Safety & Trending News Alert
CISA flags two exploited Windows flaws; September fixes are out
Two privilege-escalation flaws are being used in real attacks, according to CISA and Microsoft. The practical response is to identify the Windows version, install the matching September update and verify the restart—not click an alert in an email or pop-up.

Two Windows flaws moved onto CISA’s exploited list Tuesday
The Cybersecurity and Infrastructure Security Agency added two Microsoft Windows vulnerabilities to its Known Exploited Vulnerabilities catalog on September 8: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call, or ALPC. Microsoft released security updates for both the same day and marks both as exploited. Each is rated “Important” with a CVSS base score of 7.8 in Microsoft’s Security Update Guide. CISA lists September 22 as the federal remediation due date and says ransomware use is unknown—not absent, and not confirmed.
These are local privilege-escalation bugs, not a remote drive-by by themselves
Both vulnerabilities can let an attacker who already has a lower level of access raise privileges to SYSTEM, the most powerful Windows account context. Microsoft says CVE-2026-81963 involves improper link resolution before file access in the Windows Update Stack. CVE-2026-85880 is a heap-based buffer overflow in ALPC; Microsoft says code running in a low-privilege AppContainer can use it locally to escape that sandbox without additional user interaction. That distinction matters: the disclosures do not describe someone taking over a fully patched computer merely by knowing its internet address. They describe tools that can make an earlier foothold far more damaging.
The affected Windows versions do not line up exactly
Microsoft’s product table lists CVE-2026-81963 for Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025. CVE-2026-85880 reaches Windows 10 versions 21H2 and 22H2, certain older or long-term servicing releases and Windows Server versions through 2022; Microsoft’s current product table does not list ordinary Windows 11 editions for that second flaw. Do not use a CVE headline alone to guess whether a machine is covered. Open Settings, select System and About, and record the edition, version, operating-system build and system type before comparing it with Microsoft’s affected-product table.
Use Windows Update first, then verify the build after the restart
For a personal Windows 11 PC, open Settings, select Windows Update and choose “Check for updates.” Install the September 8 cumulative security update offered for that device and restart when prompted. Microsoft maps Windows 11 version 23H2 to KB5122880, versions 24H2 and 25H2 to KB5124008, and version 26H1 to KB5124012 for CVE-2026-81963. The company maps supported Windows 10 21H2 and 22H2 systems receiving the September security release to KB5122878 for CVE-2026-85880. Managed work or school computers may follow an administrator’s deployment schedule; do not bypass that policy or install a catalog package chosen from a search result. After rebooting, return to Windows Update, check again and open Update history to confirm that the matching cumulative update reports success.
Windows 10 users need to check support status as well as patch status
General Windows 10 support ended October 14, 2025. Microsoft says eligible personal Windows 10 PCs can receive critical and important updates through the Consumer Extended Security Updates program until October 12, 2027; commercial and long-term servicing editions have separate rules. A Windows 10 machine that still works but is not enrolled in an applicable ESU path may not receive the September fix through ordinary Windows Update. Check Settings for the exact edition and enrollment state. If the PC cannot move to a supported Windows release, treat replacement or another supported operating system as a security decision rather than assuming an antivirus subscription fills the update gap.
Do not let a real patch become the hook for a fake support call
A genuine CISA alert does not make an unsolicited caller, browser pop-up or text message trustworthy. Start from Settings on the PC or a Microsoft support page you navigated to yourself. Microsoft says its error and warning messages do not include phone numbers and that it does not make unsolicited support calls asking for personal or financial information. Do not give a caller remote-control access, a password, a one-time code, gift cards or cryptocurrency to “install” this update. If a workplace device displays an update error, use the organization’s known help-desk channel.
The September 22 date is a government deadline, not permission to wait
CISA’s catalog is the government’s authoritative list of vulnerabilities confirmed as exploited in the wild. The September 22 due date belongs to the federal risk-based remediation process; it is not a consumer warranty period or a prediction of when an attack will happen. CISA tells every organization to use the catalog to prioritize vulnerability management, and Microsoft has already supplied the September updates. Home users should install the applicable update promptly at a time when they can save work and complete the restart. Small organizations should inventory exposed and high-value devices first, preserve normal backups and confirm deployment rather than counting a queued update as installed.
What the advisories establish—and what they do not
The official records establish active exploitation, the affected components, the privilege gain, the applicable product tables and the available September patches. They do not disclose who is exploiting the flaws, how many victims exist, whether California has a cluster or whether ransomware is involved. Installing the update closes the documented vulnerabilities; it does not investigate a computer that may already be compromised. A device showing unexplained administrator accounts, disabled security tools or other credible compromise indicators needs qualified incident-response help. This article is general safety information, not a forensic assessment of any device.
Sources
- CISA: Known Exploited Vulnerabilities catalog, including the September 8 Windows additions ↗
- CISA: machine-readable KEV feed with dates, required actions and ransomware status ↗
- Microsoft Security Update Guide: CVE-2026-81963 Windows Update Stack elevation of privilege ↗
- Microsoft Security Update Guide: CVE-2026-85880 Windows ALPC elevation of privilege ↗
- Microsoft: September 2026 security-update release notes ↗
- Microsoft: KB5122880 for Windows 11 version 23H2 ↗
- Microsoft: KB5124008 for Windows 11 versions 24H2 and 25H2 ↗
- Microsoft: KB5124012 for Windows 11 version 26H1 ↗
- Microsoft: KB5122878 for Windows 10 versions 21H2 and 22H2 ↗
- Microsoft: install and verify Windows updates ↗
- Microsoft: Windows 10 Extended Security Updates program ↗
- Microsoft: protect yourself from tech-support scams ↗
Find men's massage near you
Compare local providers privately and contact the professional you choose directly.
Search NOCTI