Security News

Microsoft's Record Patch Tuesday: Two Actively Exploited Flaws Demand Urgent Attention

Key Takeaway Apply this month's Windows updates as a priority given active exploitation, and don't rely on advisories alone; make sure Edge and Chrome browsers are fully updated too.

Microsoft's September 2026 Patch Tuesday release addressed 999 vulnerabilities across Microsoft and non-Microsoft products, the highest number of CVEs the company has published in a single day, according to Rapid7 lead software engineer Adam Barnett. Of these, 974 affected Microsoft's own products, including 723 in Windows alone, with a further 25 non-Microsoft CVEs also patched.

Two of the flaws are already being exploited in the wild. CVE-2026-85880 is a Windows elevation of privilege bug in the Advanced Local Procedure Call mechanism that can grant attackers full SYSTEM access through a buffer overflow. Notably, Windows Server 2025 and Windows 11 are not patched for this issue, which Barnett suggested may relate to Microsoft's efforts to rewrite parts of the Windows kernel in the memory safe language Rust. The second, CVE-2026-81963, affects the Windows Update Stack and can also lead to SYSTEM level access, and while its severity score is moderate, attackers may still chain it with other exploits to escalate privileges.

Rapid7 also flagged a gap in visibility around CVE-2026-85046, a zero-day in Google's V8 JavaScript engine patched by Chrome on 3 September 2026. Microsoft Edge received a related fix the day before, but as of Barnett's commentary, Microsoft had not issued a formal security advisory for the flaw, meaning organisations that rely solely on advisories to track their exposure could miss it entirely.

Summarised by CISO AI from Australian Cyber Security Magazine. We link back to every original so you can read it yourself.