Microsoft has released its September monthly security update to address a record 974 vulnerabilities across its software lineup, patching two critical zero-day flaws that were already being exploited in real-world attacks. Both vulnerabilities could allow attackers to gain SYSTEM-level privileges on target devices, granting them sweeping control over compromised computers. The widespread release covers flaws in Windows, Office, SQL, Developer Tools, SharePoint Server, Azure, Skype for Business, and Exchange Server.
Zero-Day Flaws Targeted Windows ALPC and Update Stack
The first actively exploited flaw, designated as CVE-2026-85880, involves a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC). An attacker who has already secured code execution within a low-privilege AppContainer sandbox could use this weakness to break containment, escalate their permissions, and secure SYSTEM-level access. Local privilege escalation flaws present a severe risk in cyberattacks because malicious actors frequently gain an initial foothold through low-level access before exploiting such weaknesses to circumvent system restrictions. Microsoft confirmed that this flaw was being leveraged in the wild prior to the patch release.
The second zero-day, tracked as CVE-2026-81963, resides in the Windows Update Stack and stems from improper link resolution before file access. Like the ALPC flaw, it was actively exploited in live attacks. Successful exploitation enables an attacker to obtain SYSTEM privileges, potentially allowing unauthorized data access, deeper compromise of the machine, and further malicious activity.
Windows and Office Account for Bulk of Critical Patches
The September release is notable for its sheer volume of fixes across key product lines. The Windows operating system accounts for the vast majority of the patches, with 723 individual vulnerabilities resolved. Microsoft also patched 222 flaws in Office, 62 in SQL, 22 in Developer Tools, 16 in SharePoint Server, 12 in Azure, 10 in Skype for Business, and nine in Exchange Server. Because the update resolves security holes that are already under active exploitation, security professionals view timely installation as essential to prevent broader attacks.
Beyond security vulnerabilities, the update resolves several operational bugs affecting Windows 11 systems. These include issues that caused black desktop wallpapers and erratic cursor behavior, problems that had disrupted some users since late August. Addressing these performance defects makes the release an important fix for general operating system stability as well as core security.
Prompt Installation Advised to Protect Enterprise Systems
Windows typically downloads and installs monthly updates automatically, though users can also check for updates manually through the Windows Update menu in system settings. Security experts advise organizations to prioritize applying the patches on systems that house sensitive records, business data, or mission-critical services.
With both zero-day vulnerabilities confirmed as actively exploited before patches became available, delaying deployment exposes networks to a heightened risk of intrusion. Organizations and individual users are urged to verify that the latest patches have been installed and to finalize any pending update procedures immediately.