Build1 publisher2 min readPublished
Two exploited Windows privilege escalations should go first in September's record Patch Tuesday
Microsoft's record September release fixed up to 997 CVEs, including two local escalations to SYSTEM that attackers used before the patch shipped. A 7.8 score understates the step that turns a phishing foothold into control of the machine, so both go ahead of the 9.8 remote flaws.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CVE-2026-81963 is an elevation-of-privilege flaw in the Windows Update Stack, reported independently by Airbus Helicopters and the Microsoft Threat Intelligence Center.
- CVE-2026-85880 is an elevation-of-privilege flaw in Windows Advanced Local Procedure Call (ALPC), credited to Volexity and Proofpoint.
- CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a federal remediation deadline of September 22.
- The same release fixes at least 12 pre-authentication remote code execution bugs rated CVSS 9.8, in DNS Server, Remote Desktop, RRAS, SSTP, Netlogon, DHCP and other services.
- Microsoft has fixed roughly 2,750 vulnerabilities so far in 2026, more than double the 2020 full-year record of about 1,250.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint No server or workstation role can be exempted from these two patches, because the Update Stack and ALPC are present on every supported Windows build.
- cost At close to a thousand fixes in one month, patching everything on a single schedule stops working, so security teams have to write down a ranking rule they can defend.
- decision Organizations outside federal scope have to set their own date, and the post argues September 22 should be treated as the latest acceptable day for these two.
Both bugs score CVSS 7.8, which looks minor on a page of 9.8s [3][4]. A local escalation needs the attacker to already run code on the machine. The post places this kind of flaw as the second half of most intrusion chains. An attacker gets low-privilege code running through a phishing document, a browser exploit or a compromised service, then uses the escalation to reach SYSTEM [7]. From there the attacker disables defenses, installs persistence and moves laterally [7].
CVE-2026-85880 widens where that second half can start. Reporting cited in the post says it can be used to escape a low-privilege AppContainer sandbox [5]. On an unpatched machine, code confined to a sandbox has the same route to SYSTEM as code running in a normal user session [2][5]. The post does not describe either exploit beyond its weakness class: CWE-59 link following for the Update Stack bug, CWE-787 heap buffer overflow for ALPC [3][4].
The post ranks the month in three tiers. Confirmed-exploited flaws go first. Pre-authentication, network-reachable RCE on internet-facing services goes second. Everything else follows on a risk-based schedule [14]. I think that is the right order for a fleet of workstations and internal servers, where phishing and browser footholds are the likely first step [7].
It transfers less cleanly to an organization that exposes DNS Server, RDP, RRAS, SSTP or the print provider to the internet. Those are the 9.8 services an external attacker can reach [16]. ZDI reportedly classed around 20 of the month's fixes as potentially wormable, meaning pre-authentication and zero-interaction [11]. For that organization the first two tiers are both urgent, and I would staff them in parallel.
Exchange needs its own track. CVE-2026-55007 is a use-after-free that, according to reporting in the post, fires when the server processes an email carrying a malicious Visio attachment. The recipient never has to open it [10]. The post says a mail-triggered bug like this bypasses most user-awareness training and needs a faster timeline than the general cycle [15]. With on-premises Exchange receiving external mail, I would patch it alongside the two escalations.
CISA's catalog entry gave federal agencies 14 days [1]. The post's advice for the two escalations is to patch them first and then check that the update actually applied [18].
The monthly count is less settled than the record label suggests. Published tallies range from roughly 966 to 997, depending on how Chromium and third-party components are counted [1]. The gap between those tallies, 31 CVEs, is more than 15 times the length of the list that has to go first [2].
What to watch
- Whether Microsoft or CISA publish exploitation details or indicators for CVE-2026-81963 and CVE-2026-85880 beyond their weakness classes.
- Whether Exchange CVE-2026-55007 or any of the roughly 20 potentially wormable fixes shows in-the-wild exploitation and enters the KEV catalog, which would reorder the queue.
- Whether October's release keeps 2026 on pace past the roughly 2,750 fixes already shipped this year.