Web_Logo
Remote Support
Microsoft Windows: Patch Tuesday Fixes Two Active Zero-Days
Home » Microsoft Updates  »  Microsoft Windows: Patch Tuesday Fixes Two Active Zero-Days

Microsoft Windows: Patch Tuesday Fixes Two Active Zero-Days

Microsoft's September security update is its largest on record, fixing nearly 1,000 flaws in Windows and Office, including two that attackers are already exploiting.

  • What it is: September's Patch Tuesday release addresses 973 vulnerabilities, with two zero-day flaws under active attack: one lets attackers gain full system control (CVE-2026-81963), the other lets them escalate privileges on a compromised machine (CVE-2026-85880)
  • Who is affected: Any business running Windows devices or servers that have not applied this month's updates
  • What the risk is: CISA has set a 22 September deadline for patching CVE-2026-81963 given its severity and active exploitation
  • What to do: Confirm Windows Update has installed this month's patches on all devices, including servers, and restart machines showing a pending update

We recommend checking your patch status this week rather than waiting for the next scheduled maintenance window, given the active exploitation.