What Changed
Microsoft’s September 2026 Patch Tuesday—972 CVEs, a new monthly record—included two confirmed in-the-wild zero-days. One is the ALPC elevation of privilege BlueMoon already chains (CVE-2026-85880). The other is CVE-2026-81963, a link-following and improper access control bug in the Windows Update Stack. An authenticated local attacker with low privileges abuses how the update stack resolves links and lands at SYSTEM. No user interaction is required. CISA added the CVE to KEV on September 8.
Affected trains include Windows 11 versions 23H2, 24H2, 25H2, and 26H1, plus Windows Server 2025 (including Server Core). CrowdStrike and national CERTs flag it as the Update Stack elevation of privilege to prioritize first—not because a 7.8 outscores Netlogon 9.8 remote code execution bugs in the same release, but because Exploitation Detected outranks the base score for triage order.
Why This Matters Operationally
Local elevation-of-privilege bugs are easy to underrate until you remember the modern intrusion script: phishing or a browser exploit for a foothold, then escalate. The Update Stack is present on essentially every supported Windows endpoint and server, runs elevated during patch operations, and is the same machinery you would use to push the fix. An attacker who owns that path owns the eviction process. Commodity post-exploitation kits historically love reliable user-to-SYSTEM primitives; an Update Stack link-follower is exactly that class.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Pair this with BlueMoon’s browser-to-LPE narrative and September’s broader critical remote code execution list—Netlogon, DNS, DHCP, MSMQ, SSTP, Hyper-V escapes—and the month is not “one zero-day.” It is a reminder that foothold conversion and domain-controller services both need same-week attention.
What Defenders Should Verify First
- Deploy September 2026 cumulative updates that remediate CVE-2026-81963 across Windows 11 and Server 2025 fleets. Verify compliance; do not assume WSUS or Intune success from a dashboard green light alone.
- Prioritize endpoints that already showed suspicious local code execution, browser exploit indicators, or BlueMoon-adjacent process trees—this elevation of privilege is the second stage those hosts need closed.
- Hunt unexpected SYSTEM processes spawned from standard-user sessions, especially activity touching update directories or services outside maintenance windows.
- Do not let the CVSS 7.8 bury the ticket under 9.8 Netlogon and DNS items. Run parallel workstreams: domain-controller critical RCEs and workstation Update Stack elevation of privilege.
- Re-check ESU and lingering Windows 10 populations separately for the sibling ALPC zero-day (CVE-2026-85880) even where CVE-2026-81963’s product list differs.
Source Context
- CrowdStrike: September 2026 Patch Tuesday analysis
- CISA KEV additions September 8, 2026
- NVD: CVE-2026-81963
- Canadian Centre for Cyber Security: AV26-896
Ship the September cumulatives, prove they landed, and treat “local only” as “stage two of every foothold you already fear.”
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.