What happened
On the September 2026 Patch Tuesday, Microsoft released an extensive security update that addressed 974 vulnerabilities within its products. Among these, 723 vulnerabilities were identified in Windows. The update also included fixes for 25 non-Microsoft CVEs, bringing the total number of vulnerabilities addressed to 999. Notably, this release marks the highest number of CVEs published by Microsoft in a single day, signifying a significant security event. Two of the vulnerabilities were actively exploited in the wild at the time of disclosure. One critical vulnerability, CVE-2026-85880, affects the Windows Advanced Local Procedure Call (ALPC) mechanism, a kernel component responsible for inter-process communication. Exploitation of this zero-day vulnerability allows attackers to execute code with SYSTEM privileges through a buffer overflow that enables an out-of-bounds write. This flaw is particularly concerning as its exploitation can lead to privilege escalation attacks, such as ransomware deployment. Microsoft’s ongoing efforts to enhance kernel memory safety appear to be a factor, as neither Server 2025 nor Windows 11 received patches for this vulnerability at the time of disclosure. A second vulnerability, CVE-2026-81963, was also addressed but is not yet confirmed to be exploited in the wild. Several affected components include Microsoft Windows, Citrix ADC, and Google Chromium. With active exploitation confirmed for one of the CVEs, organisations are urged to review their deployment security and ensure updates are applied promptly to mitigate potential risks.
Who is affected
Organisations running affected versions of Microsoft Windows are impacted by the vulnerabilities disclosed during September 2026 Patch Tuesday. This includes systems vulnerable to the zero-day CVE-2026-85880, which targets the Windows ALPC component. Additionally, affected deployments may include systems that utilise Citrix ADC and Google Chromium, as these components also contain vulnerabilities addressed in the update. Systems that are unpatched or have delayed updates are at higher risk of exploitation, especially given the active exploitation of CVE-2026-85880. As the vulnerabilities involve core components and involve active threat actors, a broad range of organisations across different sectors may be impacted should they fail to apply the necessary patches or mitigations.
Recommended actions
- Assess systems to identify those affected by Windows vulnerabilities, particularly focusing on versions susceptible to CVE-2026-85880 and CVE-2026-81963.
- Prioritise the application of available security updates released on September 2026 Patch Tuesday to mitigate active exploitation risks.
- Implement comprehensive monitoring for signs of exploitation related to CVE-2026-85880 and other vulnerabilities addressed in the update.
- Ensure that security controls which limit the impact of kernel-level exploits, such as strict access controls and least privilege policies, are in place.
- Regularly review and update incident response plans to address potential compromise arising from privilege escalation vulnerabilities.
Indicators of compromise
Indicators of compromise specific to the active exploitation of CVE-2026-85880 are not yet publicly available. Monitoring should focus on unusual activity involving the Windows ALPC mechanism and privilege escalation attempts on affected systems. Alerts from endpoint detection and response tools concerning buffer overflow attempts or unusual inter-process communication may also provide early signs of exploitation.

