Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
Cybersecurity

Record Windows update round with two exploited flaws

9 September 2026·Trung Nguyêñ Dúc, Head of Technology
Record Windows update round with two exploited flaws

On Tuesday 8 September, Microsoft shipped the largest patch round in the company's history: depending on how you count, more than 960 vulnerabilities at once. That figure is mainly impressive on paper. What actually matters to your organisation are the two flaws that attackers were already using on the day the fixes appeared.

Two flaws already under attack

The first, CVE-2026-81963, sits in the Windows Update stack and abuses the way Windows resolves file references. The second, CVE-2026-85880, is a memory flaw in Windows ALPC, the mechanism processes use to talk to one another. Both deliver the same outcome: an attacker gains SYSTEM rights, the highest level that exists on a Windows machine.

Neither works remotely. An attacker must already be able to run something on the machine before either flaw becomes useful. That sounds more reassuring than it is, because it describes exactly the situation after one successful phishing email or one employee opening the wrong file. Without these flaws, the attacker holds the rights of that single user. With them, the attacker holds the rights of the machine, and a starting point for moving through the rest of the network. That difference decides whether you are dealing with an unpleasant incident or a weekend of crisis work.

A record number does not mean everything is equally urgent

Around a hundred of the patched vulnerabilities are marked critical, and roughly twenty can spread without any user action. At the same time, only a small part of that list applies to most organisations at all: you do not run every Microsoft product, and very little of what you do run is reachable from the internet.

That is the trap in a round like this one. The number makes an impression, after which the conclusion becomes either "we patch everything tonight" or "this is beyond us, we will wait". Neither is a plan. The question is which of these flaws touch what you genuinely run, and which of those are reachable by someone with bad intentions.

What to arrange this week

  • Have it confirmed that the September update reached every workstation, not only the machines that happened to be switched on.
  • Plan the server side in phases and with a way back. Microsoft also confirmed side effects from earlier updates on Windows Server 2016 and 2025 this month.
  • Check whether any Windows 10 machines are still in use and whether they are covered by paid security updates. If not, they simply do not receive these patches.
  • Map which devices fall outside your management: personal laptops, an older machine beside a production line, a PC at a secondary site. Those are where a flaw like this survives for years.

How we handle this for our clients

In organisations whose IT we manage, there is no monthly manual debate about what should be included. Workstations follow a fixed rhythm with controlled rollout, servers go in phases and with a way back, and exceptional cases such as these two flaws are brought forward. The dull part matters just as much: keeping track of which devices exist and which updates they actually received. A patch policy that is correct on paper but misses three machines does not protect those three machines.

Sources: BleepingComputer and SecurityWeek on the September round.

Not sure whether these two flaws have already been closed in your environment, or how many machines sit outside your update rhythm? Arrange a conversation with one of our engineers and we will go through it with you.

Sources

  1. Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days — BleepingComputer (2026-09-08)
  2. Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days — SecurityWeek (2026-09-08)
  3. August updates trigger 0xc0000409 errors on Windows Server 2016 — BleepingComputer (2026-09-08)

Read also

Attackers take over routers through open admin access

Chrome flaw under active attack: restart your browser

When your IT supplier is breached instead of you

Ready to run worry-free?

Book a no-obligation introduction. We map your IT and security and show where the difference lies.

Book a call