Microsoft Security Update Addresses Active Exploits

Microsoft Security Update Addresses Active Exploits

First seen 9 Sep 2026, 06:44 UTC Sploituswww.microsoft.com 75.8

Article Content

Browse articles
ThreatCluster

On September 8, 2026, Microsoft released a security update addressing critical vulnerabilities in its products, notably CVE-2026-85880 and CVE-2026-81963, both of which were confirmed to be actively exploited before the update was issued. The vulnerabilities involve privilege escalation in Windows Advanced Local Procedure Call (ALPC) and the Windows Update stack. Affected customers are urged to apply the updates immediately, as the vulnerabilities were added to the CISA KEV list on the same day. The update includes patches for 38 existing vulnerabilities and updates to one advisory. Microsoft emphasizes the importance of applying these updates promptly to mitigate potential risks. The updates are automatically applied for most users, but manual intervention may be required for some systems. The next scheduled security update is set for October 13, 2026.

Key Points: • Microsoft released critical security updates on September 8, 2026. • CVE-2026-85880 and CVE-2026-81963 are actively exploited vulnerabilities. • Affected users must apply updates immediately to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-08
Microsoft releases security updates
Updates address critical vulnerabilities CVE-2026-85880 and CVE-2026-81963, confirmed to be exploited in the wild.
Microsoft
2026-09-08
CVE-2026-85880 added to CISA KEV
CVE-2026-85880 was confirmed to be actively exploited and added to the CISA KEV catalog.
Microsoft
2026-09-08
CVE-2026-81963 added to CISA KEV
CVE-2026-81963 was also confirmed to be actively exploited and added to the CISA KEV catalog.
Microsoft