Microsoft has released the September 2026 Security Updates and marked two Windows vulnerabilities in MSRC as already exploited. For small and midsized businesses, this is more than a routine patch notice: both issues are local elevation-of-privilege vulnerabilities, both can allow SYSTEM privileges if exploited successfully, and Microsoft marks both with “Customer Action Required: Yes”.
What Microsoft reported on 8 September
The MSRC overview lists 974 Microsoft CVEs for the September release. Microsoft highlights two Windows issues as notable because they carry the status “Exploitation Detected”: CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC), and CVE-2026-81963 in the Windows Update Stack. According to MSRC, neither issue is publicly disclosed, but both are already being exploited.
That makes the risk decision clearer than with many routine updates. This is not only about a theoretical attack surface, but about vulnerabilities for which Microsoft has detected exploitation. Organizations running Windows clients or Windows servers should therefore avoid pushing the September updates into a long maintenance backlog.
Which systems may be affected
Microsoft maps CVE-2026-85880 to several Windows 10, Windows 11 and Windows Server versions. CVE-2026-81963 affects, according to MSRC, newer Windows 11 and Windows Server generations among others. Actual exposure depends on version, servicing state and installed components; the authoritative check remains Windows Update, Microsoft Update Catalog, Intune, WSUS or the patch-management platform you use.
- CVE-2026-85880: Windows ALPC, elevation of privilege, CVSS base score 7.8, exploitation detected.
- CVE-2026-81963: Windows Update Stack, elevation of privilege, CVSS base score 7.8, exploitation detected.
- For both CVEs, Microsoft states that a successful local exploit could give an attacker SYSTEM privileges.
Timing: do not defer the updates
Microsoft does not name a separate later deadline for these two CVEs; the action point is the September Patch Tuesday itself. Fixes are available through the normal update channels. For CVE-2026-85880, MSRC references KB5122876, KB5122882 and KB5122878 among others. For CVE-2026-81963, MSRC references KB5122871, KB5124008 and KB5122880 among others.
In practice, standard client devices can often move immediately through the normal update ring, while critical servers need a short but firmly scheduled maintenance window. If a pilot ring shows no business-impacting issue, rollout to production devices should follow promptly. A vague “we patch later this month” note is not enough when exploitation is already detected.
Why elevation of privilege matters for SMBs
Local elevation of privilege is sometimes underestimated because an attacker first needs code execution on the device. In real attack chains, however, that is often the second step after phishing, compromised credentials or a malicious download. Turning a restricted user context into SYSTEM can put protective services, local data, endpoint controls and lateral movement paths at greater risk.
For organizations with 10 to 250 users, the practical issue is that client and server operations usually compete for the same limited IT capacity. Patch windows, home-office devices, individual line-of-business applications and exceptions all need attention. A Microsoft Security Assessment helps make update processes, exceptions and critical devices visible in a structured way, without turning the topic into license advice.
What organizations should check now
The next steps are deliberately operational. The goal is not to hand-assess every CVE, but to secure update status and visibility for the affected Windows estate.
- Check in Intune, WSUS or your patch-management platform whether the September 2026 updates are offered and installed on Windows clients and servers.
- Use Microsoft Defender or Defender for Endpoint to confirm that devices missing security updates are visible as risk.
- Give servers with business applications a short maintenance window instead of postponing updates broadly until the end of the month.
- Review local administrator rights, old service accounts and remote access paths, because elevation-of-privilege bugs are especially powerful there.
- Document every exception with an owner and expiry date; open exceptions belong in regular Microsoft 365 consulting or a security review.
Official Microsoft sources
- MSRC: September 2026 Security Updates
- MSRC: CVE-2026-85880 Windows ALPC Elevation of Privilege Vulnerability
- MSRC: CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability
If you want to know which devices are still unpatched and which exceptions should be closed first, we can review that as part of a Microsoft Security Assessment – get in touch.
What does this mean for your environment?
Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.
