- Microsoft’s 8 September security updates fix exploited privilege-escalation flaws in Windows Update Stack and Advanced Local Procedure Call
- Their exploitation status gives update teams information that a patch queue based only on severity scores would miss
The fact
Microsoft released fixes on 8 September for two Windows vulnerabilities that it said had already been exploited in attacks. CVE-2026-81963 affects Windows Update Stack and allows an attacker who already has access to a vulnerable machine to gain higher privileges through improper handling of a file link. CVE-2026-85880 affects Windows Advanced Local Procedure Call, which Windows uses for communication between processes, and can allow an attacker to gain SYSTEM privileges.
Both vulnerabilities have CVSS scores of 7.8 and are rated Important by Microsoft. The reported flaws involve privilege escalation rather than initial remote access from the internet. The available reports do not identify the organisations targeted in the attacks, describe a complete intrusion chain, or establish that every Windows system is affected.
The assessment
Enterprise patching is a triage problem, not a scoreboard. Once exploitation is confirmed, teams need to move beyond a simple ranking of severity scores and establish where the vulnerable components are actually present. That means matching the advisories against their own endpoints and servers, identifying the business services those systems support and deciding where testing and deployment need to move faster.
For BTW readers, the local-access requirement narrows the risk without making it irrelevant. Patching closes the vulnerabilities on affected systems, but it cannot show whether an attacker used them before the update was installed. Security and operations teams therefore have two separate jobs: reduce the time applicable machines remain exposed and investigate suspicious systems where prior compromise is possible. Patch completion and evidence of compromise answer different questions and should not be treated as the same measure.
What to watch
Watch for Microsoft or security researchers to publish more detail on how the vulnerabilities are being exploited and which Windows configurations are affected. Within organisations, the more useful measures will be coverage of applicable systems, unresolved patch exceptions and any evidence that the flaws were used before updates were installed.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

