Two of the flaws Microsoft fixed on Tuesday were already being used against people. Both are elevation-of-privilege bugs in Windows, the kind an attacker reaches for once they are on a machine but stuck with an ordinary user's rights, and both let them finish the job. CISA added both to its Known Exploited Vulnerabilities catalog the same day.
They arrived inside an unusually large release. Cisco Talos counted 973 vulnerabilities, 113 of them marked critical by Microsoft, and 82 of those critical entries are remote code execution flaws. Rapid7 counted 974 own-product vulnerabilities, 723 of them in Windows, and with 25 non-Microsoft CVEs also addressed put the day's total at 999.
The first of the exploited pair, CVE-2026-81963, sits in the Windows Update Stack. Microsoft ties it to improper link resolution before file access, better known as link following, together with improper access control, and scores it 7.8. The second, CVE-2026-85880, is in Windows Advanced Local Procedure Call, the mechanism Windows components use to talk to each other. Microsoft attributes it to a heap-based buffer overflow and the use of an uninitialized resource, and also scores it 7.8. Neither Microsoft nor Talos published exploitation detail beyond the fact that both are being exploited, and the vendor advisories carry whatever specifics exist.
Four names on the federal list
CISA's catalog update the same day covered four vulnerabilities, not two. Alongside the pair from Microsoft it added CVE-2026-75650, an improper neutralization flaw in the template engine of Adobe Commerce and Magento, and CVE-2026-86218, the static code injection bug in N-able N-central that has kept managed service providers patching all week. Binding Operational Directive 26-04 obliges federal civilian agencies to move fast on catalog entries affecting publicly exposed assets that hand an attacker total control, and CISA repeats its standing advice that everyone else should treat the list the same way.
The unexploited ones worth reading first
Microsoft flags a handful of this month's fixes as more likely to be exploited than the rest. The heaviest is CVE-2026-69730 in Windows DNS Server, a use-after-free that Microsoft scores 9.8 for remote code execution. CVE-2026-69676 in Windows Kerberos is a capture-replay authentication bypass leading to remote code execution at 8.8. CVE-2026-69854, an improper authentication flaw in Spring Cloud Azure, carries a 9.0. Windows Routing and Remote Access Service and Windows Deployment Services each pick up a heap overflow that Microsoft rates remotely exploitable.
Take the two exploited bugs first
The order of work is not complicated. Install the September updates, and if the rollout has to be staged, put the two catalog entries at the front of it, because those are the only ones known to be in use today. Internet-facing DNS servers and domain controllers are the next queue after that. Adobe Commerce and Magento operators have their own entry to attend to, and it is not a Windows problem.
The exploited-vulnerabilities catalog keeps proving more useful than a severity score. Neither Windows flaw this month reaches the 9.8s further down the list, and both are the ones actually being used. Microsoft has also had to correct an exploitation flag in the other direction this summer, and CISA keeps adding entries that never looked like priorities, including a webhook flaw in an AI experiment server. What an attacker picks up and what a scanner ranks highest are rarely the same list.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.