Windows Update Stack and ALPC actively exploited elevation-of-privilege flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft patched two actively exploited Windows elevation-of-privilege flaws in Windows Update Stack and Windows Advanced Local Procedure Call (ALPC), preventing local attackers from escalating to SYSTEM privileges.
Related Happenings
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation Wave
H score41
First: 30.06.2026 11:53
Last: 30.06.2026 11:53
Sources 1
About this happening:
CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave
Exploitation WaveAbout this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...
CISA KEV order for BlueHammer patching
Public Sector Action
H score37
First: 23.04.2026 14:05
Last: 23.04.2026 14:05
Sources 1
About this happening:
CISA ordered Federal Civilian Executive Branch agencies to patch Windows systems against CVE-2026-33825 within two weeks after adding BlueHammer to the K...
CISA KEV order for BlueHammer patching
Public Sector ActionAbout this happening: CISA ordered Federal Civilian Executive Branch agencies to patch Windows systems against CVE-2026-33825 within two weeks after adding BlueHammer to the K...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/Mitigation
H score48
First: 14.01.2026 11:38
Last: 14.01.2026 11:38
Sources 1
About this happening:
Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/MitigationAbout this happening: Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Latest development: 10.02.2026 21:06
Microsoft released Windows 10 KB5075912 and continues rolling out replacement Secure Boot certificates to targeted Windows devices through monthly Windows updates, expanding delivery only after devices show sufficient successful update signals ahead of the June 2026 expiration.
Timeline
-
08.09.2026 21:18 3 articles · 15h ago
Microsoft patches Windows Update Stack and ALPC zero-days
Initial DisclosureMicrosoft released September 2026 Patch Tuesday security updates for 966 flaws, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 in Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC). Both flaws allow an authorized local attacker to elevate privileges to SYSTEM.
Show sources
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days — www.bleepingcomputer.com — 08.09.2026 21:18
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days — www.bleepingcomputer.com — 08.09.2026 21:18
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days — www.securityweek.com — 08.09.2026 22:20