September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
Reported exploitedWindows Update StackWindows Advanced Local Procedure CallOur summary
Microsoft has released its September 2026 security updates, addressing a record number of flaws, including two vulnerabilities currently being exploited in the wild. The critical fixes resolve CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call, both of which allow privileged users to escalate to SYSTEM rights. Additionally, researchers have published a proof-of-concept for a bypass of the Microsoft Defender patch, highlighting ongoing risks to endpoint security.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.