What happened and why it matters
CISA confirmed that attackers are already weaponising two of the 973 bugs Microsoft released on September 2026 Patch Tuesday. Those two CVEs – CVE‑2026‑81963 and CVE‑2026‑85880 – are the only ones publicly flagged as active threats.
Microsoft’s September bulletin is the largest ever, eclipsing the July record of more than 600 fixes. The cumulative count of vulnerabilities disclosed by the company in 2026 now tops 2,600.
Technical specifics
CVE‑2026‑81963 lives in the component that installs Windows updates. Tenable notes that compromising this part of the update chain could give an attacker a foothold on a system that thinks it is merely updating.
CVE‑2026‑85880 targets a Windows messaging subsystem. Tenable describes it as a flaw that could be abused to execute code within the context of the messaging service.
Who needs to act
All federal agencies have a hard deadline of 22 September 2026 to apply the patches for these two CVEs. Any organization that runs Windows – especially those that rely on the update or messaging components – should treat the advisory as urgent.
Defensive steps
- Deploy the September 2026 security updates to every Windows endpoint before the 22 September deadline.
- Verify that the update component and messaging service are running the patched versions; use inventory tools to confirm.
- Monitor network traffic for unusual activity around Windows Update services and messaging ports.
- Consider temporary mitigation such as disabling automatic update installation on critical systems until the patch is applied.
- Stay tuned to CISA alerts for any additional guidance or indicators of compromise related to these CVEs.
