Why this month's fixes deserve attention
Microsoft has confirmed that two Windows vulnerabilities fixed in its September security release were exploited before the updates were available. Its monthly MSRC bulletin identifies CVE-2026-85880, affecting Windows Advanced Local Procedure Call, and CVE-2026-81963, affecting the Windows Update Stack. Both are described as elevation-of-privilege flaws.
Canada's Cyber Centre also flags both identifiers in its September 8 advisory and encourages applying the necessary updates. The important point for affected users is that the weaknesses have been used, rather than merely identified in a theoretical scenario. The notices do not establish the scale of the attacks or show that every Windows device is vulnerable in the same way.
Start with the Windows version you actually run
For Windows 11 versions 24H2 and 25H2, Microsoft has published KB5124008, dated September 8. The package brings those branches to builds 26100.9445 and 26200.9445 respectively. Those identifiers help users and administrators check the relevant release, but they are not a universal update label for every supported edition of Windows.
The support page says the package is delivered automatically through Windows Update; managed organizations receive it according to their configured policies. If a device is maintained by an employer or school, follow that organization's update process. Installing a package intended for another branch or architecture is not a useful shortcut to getting protected.
Downloaded is not the same as finished
Microsoft describes September's Windows release as a baseline update that requires a restart, including in the hotpatch schedule. Users should therefore check whether installation is complete rather than assume that a downloaded update has finished the work. Save open work and plan the requested restart instead of leaving it pending indefinitely.
At the time of this check, Microsoft listed no known issues for KB5124008. That statement can change as reports arrive, and it does not guarantee that every application or device configuration will behave identically. For a business, our recommendation is an accelerated, controlled rollout with a clear owner, a small representative test group and an explicit check that affected machines actually reach the intended update state.
The number of fixes is not the risk assessment
In a May explanation of rising update volumes, Microsoft's Tom Gallagher connected broader vulnerability discovery with automation, researcher participation and increasing use of AI. The guidance was to prioritize exposure and impact using several signals, including observed exploitation, rather than a raw total. That is background context from May, not a separate announcement made this week.
Our reading is that a large release needs better sorting, not panic. Start with software you actually operate, establish which systems are affected and identify where a failure would hurt most. A dramatic count can attract attention without answering those questions. This report deliberately does not repeat an aggregate vulnerability total that we have not reconciled against the current official records.
What a good response looks like
For an individual user, the immediate task is to review the built-in update status and complete the applicable installation. For an IT team, it is to connect the security notice to an inventory, a deployment decision and evidence of completion. Downloading an update across a fleet is only one stage; devices that fail, remain offline or still need a restart require follow-up.
Patching also should not be presented as proof that an earlier compromise has been removed. If a device shows suspicious behavior, the response needs investigation as well as updates. September's release supplies fixes for known weaknesses. The practical result depends on getting the appropriate fixes onto affected systems and checking that they are in effect.
Sources & Methods
Checked September 9, 2026 against MSRC's September monthly bulletin and Microsoft Support's KB5124008. The bulletin body dates the release September 8 US time. The May 12 MSRC explanation is clearly labeled background. The two CVE links are the authoritative affected-product lookup; their interactive detail tables were not reproduced here. No victim count, exploit technique or independently reconciled patch total is claimed. Operational recommendations are Lumacta analysis.
- Canadian Centre for Cyber Security: September 8 Microsoft advisory — Primary source
- MSRC Japan Security Team: September 2026 security update bulletin — Primary source
- Microsoft Support: Windows 11 KB5124008, September 8 — Primary source
- MSRC: CVE-2026-85880 affected-product details — Primary source · interactive reference
- MSRC: CVE-2026-81963 affected-product details — Primary source · interactive reference
- MSRC: May 12 background on vulnerability discovery and patching — Primary source
