Windows Update Stack and ALPC: Two Exploited Local Privilege Escalation Flaws in the September 2026 Patch Tuesday
Microsoft's September 2026 security update was the largest on record by vulnerability count, with published tallies between roughly 966 and 997 CVEs depending on how Chromium and third-party components are counted. Two of those CVEs matter more than the rest, because Microsoft and CISA both confirmed they were exploited before the patches shipped.
The two exploited flaws
- CVE-2026-81963 — a Windows Update Stack elevation of privilege vulnerability, CVSS 7.8, caused by a link-following flaw (CWE-59).
- CVE-2026-85880 — a Windows Advanced Local Procedure Call (ALPC) elevation of privilege vulnerability, CVSS 7.8, caused by a heap buffer overflow (CWE-787). Reporting notes it can be used to escape a low-privilege AppContainer sandbox.
Both are local privilege escalation issues that yield SYSTEM. Microsoft credited Airbus Helicopters and the Microsoft Threat Intelligence Center for independent reports of CVE-2026-81963, and Volexity and Proofpoint for CVE-2026-85880. CISA added both to the Known Exploited Vulnerabilities catalog on September 8, 2026, with a federal remediation deadline of September 22.
Why the low CVSS is misleading here
A 7.8 score places these flaws below the critical RCE bugs that dominate patch-day headlines, and that is exactly the problem. Local privilege escalation flaws are the second half of most intrusion chains: an attacker who already has code execution as a low-privilege user, whether through a phishing document, a browser exploit or a compromised service, uses the LPE to reach SYSTEM and then disables defenses, installs persistence and moves laterally.
Both of these bugs sit in components that are always present. The Windows Update Stack runs on every supported Windows version, and ALPC is a core inter-process communication mechanism. There is no configuration in which these components are absent, so there is no configuration in which the patch can be skipped.
What the wider patch release contains
Beyond the two exploited flaws, the September release includes a set of pre-authentication RCE issues rated CVSS 9.8 that deserve attention in their own right. Reported examples include Windows DNS Server (CVE-2026-69730), Remote Desktop Services (CVE-2026-69525), the NFS ONCRPC XDR driver (CVE-2026-69595 and CVE-2026-78445), Windows Shell (CVE-2026-69829), SSTP (CVE-2026-73009), RRAS (CVE-2026-69590 and CVE-2026-69852), Netlogon (CVE-2026-72982), the DHCP Server (CVE-2026-69845), the HTTP print provider (CVE-2026-69769) and Message Queuing (CVE-2026-69579).
Microsoft also fixed an Exchange Server use-after-free RCE, CVE-2026-55007, which reporting describes as triggerable by sending an email with a malicious Visio attachment; the server processes the attachment and the recipient does not need to open it. ZDI reportedly classified around 20 of the month's fixes as having wormable potential, meaning pre-authentication, zero-interaction remote code execution.
The patch-volume problem
Microsoft has fixed roughly 2,750 vulnerabilities so far in 2026, more than double the 2020 record of about 1,250. Security commentators have attributed part of the increase to AI-assisted vulnerability research, which finds bugs faster than organizations can triage them.
The operational consequence is that "patch everything" is no longer a workable instruction. An organization facing close to a thousand fixes in a month needs a prioritization rule that is defensible. The rule that the evidence supports is: first, anything confirmed as exploited; second, pre-authentication network-reachable RCE on internet-facing services; third, everything else on a risk-based schedule.
Practical guidance
- Patch the two exploited LPE flaws first, and verify the update actually applied. These are the flaws with confirmed in-the-wild use.
- Prioritize internet-facing services with pre-authentication RCE fixes. DNS Server, RDP, RRAS, SSTP and the print provider are the ones an external attacker can reach.
- Treat Exchange separately. A mail-triggered RCE that does not require the recipient to open an attachment bypasses most user-awareness training and needs a faster timeline than the general patch cycle.
- Do not deprioritize LPE flaws because they are local. They are the escalation step, and an attacker who already has a foothold will use them.
- Track the KEV deadline as a floor, not a target. The federal deadline for these two flaws was September 22; organizations outside the federal scope should not treat that date as permission to wait.
Limitations
This article summarizes Microsoft's security update as reported by security press and vendors. It does not include exploit code. Vulnerability counts for this release vary between sources because of differing treatment of Chromium and non-Microsoft components, and the specific count should be taken from Microsoft's own release notes.
References
- CISA, Known Exploited Vulnerabilities Catalog, entries added September 8, 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Arctic Wolf, "Microsoft Patch Tuesday Security Recap: September 2026 Edition." https://arcticwolf.com/resources/blog/microsoft-patch-tuesday-security-recap-september-2026-edition/
- FreeBuf, "Microsoft releases the largest Patch Tuesday on record: 974 CVEs, including 2 exploited zero-days and 20 wormable flaws," September 9, 2026. https://m.freebuf.com/articles/system/499716.html
- 安天, "September 2026 Microsoft patch day risk notice," September 10, 2026. https://m.antiy.cn/Support/Patch/upgrade_patch_20260910.html
Top comments (0)