CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Security Alert: Microsoft Releases September 2026 Security Updates

unknownknown exploitedCVE-2026-85880CVE-2026-81963
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
JPCERT-AT-2026-0025 JPCERT/CC 2026-09-09 I. Overview Microsoft has released September 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication or elevate privileges locally after authentication, etc. Microsoft Corporation September 2026 Security Updates https://msrc.microsoft.com/update-guide/en-US/releaseNote/2026-Sep According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. Please refer to the latest information provided by Microsoft and implement the measures described in "II. Solution." CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880 CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963 II. Solution Please apply the security update programs through Microsoft Update, Windows Update, etc. Microsoft Update Catalog https://www.catalog.update.microsoft.com/ Windows Update: FAQ https://support.microsoft.com/en-us/help/12373/windows-update-faq III. References Microsoft Corporation Release Notes https://msrc.microsoft.com/update-guide/ If you have any information regarding this alert, please contact JPCERT/CC. JPCERT Coordination Center (Cyber Security Coordination Group) MAIL: [email protected] https://www.jpcert.or.jp/english/

Details

Source
JPCERT/CC Security Alerts (JP · national-cert · site)
Severity
unknown
Published
2026-09-09
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://www.jpcert.or.jp/english/at/2026/at260025.html

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-85880coverage & exploitation statusNVD · CVE.org
CVE-2026-81963coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from JPCERT/CC Security Alerts