#ALPC
974 CVEs in One Month: Mapping the Windows Patch Surface With Internet-Wide Data
# 974 CVEs in One Month: Mapping the Windows Patch Surface With Internet-Wide Data Microsoft's September 2026 Patch Tuesday fixed 974 CVEs, including two exploited zero-days (CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in ALPC). Vulnerability management teams usually read such releases as internal work queues. Internet asset mapping adds a second, external view: which Windows-exposed services sit on public IPs, which of them leak version information, and how the patch backlog translates into a measurable external footprint. ## From patch counts to external footprint A Windows server missing September's fixes does not advertise the fact, but the services it runs often do. RDP, SMB, IIS, Exchange OWA, and remote access components all expose version and configuration signals that mapping platforms index. The useful question for a team facing 974 fixes is not "how many CVEs affect us" but "which of our systems present an external face that maps onto the exploited or wormable subset." September's release included 438 elevation-of-privilege issues, 257 remote code execution issues, and 20 wormable-class vulnerabilities. The EoP bugs mostly matter after a foothold exists. The RCE and wormable subset maps directly onto external exposure: an internet-reachable system running affected remote access components is a different risk object from an internal workstation with the same patch level. ## Three mapping queries that operationalize the queue 1. Enumerate external RDP and remote access surfaces per organization or per ASN, so the exploited zero-day triage (both September zero-days are local, post-compromise bugs) gets paired with exposure triage of the remote-facing services where an RCE foothold starts. 2. Index Exchange OWA and other webmail surfaces separately. The September bulletin included a Critical Exchange RCE triggered via a Visio file over email, and OWA instances visible from the internet are the population where that path opens first. 3. Verify post-patch disappearance: after deployment, external banners and service versions shift, and mapping data can confirm the external footprint shrank, complementing internal patch compliance reports. Mapping platforms such as ZoomEye support these query patterns through product, service, and version fingerprints (https://www.zoomeye.org/). ## What mapping cannot do External fingerprinting does not see patch levels behind firewalls, and version banners lag the underlying build in cloud and containerized deployments. The two zero-days are local privilege escalations, which mapping cannot detect at all; they require internal inventory. The honest division of labor: internal tools own patch state, mapping owns the external face, and the queue priority comes from joining the two. ## Limitations This article synthesizes published September 2026 advisories and media reporting. No live mapping queries were executed for publication in this piece; the query channel was unavailable at writing time. Counts and CVE designations come from the cited sources. ## References * Microsoft MSRC September 2026 release notes (msrc.microsoft.com/update-guide/releaseNote/2026-Sep) * FreeBuf coverage of the record Patch Tuesday, September 9, 2026 * Huawei Cloud advisory summary, September 9, 2026
dev.to
September 23, 2026 at 11:45 PM
📣 New Podcast! "Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware" on @Spreaker #bluemoon #browsersecurity #chromesecurity #cleangulp #cyberattack #cyberespionage #cybersecuritynews #cyberthreats #googlechrome #hacking #infosec #malware #microsoftwindows #osint
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
https://www.osintinvestigate.com A Chinese-linked threat actor known as UTA0565 has been observed exploiting a Chrome-Windows zero-day chain to deliver CLEANGULP malware. The attacks, detected on September 3 and 4, 2026, combined two Google Chrome vulnerabilities and a Windows ALPC flaw to escape the browser sandbox and achieve remote code execution. The campaign used phishing emails, fake websites, hidden iframes, and impersonated media organizations and NGOs to deceive targeted victims. In this episode, we examine how the BlueMoon exploit chain was used, how CLEANGULP operates, and why the reuse of the same exploit kit across multiple threat actors is attracting attention from cybersecurity researchers.
www.spreaker.com
September 23, 2026 at 2:00 PM
🤖 Chinese threat actor UTA0565 chained Chrome (CVE-2026-85046, CVE-2026-87491) and Windows ALPC (CVE-2026-85880) zero-days via fake sites to deploy CLEANGULP malware.
https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html
September 23, 2026 at 11:16 AM
Researchers spotted Chinese threat actors chaining two Chrome zero-days with a Windows ALPC vulnerability to execute CLEANGULP malware.

