11 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-81963 and CVE-2026-85880 are two important elevation-of-privilege vulnerabilities affecting Microsoft Windows. Both vulnerabilities are confirmed to be actively exploited and have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
CVE-2026-81963 affects the Windows Update Stack and results from improper link resolution and access control. A locally authenticated, low-privileged attacker can exploit the flaw without user interaction to elevate privileges to SYSTEM.
CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). The vulnerability combines a heap-based buffer overflow with the use of an uninitialized resource, allowing an attacker with code execution inside an AppContainer to escape the sandbox and obtain SYSTEM privileges.
Microsoft addressed both vulnerabilities as part of its September 2026 Patch Tuesday security updates.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Windows Update Stack Elevation of Privilege Vulnerability
Identifier: CVE-2026-81963
PoC or Exploitation: Confirmed actively exploited. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
CVSS Score: 7.8 (Important, CVSS v3.1)
Update / Patch:
Description:
Mitigation Recommendation:
Apply the applicable September 2026 cumulative update for your Windows version immediately.
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Identifier: CVE-2026-85880
PoC or Exploitation:
Confirmed actively exploited. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
CVSS Score: 7.8 (Important, CVSS v3.1)
Update / Patch:
Description:
Mitigation Recommendation: