Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Microsoft’s Largest Patch Tuesday: 973 Fixes, Two Zero-Days Under Active Attack

Microsoft released the largest Patch Tuesday in its history on 8 September, fixing 973 vulnerabilities – two of which, the company says, are already under active attack.

Two zero-days for privilege escalation

Both actively exploited flaws enable a local elevation of privilege. CVE-2026-85880 sits in the Windows Advanced Local Procedure Call (ALPC) component, while CVE-2026-81963 affects the Windows Update Stack, where improper link resolution before file access is abused. Microsoft rates both only as “Important” but confirms exploitation in the wild. That is a clear signal that attackers are already chaining the bugs after an initial foothold to gain system-level rights.

Record volume with RCE risks

At 973 entries, it is the biggest Patch Tuesday Microsoft has ever shipped. Beyond the critical-rated bugs, administrators should pay particular attention to several remote code execution flaws in the Windows DNS Server and Remote Desktop Services, which may be exploitable over the network.

  • CVE-2026-85880: ALPC, elevation of privilege, actively exploited
  • CVE-2026-81963: Windows Update Stack, elevation of privilege, actively exploited
  • Windows DNS Server and Remote Desktop Services: multiple RCE fixes

Microsoft urges organisations to deploy the updates immediately through Windows Update; the two zero-days demand urgent action. Where an immediate update is not feasible, operators should harden the affected services and closely monitor accounts holding local administrator rights.

Sources: Microsoft MSRC · Cyber Security News · ntcompatible

Mastodon
Scroll to Top