# Microsoft Patches Two Exploited Windows Zero-Days

Published: 2026-09-08 · Severity: high
Canonical: https://vorant.io/reports/425854ad-b06d-53a9-b91a-e496727b7a44/microsoft-patches-two-exploited-windows-zero-days

> IPA warns two actively exploited Windows privilege escalation flaws (CVE-2026-81963, CVE-2026-85880) were fixed in Microsoft's September 2026 Patch Tuesday.

Japan's IPA (Information-technology Promotion Agency) issued its monthly advisory summarizing Microsoft's September 2026 security updates. Among the disclosed vulnerabilities, Microsoft has confirmed that two are being actively exploited in the wild: CVE-2026-81963, an elevation of privilege vulnerability in the Windows Update stack, and CVE-2026-85880, an elevation of privilege vulnerability in the Windows Advanced Local Procedure Call (ALPC) mechanism. Both flaws could allow an attacker to escalate privileges on a compromised Windows system, potentially leading to full control of the machine.

IPA urges organizations and individual users to apply the September 2026 security updates immediately via Windows Update or through managed patch deployment processes, given the confirmed in-the-wild exploitation and the risk of expanding attack activity. No further technical details, indicators of compromise, or attribution were provided in the advisory. As with all Patch Tuesday-cycle privilege escalation bugs, these are typically leveraged as a second stage following initial access to achieve local privilege escalation rather than as a standalone remote entry vector.

## Mentioned in this report

- Vulnerabilities: CVE-2026-81963 (KEV), CVE-2026-85880 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2026/0909-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/425854ad-b06d-53a9-b91a-e496727b7a44/microsoft-patches-two-exploited-windows-zero-days.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
