Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Addresses 974 Vulnerabilities, Including Two Zero-Days

Microsoft Addresses 974 Vulnerabilities, Including Two Zero-Days

Posted on September 8, 2026 By CWS

On Tuesday, Microsoft released a substantial security update, addressing 974 Common Vulnerabilities and Exposures (CVEs) across its suite of products. This includes the resolution of two zero-day vulnerabilities actively exploited in the wild.

Zero-Day Vulnerabilities Addressed

The first zero-day, identified as CVE-2026-85880, involves a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC). This flaw could enable a local attacker to gain elevated System privileges. Exploitation requires no additional user interaction, posing a significant risk to affected systems.

Microsoft’s advisory details that attackers can execute code in a low-privilege AppContainer to escape the sandbox and elevate privileges. This marks the first time since April 2023 that an ALPC flaw has been patched, with the last zero-day fix in this component occurring in January 2023, as noted by Satnam Narang, a senior staff research engineer at Tenable.

Details on the Update Stack Weakness

CVE-2026-81963, the second zero-day vulnerability, pertains to an improper link resolution in the Windows Update Stack. This component is critical for Windows update installations, and the flaw allows local privilege escalation to System level.

Narang highlights that this is the first zero-day identified in the Update Stack over the past five years, despite multiple flaws being resolved in the component during that time.

Comprehensive Patch Tuesday Updates

This month’s Patch Tuesday also includes fixes for 723 Windows vulnerabilities and 222 issues in the Office suite, with 111 specific to Office 2016. Additional security patches target SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9).

Microsoft released critical Servicing Stack Updates (SSU) for Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016. Key vulnerabilities such as CVE-2026-55007 (RCE in Exchange Server) and CVE-2026-80097 (EoP in Authenticator) were also addressed.

Impact and Future Outlook

Dustin Childs from ZDI notes that 20 of the newly resolved vulnerabilities could be considered ‘wormable,’ meaning they can enable remote code execution without authentication. Despite the increasing number of patches, Satnam Narang emphasizes that many vulnerabilities do not significantly impact most organizations.

AI-assisted vulnerability discovery is contributing to a higher number of identified issues, yet organizations need to focus on vulnerabilities that are actually exploitable, prioritizing remediation based on risk context. Tyler Reguly from Fortra suggests that the trend of frequent updates highlights a proactive approach by vendors to minimize the attack surface.

As the industry continues to address long-standing vulnerabilities, organizations are encouraged to maintain prioritization in their patch management strategies while anticipating a return to more typical update frequencies in the future.

Security Week News Tags:ALPC, Cybersecurity, Exchange Server, Microsoft, Office Suite, Patch Tuesday, security updates, Update Stack, Windows, zero-day vulnerabilities

Post navigation

Previous Post: FortiGate Firewalls Targeted by Node.js Malware Exploit
Next Post: Phishing Fuels 80% of US Cyber Attacks: SOC Detection Tips

Related Posts

40,000 Servers at Risk Due to cPanel Exploit 40,000 Servers at Risk Due to cPanel Exploit Security Week News
Flaws in Major Automaker’s Dealership Systems Allowed Car Hacking, Personal Data Theft Flaws in Major Automaker’s Dealership Systems Allowed Car Hacking, Personal Data Theft Security Week News
Virtual Event Today: Cyber AI & Automation Summit Virtual Event Today: Cyber AI & Automation Summit Security Week News
South Korea Seeks to Arrest Dozens of Online Scam Suspects Repatriated From Cambodia South Korea Seeks to Arrest Dozens of Online Scam Suspects Repatriated From Cambodia Security Week News
From Tech Podcasts to Policy: Trump’s New AI Plan Leans Heavily on Silicon Valley Industry Ideas From Tech Podcasts to Policy: Trump’s New AI Plan Leans Heavily on Silicon Valley Industry Ideas Security Week News
AI Exploitation: Emerging Threats in Cybersecurity AI Exploitation: Emerging Threats in Cybersecurity Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Releases September 2026 Security Updates
  • Phishing Fuels 80% of US Cyber Attacks: SOC Detection Tips
  • Microsoft Addresses 974 Vulnerabilities, Including Two Zero-Days
  • FortiGate Firewalls Targeted by Node.js Malware Exploit
  • Adobe Issues Critical Security Updates for Over 170 Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Releases September 2026 Security Updates
  • Phishing Fuels 80% of US Cyber Attacks: SOC Detection Tips
  • Microsoft Addresses 974 Vulnerabilities, Including Two Zero-Days
  • FortiGate Firewalls Targeted by Node.js Malware Exploit
  • Adobe Issues Critical Security Updates for Over 170 Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark