint or Microsoft on who is using the ALPC and Update Stack bugs, and against whom.
  • First confirmed exploitation of CVE-2026-55007, which would settle whether the memory-pressure requirement really constrains it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories