Windows Update Stack and ALPC Actively Exploited Zero-Days from Record September 2026 Patch Tuesday (CVE-2026-81963 / CVE-2026-85880)
Scope: Windows 10, Windows 11, Windows Server 2019, 2022, and 2025 (All Supported Versions)
Severity: Red
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities including two actively exploited elevation of privilege zero-days confirmed in the wild before today's patch. CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack, and CVE-2026-85880, a Windows Advanced Local Procedure Call flaw, both allow authorized local attackers to escalate to full SYSTEM privileges in low-complexity attacks requiring no user interaction. CISA added both to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of September 22, 2026. Organizations must apply the September 2026 cumulative update to all Windows endpoints and servers immediately, prioritizing internet-facing and remotely accessible systems first, and verify the update completed successfully by checking the build number in winver.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.