Rapid7 highlights two exploited flaws in September Patch Tuesday

0

Microsoft’s September 2026 Patch Tuesday includes 999 vulnerabilities across Microsoft and non-Microsoft products, according to commentary from Rapid7 lead software engineer Adam Barnett.

Barnett said Microsoft published 974 vulnerabilities affecting its own products, including 723 in Windows. He added Microsoft also issued fixes for 25 non-Microsoft CVEs, bringing the total to 999, which he described as the highest number of CVEs Microsoft has published in a single day.

Rapid7’s analysis said Microsoft is aware of exploitation in the wild for two vulnerabilities addressed in this release: CVE-2026-85880 and CVE-2026-81963.

According to Barnett, CVE-2026-85880 is a Windows elevation of privilege issue in the Advanced Local Procedure Call (ALPC) mechanism, where successful exploitation could grant SYSTEM privileges via a buffer overflow and out-of-bounds write. He noted Windows Server 2025 and Windows 11 do not receive patches for CVE-2026-85880, which he suggested may reflect Microsoft’s ongoing work to improve memory safety through rewriting some kernel components in Rust.

Barnett also highlighted CVE-2026-81963, an elevation of privilege vulnerability in the Windows Update Stack that he said can lead to SYSTEM privileges through improper link resolution. While he noted its CVSS v3 base score is 7.8, Barnett argued attackers may still favour multi-stage approaches that combine initial local access with privilege escalation.

Rapid7 also raised questions about browser advisory coverage for CVE-2026-85046, a zero-day vulnerability in Google’s V8 JavaScript engine that Google Chrome patched on 3 September 2026. Barnett said Microsoft Edge’s stable channel received a related patch on 2 September 2026, citing Microsoft Edge release notes, but added Microsoft had not published a Microsoft Security Response Center advisory for CVE-2026-85046 at the time of the commentary. He warned that organisations relying on advisories to track exposures could miss the issue, and said it was not yet clear whether 11 other vulnerabilities patched by Chrome alongside CVE-2026-85046 were also addressed in Edge.

Looking ahead, Barnett pointed to Microsoft product lifecycle changes due on 14 October 2026, including Windows 11 24H2 Home & Pro reaching end of servicing and Windows Server 2022 moving to extended support. He also said Windows Server 2012 and 2012 R2 are due to exit their third and final year of paid Extended Security Updates, while Office 2021 moves out of support with no ESU available for the Long-Term Servicing Channel. Barnett added Exchange Server 2016 and 2019 are also expected to move out of support in October after two six-month reprieves.

Share.