Skip to content

Security1 publisher2 min readPublished

Microsoft's two exploited September flaws escalate a foothold an attacker already has

Nightmare Eclipse published ShieldCrash, a claimed bypass of the CVE-2026-69414 Defender patch, within hours of the September fixes, while the two flaws already under attack both need an account before they reach SYSTEM.

The Watch · Security desk

Illustration accompanying Microsoft's two exploited September flaws escalate a foothold an attacker already has

What happened

  • Microsoft's September 2026 Patch Tuesday set another record for patch volume and included fixes for two vulnerabilities already exploited as zero-days, both of them privilege escalation to SYSTEM.
  • CVE-2026-81963 in the Windows Update Stack lets a low-privileged authenticated attacker reach SYSTEM on multiple Windows 11 versions and Windows Server 2025, via improper link resolution and access control.
  • CVE-2026-85880, in Windows Advanced Local Procedure Call, covers Windows 10 and Server 2012 through 2022, and came from Proofpoint researchers who have not said how widely it was used.
  • Every Windows fix this month, the two exploited flaws included, ships inside the cumulative security updates and monthly rollups, so one install closes all of them.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure No supported Windows generation sits this one out: the newer estate carries the Update Stack zero-day, the Windows 10 and Server 2012-2022 estate carries the ALPC one.
  • contradiction The flaws with confirmed exploitation need an attacker already inside, while the flaws with unauthenticated reach have no reported exploitation, so exploitation status and blast radius point at different CVEs this month.
  • decision With the Windows work collapsing into one install, the scheduling argument moves to Exchange and SharePoint, which Childs puts on the same priority list and which need their own maintenance windows.
  • precedent A bypass PoC arriving the same day as the fixes weakens patch state as evidence that a bug class is closed, and Help Net Security treats that publication rhythm as routine now rather than remarkable.

Dustin Childs of TrendAI's Zero Day Initiative doubts the automatic update process itself is compromised, and reads CVE-2026-81963 as something an attacker pairs with a code execution bug to spread malware or ransomware [6]. CrowdStrike puts the second zero-day in the same bracket, saying this class of flaw has historically appeared in post-compromise tooling used by commodity malware and by targeted intrusion operators, as a reliable final step from user-mode to kernel-mode control [8]. Both exploited bugs therefore need an attacker who already holds an account on the machine, which means the fixes raise the cost of the last step in an intrusion rather than the first [15].

Satnam Narang at Tenable counts seven privilege escalation flaws in the Windows Update Stack since 2022, and CVE-2026-81963 is the first of them to be exploited and the first to arrive as a zero-day [4]. The other six were patched without any public report of use [16]. Neither Microsoft's Threat Intelligence Centre, which reported the Update Stack flaw [5], nor Proofpoint, which reported the ALPC bug [7], has published the attacks.

ShieldCrash landed within hours of the fixes going live, with Nightmare Eclipse claiming a bypass of the patch for CVE-2026-69414, ShieldBreak, in the Microsoft Malware Protection Engine [2]. Help Net Security calls the bypass ostensible and reports no independent reproduction, and it does not date the ShieldBreak patch [17]. So the public clock runs hours from this month's release to the PoC appearing; it is not a measured interval from the Defender fix to a working bypass of it.

Reach this month sits with flaws nobody has been seen using. Childs flags a cluster of 20 bugs across most supported Windows versions where a remote, unauthenticated attacker gets arbitrary code execution with no user interaction [9], and singles out DNS flaw CVE-2026-69730 as the spiritual successor to SigRed, noting there has not been a global worm in years [10]. Kerberos authentication bypass CVE-2026-69676 is rated Exploitation More Likely, and Childs's read is one phished workstation account plus one crafted request equals code execution on a domain controller, which he calls a domain-compromise primitive [11]. CVE-2026-80093 in the Cloud Files Mini Filter Driver requires winning a race condition, and its technical details are already public [12].

Off the Windows rollup, Childs puts Exchange Server first, for a remote code execution flaw triggered when the server processes an email carrying a malicious Visio attachment, then SharePoint Server for an assortment of bugs [14].

A queue built on the known-exploited label alone patches two escalation primitives this week and leaves the DNS listener and the domain controller for the next window.

What to watch

  • Whether MSTIC or Proofpoint publish the intrusion sets behind CVE-2026-81963 and CVE-2026-85880, which would show whether this is commodity tooling or targeted operations.
  • Whether anyone reproduces ShieldCrash against a fully updated Malware Protection Engine, and whether Microsoft assigns a fresh CVE to the bypass.
  • First reported in-the-wild exploitation of DNS flaw CVE-2026-69730 or Kerberos flaw CVE-2026-69676.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories