CVE-2026-81963 (CVSS 7.8): A high-severity elevation of privilege vulnerability in the Windows Update Stack, associated with improper link resolution before file access. A local attacker who already has access to the system can exploit the flaw to elevate privileges, potentially gaining SYSTEM-level access. The vulnerability was publicly disclosed and exploited in the wild.
CVE-2026-85880 (CVSS 7.8): A high-severity elevation of privilege vulnerability in Windows Advanced Local Procedure Call (ALPC), involving heap-based buffer handling and use of an uninitialized resource. A local attacker can exploit the flaw to elevate privileges on the affected Windows system. The vulnerability is confirmed to have been exploited in the wild.[/subscribe_to_unlock_form]
CVE-2026-81963 (CVSS 7.8): A high-severity elevation of privilege vulnerability in the Windows Update Stack, associated with improper link resolution before file access. A local attacker who already has access to the system can exploit the flaw to elevate privileges, potentially gaining SYSTEM-level access. The vulnerability was publicly disclosed and exploited in the wild.
CVE-2026-85880 (CVSS 7.8): A high-severity elevation of privilege vulnerability in Windows Advanced Local Procedure Call (ALPC), involving heap-based buffer handling and use of an uninitialized resource. A local attacker can exploit the flaw to elevate privileges on the affected Windows system. The vulnerability is confirmed to have been exploited in the wild.[emaillocker id="1283"]
CVE-2026-70352 (CVSS 10.0): A critical elevation of privilege vulnerability in Azure AI Language. The flaw has a maximum CVSS score of 10.0. It is part of the September 2026 security release but was not reported as actively exploited in the supplied article.
CVE-2026-83711 (CVSS 10.0): A critical elevation of privilege vulnerability in Microsoft Azure Active Directory B2C. The vulnerability carries a maximum CVSS score of 10.0 and is included among the critical vulnerabilities addressed in the September 2026 release.
CVE-2026-83941 (CVSS 9.9): A critical elevation of privilege vulnerability affecting Microsoft Entra ID. The vulnerability has a CVSS score of 9.9 and is included among the critical Azure/identity vulnerabilities addressed in the September 2026 Patch Tuesday release.
CVE-2026-66302 (CVSS 9.8): A critical remote code execution vulnerability in Skype for Business. Successful exploitation could allow an attacker to execute arbitrary code in the context of the affected service. It was rated as less likely to be exploited.
Overall, the September 2026 Microsoft security release contains hundreds of vulnerabilities, with 973 vulnerabilities reported across the release and 113 classified as Critical by Microsoft. The two most urgent vulnerabilities are CVE-2026-81963 and CVE-2026-85880 because they are confirmed to have been exploited in the wild. The additional Critical vulnerabilities, particularly those carrying CVSS 9.8–10.0 scores, should also be prioritized according to the affected products and exposure.
We recommend you to update Microsoft Windows to version 10.0.22631.7582.
The following reports contain further technical details:
[/emaillocker]