Emergency Security Bulletin: Multiple vulnerabilities affecting Microsoft Windows Update and Windows Advanced Local Procedure Call (ALPC)

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

CVE-2026-81963 and CVE-2026-85880 are two important elevation-of-privilege vulnerabilities affecting Microsoft Windows. Both vulnerabilities are confirmed to be actively exploited and have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

CVE-2026-81963 affects the Windows Update Stack and results from improper link resolution and access control. A locally authenticated, low-privileged attacker can exploit the flaw without user interaction to elevate privileges to SYSTEM.

CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). The vulnerability combines a heap-based buffer overflow with the use of an uninitialized resource, allowing an attacker with code execution inside an AppContainer to escape the sandbox and obtain SYSTEM privileges.

Microsoft addressed both vulnerabilities as part of its September 2026 Patch Tuesday security updates.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

Windows Update Stack Elevation of Privilege Vulnerability

 

Identifier: CVE-2026-81963  
PoC or Exploitation:  Confirmed actively exploited. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog. 
CVSS Score: 7.8 (Important, CVSS v3.1)

Update / Patch:

Microsoft has released fixed builds addressing this vulnerability as part of its September 2026 Patch Tuesday release.
 
Affected versions include:
Windows 11 Version 23H2, x64-based and ARM64-based Systems
Windows 11 Version 24H2, x64-based and ARM64-based Systems
Windows 11 Version 25H2, x64-based and ARM64-based Systems
Windows 11 Version 26H1, x64-based and ARM64-based Systems
Windows Server 2025, including Server Core installation
 
Fixed versions include:
Windows 11 Version 23H2: build 10.0.22631.7582, KB5122880
Windows 11 Version 24H2: build 10.0.26100.9445, KB5124008
Windows 11 Version 25H2: build 10.0.26200.9445, KB5124008
Windows 11 Version 26H1: build 10.0.28000.2954, KB5124012
Windows Server 2025: build 10.0.26100.33438, KB5122871
 
Microsoft advisory:


Description:

CVE-2026-81963 is a local elevation-of-privilege vulnerability in the Windows Update Stack, the component responsible for installing Windows updates.
 
The vulnerability results from two weaknesses: improper link resolution before file access, known as link following, and improper access control. A locally authenticated attacker with low privileges can exploit these weaknesses to elevate to SYSTEM privileges. No user interaction is required.

 

Mitigation Recommendation:
 Apply the applicable September 2026 cumulative update for your Windows version immediately. 


Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

 

Identifier: CVE-2026-85880 
PoC or Exploitation:
 Confirmed actively exploited. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog. 
CVSS Score: 7.8 (Important, CVSS v3.1)

Update / Patch:

Microsoft has released fixed builds addressing this vulnerability as part of its September 2026 Patch Tuesday release. This vulnerability affects a broad range of Windows versions, extending back to Windows Server 2012 and Windows 10 version 1607.
 
Affected versions include:
Windows Server 2012, including Server Core installation
Windows Server 2012 R2, including Server Core installation
Windows 10 Version 1607, x64-based and 32-bit Systems
Windows Server 2016, including Server Core installation
Windows 10 Version 1809, x64-based and 32-bit Systems
Windows Server 2019, including Server Core installation
Windows 10 Version 21H2, x64-based, ARM64-based, and 32-bit Systems
Windows 10 Version 22H2, x64-based, ARM64-based, and 32-bit Systems
Windows Server 2022, including Server Core installation
 
Fixed versions include:
Windows Server 2012: build 6.2.9200.26349, KB5123065
Windows Server 2012 R2: build 6.3.9600.23397, KB5123066
Windows 10 Version 1607 and Windows Server 2016: build 10.0.14393.9512, KB5123099
Windows 10 Version 1809 and Windows Server 2019: build 10.0.17763.9245, KB5122876
Windows 10 Version 21H2: build 10.0.19044.7725, KB5122878
Windows 10 Version 22H2: build 10.0.19045.7725, KB5122878
Windows Server 2022: build 10.0.20348.5622, KB5122882
 
Microsoft advisory:
 


Description:

CVE-2026-85880 is a local elevation-of-privilege vulnerability in Windows Advanced Local Procedure Call, the internal messaging subsystem used for communication between Windows processes.
 
The vulnerability combines a heap-based buffer overflow with an uninitialized resource. A low-privileged attacker who can execute code inside an AppContainer can exploit this flaw locally to escape the sandbox and obtain SYSTEM privileges.
 
An attacker who has achieved code execution inside such a sandbox can use this flaw to break out of that isolation entirely.

 

Mitigation Recommendation:

Apply the applicable September 2026 security update for your Windows version immediately.