Windows zero-days CVE-2026-81963, CVE-2026-85880 exploited
At a glance
| Severity | HIGH |
|---|---|
| CVSS | CVE-2026-81963: 7.8, CVE-2026-85880: 7.8 |
| EPSS (30-day exploit probability) | CVE-2026-81963: 0.4%, CVE-2026-85880: 3.6% |
| In CISA KEV (exploited) | Yes, due 2026-09-22 |
| Vendor | Microsoft |
| CVE IDs | CVE-2026-81963, CVE-2026-85880 |
Two Windows privilege-escalation flaws, CVE-2026-81963 and CVE-2026-85880, were the only vulnerabilities reported as exploited in the record September 2026 Patch Tuesday, and both are in CISA’s Known Exploited Vulnerabilities (KEV) catalog with a federal due date of 22 September 2026. With the October Patch Tuesday near, any Windows system that has not taken the September updates is still exposed to a Windows vulnerability under active attack.
What happened
According to Help Net Security’s October forecast, written by an Ivanti product manager, September 2026 Patch Tuesday fixed 973 CVEs across the Microsoft portfolio, an all-time record. Of those, only CVE-2026-85880 and CVE-2026-81963 were reported as known exploited, and none were publicly disclosed before the fix.
CISA added both to KEV on 8 September 2026. How the attacks were carried out, who is behind them and how widely they have been used have not been disclosed in the material we reviewed. KEV lists ransomware campaign use as unknown for both.
Am I affected? Windows builds at risk
Per NVD, the affected builds are as follows. Anything below the listed build is vulnerable.
CVE-2026-81963 (Windows Update Stack, link following)
- Windows 11 23H2 below 10.0.22631.7582
- Windows 11 24H2 below 10.0.26100.9445
- Windows 11 25H2 below 10.0.26200.9445
- Windows 11 26H1 below 10.0.28000.2954
- Windows Server 2025 below 10.0.26100.33438
CVE-2026-85880 (Windows ALPC, heap-based buffer overflow)
- Windows 10 1607 below 10.0.14393.9512, 1809 below 10.0.17763.9245
- Windows 10 21H2 below 10.0.19044.7725 and 22H2 below 10.0.19045.7725
- Windows Server 2016 below 10.0.14393.9512, 2019 below 10.0.17763.9245, 2022 below 10.0.20348.5622
- Windows Server 2012 and 2012 R2 (no fixed build listed in NVD)
Technical details
| Detail | CVE-2026-81963 | CVE-2026-85880 |
|---|---|---|
| Component | Windows Update Stack | Windows ALPC |
| Weakness | CWE-59, CWE-284 | CWE-122, CWE-908 |
| Impact | Local privilege escalation | Local privilege escalation |
| CVSS 3.1 | 7.8 (High) | 7.8 (High) |
| Vector | AV:L/AC:L/PR:L/UI:N | AV:L/AC:L/PR:L/UI:N |
| EPSS | 0.39% | 3.6% |
| KEV added / due | 2026-09-08 / 2026-09-22 | 2026-09-08 / 2026-09-22 |
Both require an attacker who already has a low-privileged local account (PR:L) and need no user interaction. “Link following” means the component follows a file link to an unintended target; ALPC is the Windows local inter-process communication mechanism. Both end in high impact on confidentiality, integrity and availability.
Why this matters
Analysis, not new facts: local privilege escalation bugs are rarely the way in. They are the second step after phishing, a stolen credential or a web-facing foothold, turning a limited user into SYSTEM so an attacker can disable security tools or dump credentials. The CVSS score of 7.8 understates the risk because KEV status confirms real-world use. The low EPSS figures reflect a statistical model, not a reason to delay when exploitation is already confirmed.
Also in the October forecast
- Microsoft has kept issuing updates for Office 2016 and Office 2019 after their October 2025 end of support, but the author notes these are likely poorly tested. KB5002907, aimed at outdated Microsoft 365 apps, was reported to remove or deactivate those Office versions, and Microsoft paused it.
- Apple released macOS 27 Golden Gate on 14 September and reported a zero-day, CVE-2026-86950, fixed in updates for all its operating systems. Details beyond that are not in our sources.
How to fix and what to do
- Check build numbers against the lists above and confirm every endpoint and server is at or above the fixed build. The KEV due date has passed, so treat any gap as overdue.
- Prioritise multi-user hosts such as RDS servers, jump boxes, VDI and shared workstations, where a low-privileged account is most likely to exist.
- Windows Server 2012 and 2012 R2 are listed as affected without a fixed build in NVD. Check Microsoft’s advisories for their status and isolate any unpatched systems.
- Hunt for unexpected SYSTEM-level child processes spawned from standard user sessions, and new services or scheduled tasks created shortly after a low-privilege logon. This is a general hunting suggestion; no indicators of compromise have been published.
- Before October Patch Tuesday, review Office 2016 and 2019 inventory and plan migration, and test Office updates on a pilot group first.
Sources
- NVD: CVE-2026-81963
- NVD: CVE-2026-85880
- Microsoft MSRC: CVE-2026-81963
- Microsoft MSRC: CVE-2026-85880
- CISA KEV: CVE-2026-85880
- Help Net Security: October 2026 Patch Tuesday forecast
