>samit_hota
Back to security news

Security News · SN-2026-459

CRITICALCVE-2026-85880OPEN

September 2026 Patch Tuesday Arrives with AI-Fueled Fix Count and Active Zero-Days

Affected: Microsoft Windows · Windows Server · SAP ABAP/NetWeaver · Adobe Commerce · FortiOS

Samit Hota·
#news#vulnerability-disclosure#microsoft

An unprecedented volume of security updates hit enterprise networks this week as Microsoft released fixes for 964 vulnerabilities in its September 2026 Patch Tuesday cycle. Driven by the vendor’s internal AI-assisted security testing operations introduced earlier this year, the issue count breaks previous records for a single monthly update.

Among the massive volume of patches are fixes for two actively exploited zero-day vulnerabilities in Windows local IPC and update management infrastructure, alongside critical remote code execution bugs in core DNS services and severe enterprise flaws across SAP, Adobe, Fortinet, and Cisco environments.

Actively Exploited Windows Zero-Days

The most immediate operational risk stems from CVE-2026-85880, an actively exploited local privilege escalation flaw in the Windows Advanced Local Procedure Call (ALPC) subsystem. ALPC functions as the underlying message-passing framework allowing isolated processes on a Windows endpoint to exchange structured data.

The vulnerability manifests as a heap-based buffer overflow (CWE-122) caused by uninitialized memory structures (CWE-908) during message processing. The attack surface is locally reachable with low privilege requirements and requires no user interaction (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). In practice, an adversary who has gained initial code execution inside a low-privilege sandbox—such as an isolated web browser worker process or an AppContainer application—can pass malformed LPC messages to the host kernel or RPC service. This triggers a heap overrun, allowing the process to break sandbox boundaries and elevate to higher systemic privileges.

CVE-2026-85880 impacts a wide range of production systems, including Windows 10 (versions 1607, 1809, 21H2, and 22H2 prior to build 10.0.19045.7725), Windows Server 2012 R2, and Windows Server 2016 (prior to build 10.0.14393.9512). Because ALPC is fundamentally embedded across the operating system architecture, the vulnerability effectively spans both legacy host builds and modern desktop endpoints.

The second zero-day under active exploitation is CVE-2026-81963, a local privilege escalation in the Windows Update Stack. This bug stems from improper link resolution prior to file operations (link-following vulnerability), allowing an authenticated user to manipulate symbolic links or junction points manipulated during update file writes to acquire full SYSTEM privileges. While Microsoft confirmed impact on Windows 11 Desktop and Windows Server 2025, no functional workarounds exist short of applying the official update package. This marks the first zero-day exploitation recorded among seven privilege escalation vulnerabilities identified in the Windows Update Stack framework since 2022.

Wormable Remote Execution and Network Risks

Beyond local escalation paths, defenders face notable network-reachable vulnerabilities capable of rapid propagation across corporate subnets. Chief among these is CVE-2026-69730, an unauthenticated Windows DNS Remote Code Execution flaw. While not yet observed in active exploitation, the vulnerability requires zero user interaction; an attacker can execute arbitrary code with elevated system rights by transmitting a single crafted packet to an exposed DNS service.

Security researchers have drawn direct parallels between CVE-2026-69730 and historic wormable DNS infrastructure flaws such as SigRed, warning that exposure on domain controllers poses immediate lateral movement risks. Additional unauthenticated, zero-interaction network execution bugs patched in this cycle include:

  • CVE-2026-69590: A Windows Routing and Remote Access Service (RRAS) Remote Code Execution vulnerability.
  • CVE-2026-62893: A Windows Deployment Services TFTP Server Remote Code Execution flaw (originally issued in August and reiterated due to high network exposure).

Critical Flaws in SAP Infrastructure

Concurrently, enterprise environments running SAP ERP installations require critical attention. SAP released Security Note #3747649 to address CVE-2026-3747649 (tracked as “OVERPASS”), a maximum-severity memory corruption flaw carrying a CVSS score of 10.0 in the Extended Passport Processing (EPP) component of ABAP-based systems.

EPP is enabled by default across SAP S/4HANA and NetWeaver to log transaction boundaries and trace execution flows across distributed business suites. The flaw resides in missing length and boundary validation during the deserialization of externally supplied EPP data headers. An unauthenticated remote attacker can send malformed network packets over several supported communication protocols, triggering memory corruption to execute arbitrary operating system commands with full SAP administrative privileges. Because EPP functionality is embedded deeply across ABAP and Java kernels as well as SAP Web Dispatcher 9.16, network perimeter controls alone cannot mitigate the risk.

Additionally, SAP Security Note #3759472 addresses “S4GET”, a CVSS 9.8 flaw in NetWeaver Message Server across modern kernel lines (9.16 through 9.20). S4GET results from insufficient authentication checks when registering internal application server components, enabling unauthenticated attackers over the network to register rogue components and execute unauthorized administrative commands within S/4HANA 2025 environments.

Multi-Vendor Active Attacks

The security updates extend to several third-party products under active exploitation:

  • Adobe Commerce / Magento: CVE-2026-75650 (CVSS 10.0, “StyleSmuggler”), an actively exploited zero-day flaw utilized by threat actors to drop Linux web shells and backdoors.
  • Fortinet FortiOS: Ongoing exploitation targeting CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in management interfaces that grant unauthenticated remote attackers administrative control over perimeter firewalls.
  • Cisco Systems: Active exploitation targeting CVE-2026-20349, an unauthenticated denial-of-service flaw affecting Secure Firewall ASA systems.

Remediation and Prioritization Guidance

Given the sheer volume of nearly 1,000 CVEs issued in a single cycle, relying exclusively on raw CVSS scoring will stall remediation workflows. Security teams should prioritize patching based on exploitability metrics and threat landscape activity:

  1. Immediate Tier (24–48 Hours): Deploy official patches for actively exploited zero-days CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack), alongside the critical SAP OVERPASS vulnerability via Security Note #3747649.
  2. Perimeter and Core Services: Patch Windows DNS endpoints (CVE-2026-69730), Adobe Commerce instances (CVE-2026-75650), and edge firewalls (FortiOS and Cisco ASA). Ensure internal domain controllers running Windows DNS are protected against unauthenticated network packets.
  3. Build Target Verification: Verify Windows 10 host builds are brought to updated baseline revisions (e.g., build 10.0.19045.7725 for 22H2). Refer to Microsoft’s official security advisory catalog (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880) for full release package details.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call