Security Alert: Microsoft Releases September 2026 Security Updates
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
JPCERT-AT-2026-0025
JPCERT/CC
2026-09-09
I. Overview
Microsoft has released September 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication or elevate privileges locally after authentication, etc.
Microsoft Corporation
September 2026 Security Updates
https://msrc.microsoft.com/update-guide/en-US/releaseNote/2026-Sep
According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. Please refer to the latest information provided by Microsoft and implement the measures described in "II. Solution."
CVE-2026-85880
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
CVE-2026-81963
Windows Update Stack Elevation of Privilege Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
II. Solution
Please apply the security update programs through Microsoft Update, Windows Update, etc.
Microsoft Update Catalog
https://www.catalog.update.microsoft.com/
Windows Update: FAQ
https://support.microsoft.com/en-us/help/12373/windows-update-faq
III. References
Microsoft Corporation
Release Notes
https://msrc.microsoft.com/update-guide/
If you have any information regarding this alert, please contact JPCERT/CC.
JPCERT Coordination Center (Cyber Security Coordination Group)
MAIL: [email protected]
https://www.jpcert.or.jp/english/
Details
Original advisory: https://www.jpcert.or.jp/english/at/2026/at260025.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-85880Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 45% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-81963Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 48% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85880 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81963 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl
- unknownexploitedMicrosoft Monthly Security Update (September 2026)hkcert
- unknownexploitedMultiples vulnérabilités dans Microsoft Windows (09 septembre 2026)cert-fr-avis
- unknownexploitedMicrosoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1cccs
- highexploitedCVE-2026-85880: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges…nvd
- highexploitedCVE-2026-81963: Improper link resolution before file access ('link following') in Windows Update Stack allows …nvd
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- highexploitedCVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerabilitymsrc
- highexploitedCVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerabilitymsrc
- criticalexploitedCVE-2026-81963: Microsoft Windows Link Following Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerabilitycisa-kev
More from JPCERT/CC Security Alerts
- unknownSecurity Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-141)2026-09-09
- unknownSecurity Alert: Microsoft Releases August 2026 Security Updates2026-08-12
- unknownSecurity Alert: [Updated] Microsoft Releases July 2026 Security Updates2026-07-31
- unknownSecurity Alert: Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-63)2026-06-10
- unknownSecurity Alert: Microsoft Releases June 2026 Security Updates2026-06-10