Key Facts
CISA added CVE-2026-85880 and CVE-2026-81963 to its Known Exploited Vulnerabilities Catalog on September 8. Microsoft’s September release addresses both Windows elevation-of-privilege flaws.
Technical Details
Microsoft’s release notes describe CVE-2026-85880 as a Windows ALPC heap buffer overflow and CVE-2026-81963 as a Windows Update Stack link-following flaw. SecurityWeek reports that both can enable local elevation to SYSTEM.
Impact & Mitigation
Organizations should prioritize the applicable September Windows security updates and use the CISA KEV catalog in vulnerability-prioritization workflows.