When state-backed groups share weaponized exploit kits, basic endpoint protection isn't enough to keep attackers out.
Chinese Hackers Weaponize Chrome-Windows Zero-Day Chain to Deliver CLEANGULP Malware
Chinese hackers used a combined Chrome and Windows zero-day chain to execute remote code.
zubiqo.com
September 23, 2026 at 8:55 AM
Je peux coder des mots anglais avec la LfPC en découpant bien. Il existe le cued speech qui est le même code mais pour la langue anglaise (c'est le premier code a avoir été créé).
alpc.asso.fr/le-cued-spee...
Le Cued Speech, une aide pour les enfants sourds francophones - ALPC
Aujourd’hui de plus en plus d’enfants sourds se trouvent dans la nécessité d’apprendre la langue anglaise, comme leurs petits camarades entendants.Michel FRANÇOIS, parent de deux enfants sourds et pro...
alpc.asso.fr
September 22, 2026 at 4:39 PM
A local Windows bug lets any user smuggle args into WerFault.exe and pop a SYSTEM token via ALPC. https://intel.threadlinqs.com/threat/TL-2026-2479 #ThreatIntel #CVE_2026_20817 #Windows10 #itm4n
September 13, 2026 at 5:27 PM
The Sept Microsoft advisory spans Windows, Office, Azure, Entra ID, SQL Server, Exchange & more, with multiple Critical vulnerabilities and CVSS scores reaching 10.0. One Windows ALPC vulnerability is also flagged as exploited.

Read more - www.sequretek.com/resources/re...
September 10, 2026 at 6:15 AM
BlueMoon exploit kit chains Chrome V8 and Windows ALPC vulnerabilities to enable espionage-driven compromise via phishing and actor-controlled URLs.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 9, 2026 at 7:54 PM
BlueMoon exploit kit chains Chrome V8 and Windows ALPC vulnerabilities to enable espionage-driven compromise via phishing and actor-controlled URLs.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 9, 2026 at 7:52 PM
BlueMoon exploit kit chains Chrome V8 and Windows ALPC vulnerabilities to enable espionage-driven compromise via phishing and actor-controlled URLs.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 9, 2026 at 7:52 PM
Proofpoint found four state-aligned groups running the same exploit kit within a week, starting with APT31 on 28 August. BlueMoon chains a Chromium V8 zero-day with CVE-2026-85880, the Windows ALPC flaw Microsoft patched Tuesday. therecord.media/china-ha...
Multiple Chinese hacking groups seen using identical Chrome zero-day exploit
Proofpoint says four state-aligned clusters adopted the BlueMoon exploit chain within a week.
therecord.media
September 9, 2026 at 5:49 PM
Microsoft, Windows 11’in Eylül Güncellemesinde Rekor Kırdı: 974 Güvenlik Açığı Kapatıldı!

Microsoft, Windows 11 kullanıcıları için yayımladığı eylül ayı güncellemesiyle toplam 974 güvenlik açığını kapattığını açıkladı. Kapatılan açıklar arasında en dikkat çekici olanı, sistemde hâlihazırda siber…
Microsoft, Windows 11’in Eylül Güncellemesinde Rekor Kırdı: 974 Güvenlik Açığı Kapatıldı!
Microsoft, Windows 11 kullanıcıları için yayımladığı eylül ayı güncellemesiyle toplam 974 güvenlik açığını kapattığını açıkladı. Kapatılan açıklar arasında en dikkat çekici olanı, sistemde hâlihazırda siber saldırı amacıyla kullanıldığı doğrulanan CVE-2026-85880 kodlu güvenlik açığı oldu. Düşük yetkili bir AppContainer ortamında kod çalıştırabilen saldırganların, Windows Gelişmiş Yerel Prosedür Çağrısı (ALPC) üzerindeki yığın bellek taşmasından yararlanarak korumalı alandan kaçmasına imkân tanıyan bu açık, yetkilerin doğrudan "SYSTEM" seviyesine çıkarılmasına yol açıyordu.
ercanceviz.com.tr
September 9, 2026 at 4:35 PM
CVE-2026-85880 is trending. Hype score 7, currently #8 on cvemon.

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

https://cvemon.intruder.io/cves/CVE-2026-85880
September 9, 2026 at 2:39 PM
⚠️ CVE-2026-81963 and CVE-2026-85880 are already under active attack.

Both are Windows privilege-escalation flaws that can help an attacker gain SYSTEM-level control after obtaining an initial foothold.

