Microsoft’s Record Patch Day Adds Two Exploited Windows Flaws

Microsoft patched about 974 CVEs on September Patch Tuesday, including two Windows local privilege-escalation zero-days that were already being exploited: CVE-2026-81963 and CVE-2026-85880. Adobe also shipped multiple bulletins, including an exploited Commerce bug that is already on a federal remediation clock. One Windows flaw hits the update stack’s link-following logic; the other lets code running in a low-privilege AppContainer break out and reach SYSTEM. Adobe’s Commerce issue is a template-engine injection being used in the wild, so this month’s cleanup is not just large, it mixes high-volume triage with active attack paths in different products. For organizations that rely on staged testing, the pressure point is the patch queue itself: local footholds on Windows can be turned into full control, while Commerce sites exposed to the internet carry a separate deadline-driven risk. The reporting does not settle how broad the exploitation is, but it does make clear that the busiest part of September is also the part most likely to be operationally painful.

Part of the PlainSec briefing for 2026-09-08

Editions

CVEs

Sources