Two Windows Flaws Were Already Under Attack When Microsoft’s 974-CVE Patch Tuesday Landed
Microsoft’s September security release addresses 974 Microsoft CVEs. Only two were reported as already being exploited when the update arrived.
That small number should dominate the first deployment decision.
CVE-2026-85880 affects Windows Advanced Local Procedure Call and can allow code in a low-privilege AppContainer to escape that boundary and gain SYSTEM privileges. CVE-2026-81963 affects the Windows Update Stack and can allow a local attacker to follow links improperly and elevate to SYSTEM.
Neither vulnerability provides the initial foothold. Both can make that foothold dramatically more useful.
BlackTree’s complete September Patch Tuesday business guide places these exploited paths alongside Outlook, exposed Windows services, restart planning and deployment verification.
Two flaws, two parts of the Windows estate
The vulnerabilities do not map neatly to the same product generations.
BlackTree’s current applicability data maps CVE-2026-85880 to Windows 10 versions 21H2, 22H2, 1607 and 1809, and Windows Server 2012, 2012 R2, 2016, 2019 and 2022. The corresponding update records include:
- KB5122878 for applicable Windows 10 21H2 and 22H2 systems
- KB5123065 for Windows Server 2012
- KB5123066 for Windows Server 2012 R2
- KB5123099 for Windows 10 1607 and Windows Server 2016
- KB5122876 for Windows 10 1809 and Windows Server 2019
- KB5122882 for Windows Server 2022
CVE-2026-81963 maps to Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2025. The corresponding records include:
- KB5122880 for Windows 11 23H2
- KB5124008 for Windows 11 24H2 and 25H2
- KB5124012 for Windows 11 26H1
- KB5122871 for Windows Server 2025
This split creates an easy management failure. A team concentrating on the newest Windows estate can miss the AppContainer escape on older servers and Extended Security Update devices. A team focused on legacy exposure can miss the Update Stack flaw on current Windows 11 endpoints and Server 2025.
The correct question is not “Which version is vulnerable?” It is “Which of our versions is vulnerable to which path, and which package closes it?”
Why AppContainer escape matters
AppContainer is designed to limit what an application process can reach. Browsers, document-handling components and other applications can use sandboxed contexts so that hostile code has fewer privileges even if it begins running.
Microsoft says CVE-2026-85880 can let code already executing in a low-privilege AppContainer escape the sandbox and elevate to SYSTEM. The vulnerability is associated with a heap-based buffer overflow and use of an uninitialised resource in Windows ALPC.
That description matters because security boundaries work in layers. A malicious file or compromised process may first obtain only constrained execution. An elevation vulnerability can remove that constraint. The result can be access to protected data, credentials and system configuration, as well as the ability to interfere with endpoint controls or establish more durable persistence.
Microsoft rates the flaw Important with a CVSS base score of 7.8. The exploitation evidence is more operationally important than the absence of a Critical label.
Why the Update Stack flaw matters
The Windows Update Stack is supposed to help devices receive and apply trusted changes. CVE-2026-81963 is an elevation-of-privilege vulnerability involving improper link resolution before file access and an access-control weakness.
Microsoft says a low-privilege local attacker can exploit the flaw without user interaction and gain SYSTEM privileges. It also carries a CVSS base score of 7.8 and an Important severity rating.
The component’s name should not be used to invent a supply-chain story. Microsoft has not said that attackers compromised Windows Update, poisoned update delivery or remotely pushed malicious packages. The confirmed fact is narrower: attackers have exploited a local privilege-escalation weakness in the Windows Update Stack.
Precision is not a reason to minimise the risk. SYSTEM is still the destination.
What “exploitation detected” tells us
Microsoft’s advisories answer one critical question: exploitation has occurred.
