Web_Logo
Remote Support
Security Alert: Two Windows Flaws Exploited, Patch Now
Home » Security Alerts  »  Security Alert: Two Windows Flaws Exploited, Patch Now

Security Alert: Two Windows Flaws Exploited, Patch Now

Microsoft has confirmed that two Windows security flaws are already being used in real cyberattacks, and the US Cybersecurity and Infrastructure Security Agency (CISA) has set a hard deadline for organisations to patch them.

  • What it is: Two Windows vulnerabilities (CVE-2026-85880 and CVE-2026-81963) let an attacker who already has limited access to a device escalate to full control.
  • Who is affected: Any Windows PC or server that has not installed the September 2026 security update.
  • What the risk is: These flaws are being actively exploited right now, so unpatched machines are a live target, not a theoretical risk.
  • What action is needed: Install the September Windows security update as soon as possible. CISA has set a deadline of 22 September 2026 for at-risk organisations to apply the fix.

We recommend confirming that automatic updates are enabled and checking that this month's patch has installed on all devices, particularly any that have been offline for an extended period.

Source: BleepingComputer