Nearly a thousand fixes landed in a single Tuesday, and the two that matter most are the ones an attacker can use to finish a job they already started.
The two flaws being exploited right now
CVE-2026-81963 is an elevation of privilege bug in the Windows Update Stack, caused by improper link resolution: an attacker who already has a foothold can manipulate how the update process follows file links to gain SYSTEM privileges. CVE-2026-85880 sits in Windows Advanced Local Procedure Call (ALPC) and combines a heap-based buffer overflow with use of an uninitialised resource. Microsoft confirms both are being actively exploited, and both are credited to Romain Deperne and the Microsoft Threat Intelligence Center, the team that typically gets called in once a real campaign is already underway.
Neither flaw lets an attacker in from the outside on its own. Both need local code execution first, from a phishing payload, a malicious attachment, or a compromised low-privilege process. CVE-2026-85880 is particularly relevant if your endpoints run sandboxed applications: it lets an attacker already running inside a low-privilege AppContainer escape the sandbox entirely and reach SYSTEM. That is precisely the kind of second step a modern initial-access chain relies on, and it is exactly what most detection stacks are worst at catching, because the first step often looks unremarkable on its own.
The other 971 are not optional either
Of the 973 CVEs Microsoft rated with severity this month, 113 are Critical, and the majority of those critical bugs are remote code execution flaws. SharePoint Server accounts for 16 of the fixes and Exchange Server for 9, both platforms that sit on the public internet at a large share of European organisations and both frequent targets once a patch cycle passes and unpatched instances stand out to attackers scanning for them. A release this size, arriving as the single largest Patch Tuesday on record, cannot be tested and rolled out on a normal weekly cadence without something slipping through unreviewed.
What to prioritise this week
Patch CVE-2026-81963 and CVE-2026-85880 first, on every endpoint capable of running untrusted code or third-party applications, since that is the population most exposed to a chained attack. Move SharePoint and Exchange server patches to the front of the queue next, given their internet-facing footprint. Everything else in the 973 should still get triaged and scheduled, but not at the cost of delaying the flaws already in active use.
If your team needs help cutting a list this size down to an executable plan, confirming exposure to either zero-day, or building a patch cadence that survives a month like this one, contact Excello Digital. We help European IT teams turn an overwhelming CVE list into a prioritised rollout instead of a spreadsheet nobody finishes.
