Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Microsoft patched 964 CVEs in September, the most ever in a Patch Tuesday release in its history, including two zero-day vulnerabilities exploited in the wild.
https://www.infosecurity-magazine.com/news/microsoft-patch-tuesday-record/
https://www.helpnetsecurity.com/2026/09/09/september-2026-patch-tuesday-zero-days-sigred-successor/
https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html
https://cyberscoop.com/microsoft-patch-tuesday-september-2026/