ANSSI flags actively exploited Windows flaws
ANSSI advisory covers dozens of Windows/RDP client vulnerabilities patched September 2026, two of which are being actively exploited in the wild.
ANSSI (CERT-FR) published a bulletin consolidating a large set of Microsoft Windows vulnerabilities affecting virtually the full supported Windows client and server line (Windows 10, Windows 11, Windows Server 2012 through 2025) as well as the Remote Desktop client for Windows Desktop prior to version 1.2.7279.0. The flaws collectively enable remote code execution, privilege escalation, remote denial of service, information disclosure, data integrity compromise, and security policy bypass. Microsoft's own advisories, referenced throughout the bulletin, confirm that two of the vulnerabilities — CVE-2026-81963 and CVE-2026-85880 — are being actively exploited in the wild, while the remainder are disclosed as part of the same September 2026 Patch Tuesday cycle without confirmed in-the-wild exploitation at time of publication.
Given the scale of the affected product matrix (spanning nearly every currently supported Windows release, both client and server, plus the RDP client), this represents a routine but high-volume monthly patch cycle typical of CERT-FR's practice of aggregating all Microsoft Patch Tuesday CVEs into a single advisory. The presence of two actively exploited CVEs elevates the urgency for organizations running affected Windows versions to prioritize patching, particularly given RCE and privilege escalation are among the listed impacts. No specific threat actor, campaign, or malware family is named in connection with the exploitation; ANSSI directs readers to Microsoft's individual CVE bulletins for patch and mitigation guidance.
Defenders should prioritize deployment of the September 8, 2026 Microsoft security updates across all listed Windows 10/11 and Windows Server versions, with particular urgency for systems where CVE-2026-81963 and CVE-2026-85880 apply, and should also update the standalone Remote Desktop client for Windows Desktop to 1.2.7279.0 or later.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1147
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free