Microsoft's September Patch Tuesday release fixes a Windows flaw that attackers are already using in real attacks, alongside a record number of other security fixes.
- What it is: A Windows Update Stack vulnerability (CVE-2026-81963) that lets an attacker who already has some access to a machine escalate to full SYSTEM-level control. Microsoft has confirmed it is being actively exploited.
- Who is affected: All supported versions of Windows, including Windows 10 and Windows 11 business devices.
- What the risk is: Once exploited, an attacker can take complete control of the affected machine, well beyond the access they started with.
- What action is needed: Install the September Windows security update as soon as possible. If you are on Windows 11 and have hit installation issues, Microsoft has since released an emergency follow-up update (KB5129195) to address them.
We recommend prioritising this update across your fleet this week rather than waiting for the next scheduled patch cycle. Source: Microsoft Security Update Guide.