#CVE #Windows #InfoSec
September 9, 2026 at 12:16 PM
Като част от ежемесечната си инициатива Patch Tuesday, Microsoft отстрани рекордните 974 уязвимости в своите софтуерни продукти, включително две от типа „нулев ден“, които са били експлоатирани в реални условия...
Microsoft отстрани рекордните 974 уязвимости в софтуерните си продукти
Като част от ежемесечната си инициатива Patch Tuesday, Microsoft отстрани рекордните 974 уязвимости в своите софтуерни продукти, включително две от типа „нулев ден“, които са били експлоатирани в реални условия. Първата експлоатирана уязвимост от типа „нулев ден“, CVE-2026-85880 представлява проблем с препълване на буфера в Windows Advanced Local Procedure Call (ALPC), който би могъл да позволи на локален атакуващ да придобие системни привилегии. Втората уязвимост от типа „нулев ден“, CVE-2026-81963 представлява дефект при неправилно разрешаване на връзки преди достъп до файлове („следване на връзки“) в Windows Update Stack – компонентите, използвани за инсталиране на актуализации на Windows.
www.kaldata.com
September 9, 2026 at 7:53 AM
999 CVEs, biggest MS patch drop ever - 3 zero-days exploited. Patch ALPC, Update Stack, V8. https://intel.threadlinqs.com/threat/TL-2026-2407 #ThreatIntel #CVE_2026_85880 #CVE_2026_81963 #September
September 9, 2026 at 12:39 AM
Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two actively exploited zero-days in Windows Update Stack and Windows ALPC. Updates span Windows, Office, SQL Server, Exchange, Azure, and Edge. #Microsoft #WindowsUpdate
Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-days
Microsoft's September 2026 Patch Tuesday is its largest ever, fixing 966 flaws and two actively exploited zero-days, CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC. The update spans major products including Windows, Office, SQL Server, Exchange Server, Entra ID, Azure services, and Microsoft Edge, with 105 Critical vulnerabilities addressed overall. #WindowsUpdateStack #WindowsALPC #EntraID #MicrosoftExchangeServer #MicrosoftOffice #SQLServer #MicrosoftEdge
www.hendryadrian.com
September 8, 2026 at 11:15 PM
Microsoft patches a record 974 CVEs, including two exploited zero-days in Windows ALPC and Windows Update Stack that can grant SYSTEM privileges, plus critical fixes for Exchange, SharePoint, SQL Server, and RDS. #Windows #PatchTuesday #Microsoft
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft’s September 2026 Patch Tuesday addresses a record 974 CVEs, including two zero-days in Windows ALPC and the Windows Update Stack that can let local attackers gain SYSTEM privileges. The update also fixes major flaws in Exchange Server, SharePoint, SQL Server, Remote Desktop Services, and other Microsoft products, with several issues...
www.hendryadrian.com
September 8, 2026 at 10:15 PM
🛑 CVE-2026-85880
Microsoft Windows
CVSS 7.8 / KEV: No
TL;DR: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges loca…
https://cvesentinel.com/report/CVE-2026-85880?utm_source=bluesky&utm_medium=social&utm_campaign=cvesentinel
#infosec #CVE #vulnerability
September 8, 2026 at 6:50 PM
Microsoft's September Patch Tuesday fixes 973 CVEs, its largest ever, and two are Windows zero-days already under attack, both local privilege escalation at CVSS 7.8: CVE-2026-85880 in ALPC and CVE-2026-81963 in the Windows Update stack. cybersecuritynews.com/mi...
Microsoft Patch Tuesday September 2026: 973 vulnerabilities fixed, including 2 zero-days
Two actively exploited Windows elevation-of-privilege flaws among 973 Microsoft CVEs.
cybersecuritynews.com
September 8, 2026 at 6:19 PM
New WTA episode is out! We discuss Tokyo: The Last Megalopolis or Teito Monogatari or…you get the picture! We had the fine folks at Ultra Queue as guests, which means this episode is jam-packed with thoughtful discussion! Please give it a watch or listen!!! bsky.app/profile/alpc...
Hey, I do a toku podcast w/ @spiderslash.bsky.social and @rbpstix.bsky.social. We had the @ultraqueue.bsky.social crew on to talk Teito Monogatari, an 80s SFX Japanese blockbuster directed by Ultraman alum Jissoji! It stars a historically accurate robot that fights gremlins. youtu.be/aRxvgQ5PwK4?...
What'cha Toku-ing About Episode 21: Doomed Megalopolis: The Last Megalopolis ft. @UltraQueue
YouTube video by What'cha Toku-ing About
youtu.be
August 24, 2026 at 9:24 PM
Las medidas en la academia están, el problema es después, muchos acaban siendo auténticos nazis, es salir de la academia y listo, necesitan un seguimiento psicológico rutinario, ahí está lo mollar del tema…y si deja de estar apto para el servicio ALPC…
August 16, 2026 at 11:04 AM
Pues esa misma entrevista una al año desde un gabinete externo y rotatorio, veríamos desfilar a muchos ALPC…
August 14, 2026 at 6:22 AM