VYPR
Vypr IntelligenceAI-generatedSep 8, 2026· 25 CVEs

Microsoft Windows: 25 Vulnerabilities Disclosed, Including Critical Flaw and Exploited Zero-Day

Microsoft disclosed 25 Windows vulnerabilities on September 8, 2026, including a critical RNDIS flaw and an actively exploited zero-day in ALPC, impacting system security and stability.

Key findings

  • Microsoft patched 25 Windows vulnerabilities on September 8, 2026, including one Critical and multiple High severity flaws.
  • CVE-2026-69768, a Critical heap-based buffer overflow in RNDIS, allows for remote code execution.
  • CVE-2026-85880, a zero-day in Windows ALPC, was actively exploited in the "BlueMoon" chain by Chinese espionage groups.
  • Multiple vulnerabilities affect core Windows components like ALPC, SCSI Class System File, OLE DB, Schannel, and Spaceport.sys.
  • The batch includes numerous privilege escalation and remote code execution flaws, alongside information disclosure vulnerabilities.
  • This disclosure was part of Microsoft's largest-ever Patch Tuesday, addressing 974 CVEs in total.

On September 8, 2026, Microsoft released a massive batch of 25 security advisories addressing vulnerabilities in Windows. This coordinated disclosure event, occurring within a three-minute window, includes a critical flaw and several high-severity issues, impacting various components of the operating system. The vulnerabilities range from heap-based buffer overflows and use-after-free bugs to integer underflows and null pointer dereferences, with many allowing for privilege escalation or remote code execution.

Several vulnerabilities stem from issues within specific Windows components:

  • SCSI Class System File Vulnerabilities: CVE-2026-78453, CVE-2026-78452, and CVE-2026-78451 are related to the Microsoft Windows SCSI Class System File. These include an integer underflow for information disclosure, an out-of-bounds read for information disclosure with physical access, and an untrusted pointer dereference for privilege escalation with physical access.
  • ALPC Vulnerabilities: CVE-2026-85880, CVE-2026-69874, and CVE-2026-69834 are associated with the Windows ALPC component. These flaws, including heap-based buffer overflows and use-after-free bugs, allow for local privilege escalation. Notably, CVE-2026-85880 is one of two zero-days exploited in the wild.
  • Spaceport.sys Vulnerabilities: Multiple vulnerabilities, including CVE-2026-71350, CVE-2026-71349, CVE-2026-70569, and CVE-2026-69895, are present in Windows Spaceport.sys. These range from heap-based buffer overflows allowing code execution with physical access to out-of-bounds reads for information disclosure.

The disclosure of these vulnerabilities coincides with reports of active exploitation. News outlets indicate that CVE-2026-85880, a heap-based buffer overflow in Windows ALPC, was part of an exploit chain, dubbed "BlueMoon," used by multiple Chinese espionage groups since late August 2026. This chain targets both Chrome and Windows, allowing attackers to gain system privileges. Proofpoint researchers identified at least four threat groups, including TA412 (also known as APT31 or Violet Typhoon), exploiting this vulnerability. The attacks have targeted organizations globally, with fewer than 20 organizations initially identified, though the true number is likely higher.

Microsoft's September 2026 Patch Tuesday release, which included fixes for these 25 Windows vulnerabilities, was the largest on record, addressing a total of 974 CVEs. This massive update aims to patch a wide array of issues, including privilege escalation, remote code execution, and information disclosure vulnerabilities. Users are strongly advised to apply these patches immediately to mitigate the risks associated with these vulnerabilities, especially given the reports of active exploitation. The sheer volume of patches underscores the ongoing efforts by Microsoft to address security weaknesses across its product portfolio.

This batch of vulnerabilities highlights critical areas of concern within Windows, particularly concerning memory corruption flaws and privilege escalation vectors. The active exploitation of CVE-2026-85880, chained with browser vulnerabilities, demonstrates a sophisticated attack methodology targeting high-value organizations. Users should prioritize patching to protect against these threats.

The vulnerabilities patched include: CVE-2026-85880, CVE-2026-78453, CVE-2026-78452, CVE-2026-78451, CVE-2026-78442, CVE-2026-71345, CVE-2026-70575, CVE-2026-70569, CVE-2026-70565, CVE-2026-70289, CVE-2026-69906, CVE-2026-69874, CVE-2026-69846, CVE-2026-69834, CVE-2026-69818, CVE-2026-69779, CVE-2026-69770, CVE-2026-69768, CVE-2026-73005, CVE-2026-72940, CVE-2026-71350, CVE-2026-71349, CVE-2026-69895, CVE-2026-69853.

AI-written article. Grounded in 25 CVE records listed below.