September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows
Summary
Microsoft's September Patch Tuesday release addresses 964 vulnerabilities, including two zero-day exploits that are already being actively exploited. One zero-day, CVE-2026-85880, is a heap-based buffer overflow in Windows ALPC that allows for privilege escalation. Another critical vulnerability with a CVSS score of 10.0 has been identified in SAP's ABAP Extended Passport Processing component.
IFF Assessment
The article details multiple critical vulnerabilities, including actively exploited zero-days and a CVSS 10.0 vulnerability, which represent significant threats to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: May 03, 2022. Known ransomware use: Known.
Defender Context
Defenders must prioritize patching the identified vulnerabilities, especially the two zero-days, as they are actively exploited and affect a wide range of Windows systems. The critical SAP vulnerability also requires immediate attention to prevent severe impacts on business applications.