CISA Tracks Two Actively Exploited Windows Vulnerabilities After Microsoft’s September Patches
Microsoft released its September security updates, including KB5122878 for Windows 10. CISA also added two Windows vulnerabilities to its Known Exploited Vulnerabilities catalog.

Microsoft’s September Windows updates also address two vulnerabilities that the U.S. agency CISA tracks as actively exploited. These are CVE-2026-81963 in the Windows Link Following function and CVE-2026-85880, a heap-based buffer overflow in Windows. On September 8, CISA added them to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of real-world exploitation.
That same day, Microsoft released cumulative update KB5122878 for Windows 10 version 22H2 and LTSC editions. Independent security media agree that both vulnerabilities were part of the September Patch Tuesday release and that fixes are available.
September Windows updates include two vulnerabilities in the KEV catalog
Both tracked vulnerabilities allow local privilege escalation. For CVE-2026-85880, secondary security reports cite the possibility of escaping the AppContainer isolation environment and gaining SYSTEM privileges.
The fact that CISA added both vulnerabilities to KEV means the agency has evidence of their exploitation in practice. However, the available materials do not confirm that a working exploit is publicly available. Specific technical details of the attacks or indicators of compromise associated with these two CVEs have likewise not been published.
The number of fixed CVEs is not reported consistently
The September release is among the larger patch packages by scope, but the exact number of vulnerabilities has not been reliably established. Different sources report 966, 972, 973, or 974 vulnerabilities. The differences likely relate to how CVEs are counted and to republished third-party vulnerabilities.
System administrators should therefore not treat any one of these figures as a definitive total. What matters is that, according to CISA, two fixed Windows vulnerabilities are already being actively exploited and Microsoft has released patches.
What system administrators should do
The priority is deploying the September security updates to Windows systems. For Windows 10 22H2 and LTSC, Microsoft lists package KB5122878.
- Verify that the September updates are available and successfully installed on managed devices.
- Before broad deployment, follow your own update testing process.
- Prioritize Windows devices because CVE-2026-81963 and CVE-2026-85880 are listed in CISA’s KEV catalog.
- Monitor Microsoft’s official release notes and any reports of problems after installing KB5122878.
Additional information may come from potential technical analyses of the vulnerabilities, public exploits, or indicators of compromise. For now, active exploitation and patch availability are confirmed, but the specific attack methods are not.
Sources
- Microsoft Learn – Windows 10 release information – Confirms the release of KB5122878 on September 8, 2026, for Windows 10 22H2 and LTSC.
- CISA – Adds Four Known Exploited Vulnerabilities to Catalog – Confirms the addition of CVE-2026-81963 and CVE-2026-85880 to KEV based on active exploitation.
- BleepingComputer – Reports 966 flaws and two actively exploited zero-day vulnerabilities; this is one of the differing counting methodologies.
- Ars Technica – Documents a different total of 972 and the scope of the critical patches.
- SecurityWeek – Confirms two exploited vulnerabilities and describes the technical impact of CVE-2026-85880.
Verified and updated: 09/09/2026 06:21



