
🛡️ **CRITICAL: Microsoft Patches Two Actively Exploited Windows Privilege Escalation Zero-Days**
Published Wednesday, September 09, 2026 at 05:32 PM PT BLUF: Microsoft’s September 2026 Patch Tuesday includes fixes for CVE-2026-85880 and CVE-2026-81963, two Windows privilege escalation vulnerabilities already exploited in active attacks. Both allow local attackers to escalate to SYSTEM access. Patch immediately on all Windows systems; exploitation requires local access but no user interaction. DETAILS Both CVE-2026-85880 and CVE-2026-81963 are Windows privilege escalation flaws carrying CVSS 7.8 severity Vulnerabilities are actively exploited in the wild — in-the-wild exploitation is confirmed, not theoretical Attack chain: attacker with initial local access (compromised account, physical access, or lateral movement from network compromise) can escalate privileges to SYSTEM without additional user action Microsoft addressed both in September 2026 Patch Tuesday cycle Both are zero-days — previously unknown and unpatched before this cycle IMPACT ...