Fetching from the wire…
Public story · 2026-09-09 · high
Two of the bugs are already being exploited and went straight into CISA's must-patch list the same day.
Why now: Microsoft shipped the update on September 9, 2026, and CISA added both exploited CVEs to its Known Exploited Vulnerabilities catalog the same day.
Microsoft's September patch batch covers roughly 972 vulnerabilities, the largest count the company has shipped in a single cycle. The exact number depends on who's counting: Microsoft's own release notes say 974, the Zero Day Initiative logged 972, BleepingComputer counted 966, and Tenable put it at 964. About 112 of them are rated critical, per Ars Technica.
The count discrepancy isn't a rounding error. Different vendors draw the boundary of "this patch" differently. That matters if you're reconciling your own vulnerability scanner's output against a headline number and it doesn't match.
What matters more than the total is which two bugs are already in the wild. CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack, and CVE-2026-85880, an elevation-of-privilege flaw in Windows ALPC, are both under active exploitation. CISA added both to its Known Exploited Vulnerabilities catalog on September 9, 2026, the day the patch went out. For federal agencies that starts a mandatory remediation clock. For everyone else it's the clearest signal in the pile about where to start.
With 112 critical bugs in one release, most teams can't triage all of them fast. Elevation-of-privilege bugs in core OS plumbing like the update stack and ALPC are especially bad because they turn a foothold into full control, and these two are confirmed exploited, not theoretical. Patch those two first, then work down by severity. The rest of the pile can wait a few days. These two can't.
Each link below shares sources, entities, or timing with this story.
CVE-2026-33017 is an unauthenticated RCE (CVSS ~9.8) in Langflow's public flow-build endpoint. Attackers weaponized it within 20 hours of disclosure, before any public PoC, by reverse-engineering the advisory text. Exploitation systematically exfiltrated OpenAI, Anthropic, and...
Microsoft's March 2026 Patch Tuesday (79 flaws, 2 zero-days) includes a Critical vulnerability where Excel's Copilot Agent mode silently exfiltrates data with zero user interaction. An attacker crafts a malicious document; when opened, the Copilot Agent triggers network egress...
The single biggest cross-agent story this week isn't one CVE. It's that MCP became the dominant agent-hijack surface, and this is the defense that actually stops it. The pattern across a dozen findings: Sentry's MCP server weaponized via fake error events for an 85% agent-hija...
OX Security disclosed a systemic vulnerability on June 16 in core Model Context Protocol implementations that enables arbitrary command execution, exposing API keys, internal databases, and chat histories on any vulnerable MCP host. This isn't one bad server. It's a protocol-l...
CVE-2026-27896 (MCP Go SDK): High-severity interpretation conflict in the *official* MCP Go SDK (maintained by Anthropic + Google). Go's encoding/json performs case-insensitive matching — attackers bypass WAFs by sending JSON-RPC messages with non-standard casing the SDK accep...
Windows Latest covered the September 5 post from Fowler, an 18-year Microsoft veteran who leads Aspire, arguing developers now own architecture, testing, performance and security review while agents produce code. Supporting numbers in the coverage: Nadella's 20-30% AI-written...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.