Published on September 20, 2026 · The mitza.es team

Microsoft released its monthly security bulletin on September 8, 2026, and this time it set an unwelcome record: 966 vulnerabilities fixed in total, 105 of them rated critical, making it the largest update bulletin in the company's history. Among all those fixes, two deserve absolute priority: two zero-days that are already being actively exploited.
The two zero-days you need to patch now
The first is CVE-2026-81963, an elevation of privilege vulnerability in the Windows Update Stack (Windows' own update system), rated CVSS 7.8. The flaw lets an attacker who already has local access exploit improper link resolution before file access to escalate to SYSTEM privileges. It's the first zero-day in this specific component since 2022.
The second is CVE-2026-85880, in Windows Advanced Local Procedure Call (ALPC), also rated CVSS 7.8. It's a heap-based buffer overflow that, again, allows escalation to SYSTEM privileges. It's only the second ALPC zero-day since early 2023 — the first in over three years. Both flaws are already confirmed as actively exploited in the wild.
Another critical vulnerability worth watching
Although it's not on the active zero-day list, CVE-2026-69730 deserves a separate mention: it's a remote code execution flaw in Windows DNS Server, rated CVSS 9.8 out of 10, the top of the scale. An unauthenticated attacker could send a crafted packet to exploit a use-after-free bug and execute code remotely. Microsoft and several security firms flag it as "exploitation more likely," so even though it's not listed as exploited today, it's not one to leave for later.
Why active exploitation outranks the technical score
This bulletin is a good example of something we already covered with August's Patch Tuesday: this month's two zero-days carry a CVSS score of 7.8, lower than the DNS Server flaw's 9.8, but because they're being actively exploited right now, they're the ones that represent the real, immediate risk. A flaw with a maximum score but no confirmed exploitation yet is, in practice, less urgent than a more modest one already being used against real systems.
What to do if you manage Windows machines in your business
Update as soon as possible, prioritizing the two active zero-days. With a bulletin this size, it's a good moment to check once and for all which of your machines are actually up to date and which aren't, rather than waiting for an incident to reveal it. It doesn't matter whether your business runs Windows, macOS, or both: staying up to date remains the most effective and cheapest defense there is, as we also saw with this month's Chrome zero-day. Our IT maintenance service includes this review, and if you want a more complete diagnostic of your overall exposure, you can request a tailored audit.