Circuit Wire — a daily news update from the Circuit.
Microsoft fixed more than 960 security flaws on September 8, including two Windows zero-day vulnerabilities that attackers were already exploiting, in the company's largest Patch Tuesday on record.
The first zero-day, tracked as CVE-2026-81963, sits in the Windows Update Stack, the set of components that installs Windows updates. It lets an attacker who already has a foothold raise their access to SYSTEM, the highest privilege level on a Windows machine. Researchers said it is the first flaw in that component confirmed to be exploited in the wild.
The second, CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call component, rated 7.8 out of 10. It also hands a local attacker SYSTEM control, and it is only the second flaw of its kind patched as a zero-day since 2023. Neither bug opens a remote entry point on its own. Both are used to deepen control after an intruder is already inside a system.
The Cybersecurity and Infrastructure Security Agency added both flaws to its Known Exploited Vulnerabilities catalog on September 8, the same day the fixes shipped. That catalog is binding on federal civilian agencies, which face set deadlines to patch, and many private firms use it to rank their own repairs.
The update lands during a steady run of exploited flaws in widely used software. In recent weeks, agencies were ordered to patch problems in SonicWall and Citrix products, and Adobe repaired a Magento zero-day used to backdoor online stores. Attackers often pair elevation-of-privilege flaws like this month's with other bugs to move from one machine to a whole network.
Microsoft published advisories through its Security Response Center as the patches went live, and both the company and CISA pointed to the two zero-days as the most urgent items in the release. Windows runs the desktops, servers, and back-office systems inside most organizations, so a SYSTEM-level flaw can reach nearly every part of a network. The company did not say who was behind the attacks or how many organizations were hit.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

