ZeroHour
The Recordpublished ()ingested

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

highExploit / PoC exploited in the wildimportance 80CVE-2026-81963CVE-2026-85880
AI summary · glm-5.3-flash

CISA confirms exploitation of two Windows zero-days among 973 Microsoft patches; 22,000 Exchange servers remain unpatched.

Microsoft's September Patch Tuesday sets a record with 973 vulnerabilities, and CISA confirms CVE-2026-81963 and CVE-2026-85880 are being exploited, giving federal agencies until September 22 to patch. Nightwing estimates over 22,000 corporate Exchange servers are unpatched against weaponized exploit code. Analysts describe CVE-2026-81963 as an early link in ransomware chains where phishing leads to privilege escalation, and note year-to-date Microsoft disclosures exceed 2,600 bugs.

  • CISA confirms exploitation of both zero-days; federal patch deadline is September 22
  • Nightwing estimates 22,000 corporate Exchange servers unpatched against weaponized exploit code
  • CVE-2026-81963 seen as early step in ransomware chains via phishing and privilege escalation
  • Year-to-date Microsoft disclosures top 2,600, double the previous record year of 2020

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-81963
+1 in the same advisory: …85880
Local Privilege Escalation via Link Following in Windows Update Stack

CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.

Do: Immediately deploy the September 2026 Patch Tuesday cumulative updates to every Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 host; as a KEV entry under BOD 26-04, prioritize internet-exposed and high-value assets, apply vendor mitigations (or discontinue use) where patching is delayed, and follow CISA's forensics triage requirements if compromise is suspected. Verify deployment via patch telemetry and review which local accounts can trigger update-stack activity on shared or multi-user systems.

7.8<1% KEV
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2025
masswell over 1,000,000
Full article279 words · extracted from therecord.media · click to collapse

Microsoft’s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time.

The federal cyberdefense agency, CISA, confirmed that two of them — CVE-2026-81963 and CVE-2026-85880 — are being exploited by hackers. Federal agencies have until September 22 to patch them. 

Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows. More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll. 

Others explained that bugs like CVE-2026-81963 are the first step in a ransomware chain where hackers phish one user and use their access to gain escalated privileges. 

“The component makes it worse. An attacker who owns the update stack owns the thing you'd use to evict them,” Automox engineer Serena DiPenti said. “If you can't say when the update stack last ran, you can't say whether it's patched.”

The two are among 973 bugs disclosed on Patch Tuesday by Microsoft. The company set a previous record in July with fixes for more than 600 security vulnerabilities — which itself was triple the size of the previous record set the month before.

Cybersecurity researchers and defenders have warned for months that the use of artificial intelligence code-review tools would prompt an onslaught of minor vulnerabilities that could be chained together for dangerous attacks. 

Narang noted that the latest Patch Tuesday release pushes the year’s total bugs disclosed over 2,600, which is already more than double the previous record-setting year of 2020. Qualys cybersecurity expert Diksha Ojha added that another vulnerability announced by Adobe this month was a critical-severity bug in Adobe Commerce. 

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-patch-tuesday-september-2026