Microsoft has released its monthly batch of security updates to fix over 900 flaws across its software products, including two vulnerabilities in Windows that are being exploited in the wild.
The first zero-day, tracked as CVE-2026-81963, is a privilege escalation issue in Windows update stack. It can be used by a local user to create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the SYSTEM user account.
The second exploited vulnerability is CVE-2026-85880, a heap-based overflow issue in Windows ALPCA that also could allow a local user to execute arbitrary code with SYSTEM privileges.
The Windows maker didn’t share any additional details about attacks exploiting the zero-day flaws.
Microsoft’s September 2026 Patch Tuesday also addresses a slew of high-risk and medium-risk vulnerabilities affecting Microsoft Visual Studio, Microsoft Office Graphics Component, MS SQL Server, MS Office, Visual Studio Code, MS Exchange Server, MS SharePoint Server, MS .NET Framework, MS Authenticator, and other products.
In the meantime, Google has patched over 200 security flaws in Chrome, including an actively exploited zero-day.
Google describes the zero-day flaw (CVE-2026-87491) as an out of bounds write in the V8 engine. As always, the company withheld further details about the issue until a majority of users update their browsers.