VYPR
patchPublished Sep 14, 2026· 1 source

Microsoft's September Patch Tuesday Addresses 973 Vulnerabilities, Including Two Actively Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday tackles a massive 973 vulnerabilities, with two zero-days in Windows ALPC and the Update Stack actively exploited for privilege escalation.

Microsoft's September 2026 Patch Tuesday has rolled out with an overwhelming 973 vulnerability fixes across its product suite, including Windows, Office, SQL Server, Exchange, SharePoint, Azure, and various developer tools. This extensive release highlights the ongoing challenge of maintaining secure systems, with elevation of privilege flaws constituting the largest category at 438 issues, followed closely by 258 remote code execution (RCE) bugs. The sheer volume, with Windows Biometric Service alone accounting for 64 vulnerabilities, suggests potential systemic weaknesses in critical authentication subsystems.

Two zero-day vulnerabilities were confirmed to be under active exploitation: CVE-2026-85880, affecting the Windows ALPC (Advanced Local Procedure Call) interface, and CVE-2026-81963, impacting the Windows Update Stack. Both are classified as 'Important' severity and allow attackers to gain elevated privileges on compromised systems. Critical patches were also issued for vulnerabilities in Windows Secure Kernel Mode, VBS Enclave, and for RCE flaws in Excel and Word, marking this as one of the most urgent and extensive patch cycles for enterprise IT teams this year.

Beyond Microsoft's extensive update, the cybersecurity landscape remains fraught with other critical threats. Researchers have uncovered an active campaign exploiting CVE-2025-25249, a critical heap overflow vulnerability in FortiOS and FortiSwitchManager's CAPWAP service. This flaw, rated 9.8 out of 10, is being used to deploy a custom Node.js Remote Access Trojan (RAT) named PivotC2. The malware is designed to bypass firewall restrictions by establishing outbound TLS connections, harvest device configurations, and exfiltrate sensitive credentials, including VPN and SSL-VPN secrets.

The PivotC2 campaign has already targeted over 30,000 FortiGate IP addresses, with confirmed intrusions against U.S. organizations leading to the exfiltration of Exchange mailbox data to Wasabi cloud storage. Researchers attribute this campaign to a Russian-speaking, financially motivated threat group, which is also reportedly targeting vulnerabilities in FortiManager and ArubaOS. Fortinet urges immediate upgrades to FortiOS versions 7.6.4, 7.4.9, 7.2.12, or 7.0.18, or later, to mitigate this threat.

Palo Alto Networks has also released a fix for CVE-2026-0310, a critical buffer overflow vulnerability in PAN-OS's XML processing. This flaw allows unauthenticated attackers to achieve root-level code execution on PA-Series hardware firewalls, posing a significant risk to network security infrastructure. While VM-Series firewalls are only impacted with a denial-of-service risk, the potential for full system compromise on hardware appliances is severe. Affected versions span multiple PAN-OS branches prior to specific updates, and Palo Alto Networks advises immediate upgrades, noting that no workaround is available.

In other news, a 12-year-old PostgreSQL vulnerability, dubbed 'PostGREShell' (CVE-2026-6471), has been disclosed. This flaw allows low-privileged accounts with the REPLICATION attribute to abuse logical decoding to load attacker-controlled shared libraries, leading to code execution with server process permissions. Given that replication accounts are often used for backups and disaster recovery, this vulnerability presents a direct path to full database compromise. Patches are available for PostgreSQL versions 18.6, 17.11, 16.15, 15.19, and 14.24.

Finally, the financial technology firm Revolut has reported a data breach where sensitive customer information, including passport copies and transaction histories, was exposed. The breach occurred through a fraudulent request that impersonated a government agency, highlighting the persistent threat of social engineering and impersonation tactics. This incident underscores the need for robust verification processes and vigilance against sophisticated phishing and pretexting attacks, even within the financial sector.

Synthesized by Vypr AI