Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Windows Zero-Days CVE-2026-81963 & CVE-2026-85880: September 2026 Patch Tuesday

High CVE-2026-81963, CVE-2026-85880 — Two Windows privilege-escalation bugs were exploited before September 2026's Patch Tuesday: one in the Windows Update stack (Windows 11 / Server 2025) and one in ALPC (Windows 10, Server 2012-2022). Fixed build numbers and how to check.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Attackers were already using two Windows bugs to go from a normal user (or malware running as one) to SYSTEM. Both were fixed in the September 8, 2026 updates. If a PC or server is below the build numbers below, install the latest cumulative update and reboot. Windows 10 PCs only get the fix if they're enrolled in Extended Security Updates.

CVE-2026-81963Windows Update Stack, link-following → SYSTEM. Windows 11 23H2–26H1, Server 2025
CVE-2026-85880Advanced Local Procedure Call (ALPC) heap overflow → elevation of privilege. Windows 10, Server 2012–2022
CVSS 3.17.8 High (both)
Access neededLocal: the attacker must already run code as a normal user
Exploited?Yes, both added to CISA KEV 2026-09-08
FixedSeptember 8, 2026 cumulative updates and later

What these bugs do

Neither of these lets someone break in from the internet on its own. They’re privilege escalation bugs: the second step of almost every real Windows compromise. Someone opens a malicious attachment or runs a fake installer, the malware lands as a normal user, and one of these bugs turns that into SYSTEM: full control, able to disable antivirus, dump passwords, and spread across the network.

  • CVE-2026-81963 (Windows Update Stack): the update component follows a file-system link it shouldn’t. A local user can plant a link that makes a SYSTEM-level process write or act on a file of the attacker’s choosing.
  • CVE-2026-85880 (ALPC): a heap buffer overflow in the inter-process messaging system Windows services use to talk to each other.

Both were exploited before Microsoft released the fix, which is why CISA added them to its Known Exploited Vulnerabilities list the same day.

Am I affected?

Check the full build number. Press Win+R, type winver, or in PowerShell:

$v = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
"$($v.DisplayVersion)  build $($v.CurrentBuild).$($v.UBR)"

You’re patched if your build is at or above the number in the table:

Windows versionFixed buildCVE
Windows 11 23H222631.758281963
Windows 11 24H226100.944581963
Windows 11 25H226200.944581963
Windows 11 26H128000.295481963
Windows Server 202526100.3343881963
Windows 10 22H2 / 21H219045.7725 / 19044.772585880
Windows 10 1809 / Server 201917763.924585880
Windows 10 1607 / Server 201614393.951285880
Windows Server 202220348.562285880
Windows Server 2012 R29600.2339885880
Windows Server 20129200.2634985880

How to patch

  1. Settings → Windows Update → Check for updates, install the latest cumulative update, and restart. The fix isn’t active until the reboot.
  2. For servers, use Windows Update, WSUS, or your RMM tool, and schedule the reboot.
  3. Re-run the build check above to confirm.

Any later monthly update also contains these fixes, so you don’t need the September one specifically. Just get current.

The Windows 10 problem

Windows 10 reached end of support in October 2025. Microsoft still publishes fixes like CVE-2026-85880 for it, but only PCs enrolled in Extended Security Updates (ESU) receive them. A Windows 10 machine outside ESU will never get this patch. The same goes for Server 2012 / 2012 R2 without ESU.

If your business still has Windows 10 PCs, they need to go into ESU, be upgraded to Windows 11, or be replaced. An unpatched machine with a known, exploited privilege-escalation bug is an easy foothold for ransomware.

Reduce the impact of the next one

  • Don’t give everyday users local admin. It doesn’t stop these bugs, but it removes many simpler paths to the same result.
  • Turn on automatic updates and make sure PCs actually reboot. A pending-restart PC is an unpatched PC.
  • Keep endpoint protection (Defender or similar) on and monitored. It’s often what catches the malware before it gets to use a bug like this.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories