The Fix Arrives Through The Thing That Broke
Microsoft's September 8 Patch Tuesday fixed CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack caused by improper link resolution, the same component that delivers every security patch to a Windows machine. A locally authenticated attacker who already has low-level access can exploit it without any user interaction to gain full SYSTEM privileges. CISA confirmed active exploitation and added the flaw to its Known Exploited Vulnerabilities catalog on September 8, with a remediation deadline of September 22 under Binding Operational Directive 26-04.
Seven Windows Update Stack elevation-of-privilege bugs have been patched on Patch Tuesday since 2022. CVE-2026-81963 is the first of those seven to have been exploited in the wild as a zero-day, meaning attackers were already using it before Microsoft's fix existed, not after. Microsoft rates it 7.8 out of 10, Important rather than Critical, the same tier assigned to routine local privilege-escalation bugs that never see real-world exploitation.
You Cannot Sandbox The Channel That Fixes You
Most exploited vulnerabilities give a security team a mitigation to reach for while a patch is tested: disable a feature, block a port, isolate a service. The Windows Update Stack does not allow that option. Disabling or restricting the component that was attacked also disables the mechanism an organization needs to receive this exact fix, and every fix after it. A team that wanted to wait and test this patch on a slower ring, the normal practice for a security update with unknown side effects, spent that waiting period running the vulnerable component with no isolation available at all.
Microsoft's own Windows Advanced Local Procedure Call component, ALPC, carried a second actively exploited zero-day in the same release, CVE-2026-85880, also rated 7.8 and also added to CISA's catalog with the same September 22 deadline. Sixteen ALPC vulnerabilities have been patched since 2022, but this is the first one exploited in the wild to appear in a Patch Tuesday release in more than three years, since April 2023. Two structurally different components, both sitting close to the machine's own trust boundary, both weaponized before Microsoft's fix reached anyone.
What This Means For A Patch Cycle
A vendor severity label of Important typically lets a patch queue behind higher-priority work. CISA's inclusion of both flaws in its Known Exploited Vulnerabilities catalog exists precisely to override that instinct: KEV listings are built from confirmed exploitation, not from a vendor's own triage, and Binding Operational Directive 26-04 asks federal agencies, and by extension any organization tracking CISA guidance for its own patch-priority triage, to treat a KEV entry as urgent regardless of the CVSS tier attached to it.
For organizations running staggered rollout rings, September's Patch Tuesday is the case for shortening the gap between release and full deployment specifically for anything touching the update pipeline itself, because a vulnerability inside the mechanism that eventually delivers your fix is not one you can afford to leave running unpatched while you evaluate it on a test ring. The practical lesson is the same one CISA's KEV catalog exists to teach: pull the exploitation-confirmed list directly into patch-priority decisions, rather than trusting a vendor's own severity tier to tell you what can wait.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Half of Chrome's Six 2026 Zero-Days Hit the Same Engine | Chrome's Next Zero-Day Files to Brussels



