← All news
ARTICLE
22 September 2026

Microsoft KEV zero-days due 2026-09-22 — MSP patch priority

DRAFT, defensive only. CISA KEV entries CVE-2026-81963 and CVE-2026-85880 were added 2026-09-08 and are due 2026-09-22. MSP checklist, no exploit/PoC.

Two Microsoft KEV entries, one MSP deadline

CISA lists CVE-2026-81963 (Windows Update Stack elevation of privilege) and CVE-2026-85880 (Windows ALPC elevation of privilege) as added 2026-09-08, with remediation due 2026-09-22. Prioritize managed Windows estates before tomorrow’s deadline.

Sources: CISA KEV catalog, MSRC 81963, MSRC 85880, and Tenable, 2026-09-08.

Use the KEV due date as an operational queue: identify exposed or business-critical Windows assets, stage the vendor updates, validate reboot and service health, then record exceptions with an owner and expiry. This draft avoids asserting CVSS values beyond the cited Tenable roundup.

# MSP defensive checklist — NO exploit / NO PoC
1. Export Windows estate inventory and map owners
2. Identify internet-facing and business-critical hosts
3. Apply vendor updates through approved change control
4. Validate reboot, services, monitoring and backup health
5. Record exceptions with owner, compensating control and expiry
6. Recheck KEV status and close evidence before 2026-09-22

Ban: no exploit, no PoC and no attack reproduction steps. Draft only.