Microsoft released the largest Patch Tuesday in its history on 8 September, fixing 973 vulnerabilities – two of which, the company says, are already under active attack.
Two zero-days for privilege escalation
Both actively exploited flaws enable a local elevation of privilege. CVE-2026-85880 sits in the Windows Advanced Local Procedure Call (ALPC) component, while CVE-2026-81963 affects the Windows Update Stack, where improper link resolution before file access is abused. Microsoft rates both only as “Important” but confirms exploitation in the wild. That is a clear signal that attackers are already chaining the bugs after an initial foothold to gain system-level rights.
Record volume with RCE risks
At 973 entries, it is the biggest Patch Tuesday Microsoft has ever shipped. Beyond the critical-rated bugs, administrators should pay particular attention to several remote code execution flaws in the Windows DNS Server and Remote Desktop Services, which may be exploitable over the network.
- CVE-2026-85880: ALPC, elevation of privilege, actively exploited
- CVE-2026-81963: Windows Update Stack, elevation of privilege, actively exploited
- Windows DNS Server and Remote Desktop Services: multiple RCE fixes
Microsoft urges organisations to deploy the updates immediately through Windows Update; the two zero-days demand urgent action. Where an immediate update is not feasible, operators should harden the affected services and closely monitor accounts holding local administrator rights.
Sources: Microsoft MSRC · Cyber Security News · ntcompatible



















