On the second Tuesday of September, Microsoft released its monthly round of security updates. This one was big — over 960 flaws fixed, a record — and buried in it were two Windows vulnerabilities that Microsoft says attackers were already using before a fix shipped. For a small business, a school, or a church running office computers, that sentence usually means one thing: panic. Here is the plain-English version of what actually got patched, what the "exploited in the wild" label really means, and what you should do about it.
TL;DR
Microsoft patched two Windows flaws in September that were already being actively exploited: one in Windows Update Stack and one in Windows Advanced Local Procedure Call (ALPC). Both are what security folks call elevation of privilege bugs — meaning an attacker uses them to climb from a limited foothold up to full system control. The patches are out now. The practical response is: get the standard monthly Windows updates installed, make sure you have a real backup, and keep the "someone already got in" scenarios in mind. For most small teams this is a normal patch month with an extra nudge of urgency, not an emergency that changes your whole plan.
What the two exploited flaws actually are
Microsoft tracks these as CVE-2026-81963 and CVE-2026-85880. Both are rated Important, which can sound low compared to the Critical ratings on other bugs, but the ratings don't tell the whole story — what matters here is that both were used in real attacks.
- CVE-2026-81963 is in Windows Update Stack, the behind-the-scenes machinery that installs Windows updates on your machine. The flaw is a link-following bug that lets an attacker who already has some access on the computer lift themselves up to SYSTEM-level control — effectively the keys to the machine.
- CVE-2026-85880 is in Windows Advanced Local Procedure Call (ALPC), a helper Windows uses for programs to talk to each other. It is a heap-based buffer overflow with the same end result: an attacker gains higher privileges than they should have.
Microsoft has not shared specifics about how either was used in attacks, which is common and doesn't change the recommendation. The important framing for a small team is that these are not the flashy "clicked a bad link and the attacker is now inside over the internet" bugs. They are the second half of an attack — the step where someone who has already found a way onto a machine gets more control. That distinction matters, because it points at where your defenses should sit.
What "exploited in the wild" does and doesn't mean
It is worth being precise here, because headlines love the phrase. When Microsoft marks a flaw as exploited in the wild, it means there is evidence attackers used it before a fix was available. It does not mean your organization was specifically targeted, and it does not mean there's a worm crawling across the internet grabbing every Windows machine it finds. In this case both flaws require the attacker to already have a foothold on the target system. The realistic picture is criminals steadily working through victims they have already pried open — not a wave of fresh break-ins crashing through locked doors.
That said, mark-as-exploited is the closest thing the industry has to a "this one is real" signal, and it earns these two patches a higher priority than the other 960 fixes in the release.
What a small team should actually do
The good news is the checklist is short and it's the same checklist you should be running every month. If you manage your own computers, start there:
- Install the September Windows updates on every machine, including the ones that rarely get used. A spare laptop, a machine in a back office, a point-of-sale computer — these are the ones that quietly miss patches and become the weak link.
- Make sure your backups actually work. An elevation-of-privilege bug matters most when it rides on top of ransomware. A fresh, tested backup is the thing that turns a bad week into an inconvenience.
- Do not click "run" on unexpected files, even from people you know. An attacker needs a starting point to reach these flaws. Phishing resistance and cautious clicking are exactly what defuses that first step.
- Restrict who can log in as an administrator. The fewer people with full control, the fewer doors an attacker can push through to reach the deeper layer.
If your updates are handled for you — by us, by another IT provider, or by a managed service — there is nothing pressing to do today. Confirm the person looking after your machines knows this month's release includes two actively exploited flaws and that both got deployed. A five-minute message to your IT contact is a reasonable asks for a month like this.
The takeaway
A record-breaking Patch Tuesday with two exploited zero-days sounds like an emergency, and for security teams it is a real priority. For a small business, a school, or a ministry, the honest read is simpler: get the standard monthly updates applied, verify your backup, and keep doing the everyday things that stop an attack before it ever reaches a flaw like these. The scary headline is really a reminder that the unglamorous month-to-month habits are what keep you safe.
If you would like help making sure updates are actually flowing to every machine you rely on — including the ones that are easy to forget — that is exactly the kind of thing we look at. It starts with our free 30-minute IT review, and we work with small teams and ministries around Washington County.