Windows Ecosystem Bulletins & Field News
Welcome to the Windows Ecosystem Bulletins & Field News stream. This live chronological journal compiles verified Microsoft cumulative updates, Patch Tuesday zero-day disclosures, Windows Server operational advisories, and enterprise Active Directory developments.
All bulletins include official source attribution, publication timestamps, and actionable remediation steps.
π Published: September 15, 2026
πͺ Windows September 2026 Patch Tuesday Zero-Days: ALPC & Update Stack Privilege Escalations (CVE-2026-85880 & CVE-2026-81963)
In the historic September 2026 Patch Tuesday release, Microsoft resolved two actively exploited zero-day Elevation of Privilege (EoP) flaws:
- CVE-2026-85880: A heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component, allowing local low-privilege attackers to break sandbox barriers and elevate to
NT AUTHORITY\SYSTEM. - CVE-2026-81963: An improper link resolution (βlink followingβ) defect in the Windows Update Stack, enabling local attackers to abuse SYSTEM write privileges and plant arbitrary binaries.
Both vulnerabilities were immediately added by CISA to the Known Exploited Vulnerabilities catalog.
π Published: September 29, 2026
πͺ Windows 11 Version 26H2 Release, JIT Administrator Protection & Server 2025 RDS Hotfixes
On September 29, 2026, Microsoft officially released Windows 11 Version 26H2 (the Windows 11 2026 Update). Delivered primarily as a lightweight enablement package (KB5121794) for devices on previous annual baselines, the update introduces major enterprise system security changes.
At the same time, sysadmins managing enterprise fleets face critical operational updates: Microsoft released emergency out-of-band updates (KB5129235) for Windows Server 2025 to resolve severe Remote Desktop Services (RDS) server crashes caused by the September cumulative patch, alongside the formal deprecation announcement of the legacy Windows Deployment Services (WDS) role.
π Published: September 25, 2026
πͺ Microsoft SharePoint Server Authenticated Remote Code Execution (CVE-2026-65660)
Added to CISA KEV on September 25, 2026: A code injection defect in Microsoft SharePoint Server allows authenticated users with standard site member privileges to trigger server-side code execution in the context of the SharePoint application pool worker process (w3wp.exe).