VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Patches Two Exploited Windows Zero-Days

high vulnerability

IPA warns two actively exploited Windows privilege escalation flaws (CVE-2026-81963, CVE-2026-85880) were fixed in Microsoft's September 2026 Patch Tuesday.

Japan's IPA (Information-technology Promotion Agency) issued its monthly advisory summarizing Microsoft's September 2026 security updates. Among the disclosed vulnerabilities, Microsoft has confirmed that two are being actively exploited in the wild: CVE-2026-81963, an elevation of privilege vulnerability in the Windows Update stack, and CVE-2026-85880, an elevation of privilege vulnerability in the Windows Advanced Local Procedure Call (ALPC) mechanism. Both flaws could allow an attacker to escalate privileges on a compromised Windows system, potentially leading to full control of the machine.

IPA urges organizations and individual users to apply the September 2026 security updates immediately via Windows Update or through managed patch deployment processes, given the confirmed in-the-wild exploitation and the risk of expanding attack activity. No further technical details, indicators of compromise, or attribution were provided in the advisory. As with all Patch Tuesday-cycle privilege escalation bugs, these are typically leveraged as a second stage following initial access to achieve local privilege escalation rather than as a standalone remote entry vector.

Mentioned in this report

Vulnerabilities CVE-2026-81963KEVCVE-2026-85880KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/0909-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free