CVE Tools

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

Help Net SecurityBy Zeljka Zorz

Reported exploitedWindows Update StackWindows Advanced Local Procedure Call

Our summary

Microsoft has released its September 2026 security updates, addressing a record number of flaws, including two vulnerabilities currently being exploited in the wild. The critical fixes resolve CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call, both of which allow privileged users to escalate to SYSTEM rights. Additionally, researchers have published a proof-of-concept for a bypass of the Microsoft Defender patch, highlighting ongoing risks to endpoint security.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store