They do not answer several others:
- who carried it out
- how attackers obtained their initial local access
- which organisations or sectors were affected
- how many devices were compromised
- whether the two vulnerabilities were used together or in separate campaigns
- whether public proof-of-concept code exists
- which file, process or network indicators defenders should search for
Those gaps should shape the response. Security teams should not wait for a named campaign before patching, and communications teams should not fill the gaps with speculation. The honest position is that the flaws are valuable enough to have been used and the public advisories do not reveal the surrounding operation.
The business response should begin with applicability
1. Split the inventory into exact operating-system releases
Do not use a single “Windows” collection. Create separate groups for the older Windows and Server versions affected by CVE-2026-85880, and for the current Windows 11 and Server 2025 versions affected by CVE-2026-81963.
Include powered-off devices, golden images, virtual-desktop pools, recovery environments and machines that have stopped reporting to central management. Silence is not evidence of safety.
2. Find the endpoints where escalation would be most valuable
Move the following towards the front of the deployment ring:
- privileged workstations and administrator jump hosts
- shared or multi-user systems
- endpoints exposed to untrusted web and email content
- servers holding credentials, management tools or sensitive data
- remote systems with weak visibility or delayed maintenance
- devices where a compromise would provide access to other trust zones
The exploit requires local access. Those systems are where limited access would have the greatest consequence.
3. Test both product generations
A successful Windows 11 pilot says nothing about Server 2012 or Windows 10 ESU behaviour. Include at least one representative system for every affected update family in the emergency ring.
Test the workload after the restart. For servers, that means the hosted service, authentication, monitoring, backup and dependent connections. For endpoints, it means the applications people need to work.
4. Schedule the restart as part of the fix
BlackTree’s eleven accelerated September records all require a restart. Microsoft also says September is a baseline month for relevant hotpatch-enrolled devices, so organisations should not assume their usual restart-free path applies.
Track four states separately: not offered, downloaded, installed and restarted. Only the last state demonstrates that the new code is active.
5. Hunt without pretending the hunt can prove absence
Microsoft has not published campaign-specific indicators with these advisories. Defenders can still look for suspicious local privilege escalation, unexpected SYSTEM processes, security-control interference, unusual child processes from sandboxed applications and persistence created after low-privilege execution.
Those are behavioural hypotheses, not official indicators for these vulnerabilities. A clean hunt does not justify delaying the update, and installing the update does not establish that a previously exposed device was never compromised.
Where credible suspicious activity exists, preserve evidence and investigate before routine clean-up destroys it.
The Wednesday-morning questions
Leaders should ask for more than an overall compliance percentage:
- How many devices are applicable to each flaw?
- How many have both installed the correct KB and restarted?
- Which high-value systems remain exposed?
- Which unsupported, ESU or unmanaged devices sit outside normal deployment?
- Which failures are technical, and which are waiting for a business owner?
- Did monitoring reveal evidence that requires incident response rather than patch management?
A 99 per cent result can still leave the most valuable server unpatched. A lower percentage may be less dangerous if the remainder is powered off, isolated and awaiting controlled maintenance. The asset list decides the meaning of the number.
A privilege-escalation flaw is rarely the beginning of the story
The most dangerous temptation with both vulnerabilities is to dismiss them because they need local access. In real intrusions, attackers chain capabilities. One weakness gets code running. Another breaks a security boundary. A third exposes credentials or creates movement.
The September evidence does not tell us what the full chains looked like. It does tell us that attackers have already found value in two routes to SYSTEM across different parts of the Windows estate.
That is enough to act.
Sources and live records
- BlackTree live record for the Windows ALPC vulnerability
- Microsoft advisory for the Windows ALPC vulnerability
- BlackTree live record for the Windows Update Stack vulnerability
- Microsoft advisory for the Windows Update Stack vulnerability
- Microsoft September 2026 Security Updates release notes
- BlackTree September 2026 Patch Intelligence cycle
- Microsoft September 2026 hotpatch baseline notice
Editorial note: Applicability and package data were checked on 8 September 2026. Recheck the linked live records and Microsoft’s known-issue information before deployment.


