[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVTvZ31jO2E1Usp18AGYTdJB2HMVDp6wyLIyHtO5m9_Q":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"b388d4b7-e1ce-4473-9c33-d050f4df5df7","record-974-microsoft-vulnerabilities-patched-including-two-actively-exploited-zero-days","e4fb5699-48f4-434c-890e-9639458a2c45","Record 974 Microsoft Vulnerabilities Patched, Including Two Actively Exploited Zero-Days","Microsoft's September Patch Tuesday addressed a staggering 974 vulnerabilities, setting a new record and highlighting the growing complexity of managing software security at scale. Two zero-day vulnerabilities — a heap buffer overflow in Windows ALPC (CVE-2026-85880) and an update stack flaw (CVE-2026-81963) — were actively exploited in the wild before patches were available, meaning attackers had a window to escalate privileges on unpatched systems. Additionally, 20 potentially wormable vulnerabilities were included, raising the risk of rapid lateral movement across networks if left unpatched. This underscores that even well-resourced vendors face an ever-expanding attack surface, and organizations that delay patching expose themselves to both opportunistic and targeted attacks.","**Immediate Actions:**\n- Apply Microsoft's September Patch Tuesday updates immediately, prioritizing CVE-2026-85880 and CVE-2026-81963 on all Windows systems.\n- Run an authenticated vulnerability scan across your environment to identify all unpatched and exposed assets.\n- Isolate or apply compensating controls to any critical systems that cannot be patched immediately.\n\n**Long-Term Improvements:**\n- Establish a formal patch management policy with defined SLAs (e.g., critical patches applied within 24–72 hours of release).\n- Maintain a continuously updated asset inventory so no system is overlooked during emergency patch cycles.\n- Implement network segmentation to limit lateral movement potential from wormable vulnerabilities.\n\n**Detection Measures:**\n- Enable endpoint detection and response (EDR) tooling to monitor for privilege escalation behaviors associated with ALPC and update stack exploits.\n- Configure SIEM alerting for anomalous privilege escalation events and unusual inter-system communication patterns.\n- Subscribe to Microsoft Security Update Guide notifications to ensure zero-day advisories are received and acted on without delay.",[12,13,14,15,16,17,18,19],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SI-2: Flaw Remediation","NIST SI-5: Security Alerts, Advisories, and Directives","NIST RA-5: Vulnerability Monitoring and Scanning","ITIL Change Management: Emergency Change Procedures","CISA KEV (Known Exploited Vulnerabilities) Catalog: Prioritization Guidance","published","2026-09-08T20:20:19.021704+00:00","2026-09-08T20:20:18.896+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.securityweek.com\u002Fmicrosoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days\u002F","microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days-9d5b32","Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]