September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Summary

Microsoft's September Patch Tuesday release addresses 964 vulnerabilities, including two zero-day exploits that are already being actively exploited. One zero-day, CVE-2026-85880, is a heap-based buffer overflow in Windows ALPC that allows for privilege escalation. Another critical vulnerability with a CVSS score of 10.0 has been identified in SAP's ABAP Extended Passport Processing component.

IFF Assessment

FOE

The article details multiple critical vulnerabilities, including actively exploited zero-days and a CVSS 10.0 vulnerability, which represent significant threats to defenders.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: May 03, 2022. Known ransomware use: Known.

Defender Context

Defenders must prioritize patching the identified vulnerabilities, especially the two zero-days, as they are actively exploited and affect a wide range of Windows systems. The critical SAP vulnerability also requires immediate attention to prevent severe impacts on business applications.

Read Full Story →