High CVE-2026-81963, CVE-2026-85880 — Two Windows privilege-escalation bugs were exploited before September 2026's Patch Tuesday: one in the Windows Update stack (Windows 11 / Server 2025) and one in ALPC (Windows 10, Server 2012-2022). Fixed build numbers and how to check.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Attackers were already using two Windows bugs to go from a normal user (or malware running as one) to SYSTEM. Both were fixed in the September 8, 2026 updates. If a PC or server is below the build numbers below, install the latest cumulative update and reboot. Windows 10 PCs only get the fix if they're enrolled in Extended Security Updates.
| CVE-2026-81963 | Windows Update Stack, link-following → SYSTEM. Windows 11 23H2–26H1, Server 2025 |
|---|---|
| CVE-2026-85880 | Advanced Local Procedure Call (ALPC) heap overflow → elevation of privilege. Windows 10, Server 2012–2022 |
| CVSS 3.1 | 7.8 High (both) |
| Access needed | Local: the attacker must already run code as a normal user |
| Exploited? | Yes, both added to CISA KEV 2026-09-08 |
| Fixed | September 8, 2026 cumulative updates and later |
Neither of these lets someone break in from the internet on its own. They’re privilege escalation bugs: the second step of almost every real Windows compromise. Someone opens a malicious attachment or runs a fake installer, the malware lands as a normal user, and one of these bugs turns that into SYSTEM: full control, able to disable antivirus, dump passwords, and spread across the network.
Both were exploited before Microsoft released the fix, which is why CISA added them to its Known Exploited Vulnerabilities list the same day.
Check the full build number. Press Win+R, type winver, or in PowerShell:
$v = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
"$($v.DisplayVersion) build $($v.CurrentBuild).$($v.UBR)"
You’re patched if your build is at or above the number in the table:
| Windows version | Fixed build | CVE |
|---|---|---|
| Windows 11 23H2 | 22631.7582 | 81963 |
| Windows 11 24H2 | 26100.9445 | 81963 |
| Windows 11 25H2 | 26200.9445 | 81963 |
| Windows 11 26H1 | 28000.2954 | 81963 |
| Windows Server 2025 | 26100.33438 | 81963 |
| Windows 10 22H2 / 21H2 | 19045.7725 / 19044.7725 | 85880 |
| Windows 10 1809 / Server 2019 | 17763.9245 | 85880 |
| Windows 10 1607 / Server 2016 | 14393.9512 | 85880 |
| Windows Server 2022 | 20348.5622 | 85880 |
| Windows Server 2012 R2 | 9600.23398 | 85880 |
| Windows Server 2012 | 9200.26349 | 85880 |
Any later monthly update also contains these fixes, so you don’t need the September one specifically. Just get current.
Windows 10 reached end of support in October 2025. Microsoft still publishes fixes like CVE-2026-85880 for it, but only PCs enrolled in Extended Security Updates (ESU) receive them. A Windows 10 machine outside ESU will never get this patch. The same goes for Server 2012 / 2012 R2 without ESU.
If your business still has Windows 10 PCs, they need to go into ESU, be upgraded to Windows 11, or be replaced. An unpatched machine with a known, exploited privilege-escalation bug is an easy foothold for ransomware.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.