CISA Tracks Two Actively Exploited Windows Vulnerabilities After Microsoft’s September Patches

Microsoft released its September security updates, including KB5122878 for Windows 10. CISA also added two Windows vulnerabilities to its Known Exploited Vulnerabilities catalog.

Microsoft’s September Windows updates also address two vulnerabilities that the U.S. agency CISA tracks as actively exploited. These are CVE-2026-81963 in the Windows Link Following function and CVE-2026-85880, a heap-based buffer overflow in Windows. On September 8, CISA added them to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of real-world exploitation.

That same day, Microsoft released cumulative update KB5122878 for Windows 10 version 22H2 and LTSC editions. Independent security media agree that both vulnerabilities were part of the September Patch Tuesday release and that fixes are available.

September Windows updates include two vulnerabilities in the KEV catalog

Both tracked vulnerabilities allow local privilege escalation. For CVE-2026-85880, secondary security reports cite the possibility of escaping the AppContainer isolation environment and gaining SYSTEM privileges.

The fact that CISA added both vulnerabilities to KEV means the agency has evidence of their exploitation in practice. However, the available materials do not confirm that a working exploit is publicly available. Specific technical details of the attacks or indicators of compromise associated with these two CVEs have likewise not been published.

The number of fixed CVEs is not reported consistently

The September release is among the larger patch packages by scope, but the exact number of vulnerabilities has not been reliably established. Different sources report 966, 972, 973, or 974 vulnerabilities. The differences likely relate to how CVEs are counted and to republished third-party vulnerabilities.

System administrators should therefore not treat any one of these figures as a definitive total. What matters is that, according to CISA, two fixed Windows vulnerabilities are already being actively exploited and Microsoft has released patches.

What system administrators should do

The priority is deploying the September security updates to Windows systems. For Windows 10 22H2 and LTSC, Microsoft lists package KB5122878.

  • Verify that the September updates are available and successfully installed on managed devices.
  • Before broad deployment, follow your own update testing process.
  • Prioritize Windows devices because CVE-2026-81963 and CVE-2026-85880 are listed in CISA’s KEV catalog.
  • Monitor Microsoft’s official release notes and any reports of problems after installing KB5122878.

Additional information may come from potential technical analyses of the vulnerabilities, public exploits, or indicators of compromise. For now, active exploitation and patch availability are confirmed, but the specific attack methods are not.

Sources

Verified and updated: 09/09/2026 06:21

Sharing