A Windows security flaw that attackers are actively exploiting has a patch deadline today for government systems, and the same advice applies to every business. If this month's Windows updates have not been installed yet, now is the time.
- What it is: A high-severity flaw (CVE-2026-85880) in a core Windows component (Advanced Local Procedure Call) that lets an attacker who already has basic access escalate to full control of the machine.
- Who is affected: Windows 10 and Windows Server users (versions 2012 through 2022) who have not yet applied Microsoft's September 2026 security updates, released 8 September.
- What the risk is: This is confirmed active exploitation, meaning attackers are using the flaw now, not just in theory.
- What to do: Confirm this month's Windows updates have installed successfully across all devices and servers.
We recommend treating this as a priority patch check today, particularly for any Windows Server still running last month's updates.