VYPR
Vypr IntelligenceAI-generatedSep 8, 2026· 2 CVEs

Microsoft: 2 Actively-Exploited Flaws Added to CISA KEV

CISA has added two actively-exploited Microsoft vulnerabilities to its Known Exploited Vulnerabilities Catalog, underscoring the immediate threat these flaws pose to federal agencies and critical infrastructure.

Key findings

  • Two Microsoft vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are now in CISA's KEV catalog.
  • Both flaws are confirmed to be under active exploitation in real-world attacks.
  • Immediate patching and mitigation are critical for all organizations to prevent compromise.
  • No ransomware association has been reported for these specific vulnerabilities.
  • CISA mandates remediation for federal agencies, but all entities should prioritize these fixes.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert, adding two new Microsoft vulnerabilities, CVE-2026-81963 and CVE-2026-85880, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition signifies that these flaws are under active exploitation in the wild, making them critical targets for immediate remediation across all organizations.

These two distinct vulnerabilities, while batched together in this KEV update, represent separate security risks within Microsoft's ecosystem. CVE-2026-81963 is an actively exploited flaw that could allow attackers to compromise systems, while CVE-2026-85880 also presents a significant risk due to its confirmed exploitation. The inclusion in the KEV catalog serves as a definitive warning that these are not theoretical threats but actively leveraged attack vectors.

There is no indication from the provided information that either of these vulnerabilities are currently associated with ransomware campaigns. However, active exploitation of any kind can lead to severe consequences, including data breaches, system compromise, and further network infiltration.

Organizations, particularly federal civilian executive branch (FCEB) agencies, are mandated by CISA's Binding Operational Directive (BOD) 22-01 to address KEV entries by their specified due dates. However, given the active exploitation, all organizations are strongly advised to prioritize patching and mitigation efforts for CVE-2026-81963 and CVE-2026-85880 immediately. Proactive defense is crucial to prevent potential exploitation and safeguard digital assets.

AI-written article. Grounded in 2 CVE records listed below.