CyberzSOC

Publication detail
← Back to advisories & guidance

Microsoft Releases September 2026 Security Updates ↗ source

September 9, 2026 JPCERT/CC Alert

Summary

Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication or elevate privileges locally after authentication, etc. September 2026 Security Updates According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. Please refer to the latest information provided by Microsoft and implement the measures described in "II. Solution." Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Update Stack Elevation of Privilege Vulnerability Please apply the security update programs through Microsoft Update, Windows Update, etc. If you have any information regarding this alert, please contact JPCERT/CC.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-81963 7.8 High Microsoft Windows Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
CVE-2026-85880 7.8 High Microsoft Windows Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges loc…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.