Key Facts

CISA added CVE-2026-85880 and CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog on September 8. Microsoft’s September release addresses both Windows elevation-of-privilege flaws.

Technical Details

Microsoft’s release notes describe CVE-2026-85880 as a Windows ALPC heap buffer overflow and CVE-2026-81963 as a Windows Update Stack link-following flaw. SecurityWeek reports that both can enable local elevation to SYSTEM.

Impact & Mitigation

Organizations should prioritize the applicable September Windows security updates and use the CISA KEV catalog in vulnerability-prioritization workflows.

Sources

By Allan