Web_Logo
Remote Support
Microsoft Windows: September Patch Fixes Two Active Zero-Days
Home » Microsoft Updates  »  Microsoft Windows: September Patch Fixes Two Active Zero-Days

Microsoft Windows: September Patch Fixes Two Active Zero-Days

Microsoft's September update round is its largest yet, fixing nearly 1,000 security flaws in Windows and related products, including two that are already being used in real attacks.

  • What it is: September's Patch Tuesday addresses over 970 vulnerabilities, with two actively exploited zero-days: CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack).
  • Who is affected: Anyone running Windows, including Windows 10 and 11 devices and Windows Server.
  • The risk: Both zero-days let an attacker who already has limited access to a device escalate to full System-level control.
  • What to do: Install the update via Settings > Windows Update, or confirm with your IT provider that it has been pushed across your fleet.

We recommend applying this update without delay given both flaws are already being exploited.

Source: BleepingComputer