Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days.
The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges.
“An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required,” Microsoft notes in its advisory.
Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023, Tenable senior staff research engineer Satnam Narang points out.
The second zero-day, CVE-2026-81963, is an improper link resolution before file access (‘link following’) defect in Windows Update Stack, the components used for Windows update installation. The vulnerability also allows local attackers to elevate their privileges to System.











