By @venturebeat
Publication Date: 2026-10-05 18:17:00
The two flaws attackers were already exploiting when Microsoft’s September 8 Patch Tuesday landed were both rated Important by Microsoft. Both are local elevation-of-privilege vulnerabilities. An attacker who can run low-privilege code on the machine can elevate to SYSTEM privileges.
SANS Internet Storm Center counted 973 CVEs in the release, 113 rated Critical. The release was also Microsoft’s largest Patch Tuesday on record. A team that works the batch from Critical downward reaches neither exploited flaw first. CISA added both, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC, to the Known Exploited Vulnerabilities catalog on September 8.
Mandiant’s M-Trends 2026 puts the mean time to exploit in 2025 at an estimated negative seven days. A negative mean does not mean every vulnerability was exploited before a patch existed; it means exploitation occurred, on average, seven days before patch release.
CrowdStrike’s 2026 Global Threat Report shows how…

