[CIAD-2026-0044] Multiple Vulnerabilities in Microsoft Products

By Published On: September 10, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Microsoft Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: High


Software Affected


Microsoft Windows

Microsoft Office

Microsoft Dynamics

SQL Server

Extended Security Updates (ESU) for legacy Microsoft products

Azure

Apps

Developer Tools

Open Source Software

Server Software

Overview


Multiple vulnerabilities have been reported in Microsoft products that could allow an attacker to gain elevated privileges, obtain sensitive information, execute arbitrary code remotely, bypass security restrictions, conduct spoofing attacks, perform tampering of data or system processes, or cause denial-of-service (DoS) conditions.


Target Audience:

Individuals and IT administrators, security teams responsible for maintaining and updating Microsoft products.


Risk Assessment:

Risk of remote code execution, system instability or sensitive information disclosure.


Impact Assessment:

Potential compromise of system, exfiltration of data, ransomware attacks or system crashes.


Description


Multiple vulnerabilities have been reported in Microsoft products that could allow an attacker to gain elevated privileges, obtain sensitive information, execute arbitrary code remotely, bypass security restrictions, conduct spoofing attacks, perform tampering of data or system processes, or cause denial-of-service (DoS) conditions.


CVE-2026-81963: This vulnerability exists in the Microsoft Windows Update Stack due to improper link resolution before file access. An authorized attacker could exploit this vulnerability locally to elevate privileges. Successful exploitation could result in elevated privileges on the affected system.


CVE-2026-85880: This vulnerability exists in Microsoft Windows Advanced Local Procedure Call (ALPC) due to a heap-based buffer overflow. An authorized attacker could exploit this vulnerability locally to elevate privileges. Successful exploitation could result in elevated privileges on the affected system.


Note: These vulnerabilities are being exploited in the wild. Users are advised to apply patches immediately.


For complete list of affected products, CVEs, workarounds and solutions, refer to the Microsoft security updates.

https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep




Solution


Apply appropriate security updates as mentioned in  

https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep


Vendor Information


Microsoft

https://msrc.microsoft.com/update-guide/


References


 

https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqirdUACgkQ3jCgcSdc

ys/5YBAAqIU8wiifO6k4UguTqZwZ3Px9C20EZ33AscfefbQVTXTmg5zric4HXXV+

0b2KDf03QSxwho4QXWzEuL17ZHeRKqBTsM9pMDJ+lJDsov0W7sn988buCcOKQsJP

XYvQkdtS+Sfi+PG1uXcFh7pXY7vQhAnogRy5noY7YFnNqHI0IFM3SGXzw6gsitxj

GYLSuokB4Bbl+O6YzvMt9lQZqxFIMIqurW7Cw4lHo/xexYBafJUPPW2YmUj3wXua

LSrMo15p4ajvlSKEVgITcx5B8DOrN72QJ+jsfDG1Rv9nQUbVBLDesq6W79ZJr+yN

5h+tOQ7Ro1fCbygmDBXbBcQEffW5n0mROFCft1Et/SQK3Rw+lgK7biRQaogw+4v+

8TRxpDjGeZlTu8LnwZAlJzjHSjzs6VM7l96RIGfBXv7xK4xyKwr4gyKyn/Jc36Wu

rrNU6u/80KTRD2Md0euLhaYYyTgVYrbLX0aCKQeRosfxzIIRzmQeQ6iNhvyuUebc

uVoEyh6tsk0MFvq0JfQ8hyiJI5inVULgaxcsqgQEN52TUQW//x907aw1LlgOKKln

N4BvwQXLAC4VSrwSfCD5PzRMPWTx7lNiqYW3DaiiTRIU9l0w9Zz2ylwhJarF6i+4

taBu+dIsDnM+iYWJp7ZqyryQX2Q+ctldJU7OV7qly7OhtJ3UHJs=

=mH/j

—–END PGP SIGNATURE—–

Share this article