Update / Patch:
Microsoft has released fixed builds addressing this vulnerability as part of its September 2026 Patch Tuesday release.
Affected versions include:
Windows 11 Version 23H2, x64-based and ARM64-based Systems
Windows 11 Version 24H2, x64-based and ARM64-based Systems
Windows 11 Version 25H2, x64-based and ARM64-based Systems
Windows 11 Version 26H1, x64-based and ARM64-based Systems
Windows Server 2025, including Server Core installation
Fixed versions include:
Windows 11 Version 23H2: build 10.0.22631.7582, KB5122880
Windows 11 Version 24H2: build 10.0.26100.9445, KB5124008
Windows 11 Version 25H2: build 10.0.26200.9445, KB5124008
Windows 11 Version 26H1: build 10.0.28000.2954, KB5124012
Windows Server 2025: build 10.0.26100.33438, KB5122871
Microsoft advisory:
Description:
CVE-2026-81963 is a local elevation-of-privilege vulnerability in the Windows Update Stack, the component responsible for installing Windows updates.
The vulnerability results from two weaknesses: improper link resolution before file access, known as link following, and improper access control. A locally authenticated attacker with low privileges can exploit these weaknesses to elevate to SYSTEM privileges. No user interaction is required.
Mitigation Recommendation:
Apply the applicable September 2026 cumulative update for your Windows version immediately.
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Identifier: CVE-2026-85880
PoC or Exploitation:
Confirmed actively exploited. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
CVSS Score: 7.8 (Important, CVSS v3.1)
Update / Patch:
Microsoft has released fixed builds addressing this vulnerability as part of its September 2026 Patch Tuesday release. This vulnerability affects a broad range of Windows versions, extending back to Windows Server 2012 and Windows 10 version 1607.
Affected versions include:
Windows Server 2012, including Server Core installation
Windows Server 2012 R2, including Server Core installation
Windows 10 Version 1607, x64-based and 32-bit Systems
Windows Server 2016, including Server Core installation
Windows 10 Version 1809, x64-based and 32-bit Systems
Windows Server 2019, including Server Core installation
Windows 10 Version 21H2, x64-based, ARM64-based, and 32-bit Systems
Windows 10 Version 22H2, x64-based, ARM64-based, and 32-bit Systems
Windows Server 2022, including Server Core installation
Fixed versions include:
Windows Server 2012: build 6.2.9200.26349, KB5123065
Windows Server 2012 R2: build 6.3.9600.23397, KB5123066
Windows 10 Version 1607 and Windows Server 2016: build 10.0.14393.9512, KB5123099
Windows 10 Version 1809 and Windows Server 2019: build 10.0.17763.9245, KB5122876
Windows 10 Version 21H2: build 10.0.19044.7725, KB5122878
Windows 10 Version 22H2: build 10.0.19045.7725, KB5122878
Windows Server 2022: build 10.0.20348.5622, KB5122882
Microsoft advisory:
Description:
CVE-2026-85880 is a local elevation-of-privilege vulnerability in Windows Advanced Local Procedure Call, the internal messaging subsystem used for communication between Windows processes.
The vulnerability combines a heap-based buffer overflow with an uninitialized resource. A low-privileged attacker who can execute code inside an AppContainer can exploit this flaw locally to escape the sandbox and obtain SYSTEM privileges.
An attacker who has achieved code execution inside such a sandbox can use this flaw to break out of that isolation entirely.
Mitigation Recommendation:
Apply the applicable September 2026 security update for your Windows version immediately.