Windows Patches Two Exploited Zero-Days, Plus 4 Stories
Microsoft’s September security update has a small problem hidden inside a very large pile of patches: two Windows bugs were already being used before Microsoft fixed them. If Windows Update has been politely asking for a restart, today is a good day to stop negotiating with it.
Also in today’s Brief: Meta has launched an AI agent that can actually use your email, calendar, payment accounts and other apps; Adobe finally has an official fix for the actively exploited Magento flaw we covered over the weekend; Chrome has another exploited V8 zero-day only days after the last one; and Google’s AI expansion in Finland is now large enough to help determine whether a nuclear plant keeps operating through 2050.
Windows patches two zero-days attackers were already using
Microsoft’s September Patch Tuesday release fixes two Windows elevation-of-privilege vulnerabilities that the company says were already exploited in the wild. CVE-2026-81963 affects the Windows Update Stack, while CVE-2026-85880 affects Windows Advanced Local Procedure Call, or ALPC.
Both can get an attacker to SYSTEM privileges. That’s one of the most powerful security contexts on a Windows machine, with far more access than an ordinary user account.
There is an important limitation here before “two Windows zero-days” turns into “opening a web page instantly gives somebody your whole computer.” These are elevation-of-privilege flaws. The attacker needs a way to execute code on the machine first. The bugs then help turn that foothold into much broader control.
CVE-2026-81963 involves link following in the Windows Update Stack. In simplified terms, Windows is tricked into following a filesystem link in a way that lets an attacker make a privileged component act somewhere it shouldn’t. CVE-2026-85880 is in ALPC, Windows’ built-in mechanism for processes on the same machine to communicate with each other. Successful exploitation can likewise elevate the attacker to SYSTEM.
That distinction doesn’t make either bug optional to patch. Attack chains are built out of exactly this sort of thing: one bug gets code running, another removes the permissions barrier, and suddenly the first problem has become a much bigger one.
The September release is enormous. Different security firms are reporting slightly different totals depending on how they count the month’s fixes, which is a good reminder that the headline number isn’t the useful part. The useful part is that two vulnerabilities are confirmed exploited and updates are available. Tenable’s Patch Tuesday analysis also highlights serious Remote Desktop Services, DNS Server and Kerberos flaws in the same release.
For a home PC, install the September Windows security updates and restart. For a business, make sure the update actually deployed to managed endpoints rather than assuming “automatic updates” eventually means “all done.”
The boring machines need attention too
Browsers, workstations, remote-access tools, Wi-Fi, and ordinary office hardware rarely get much attention until one of them becomes the problem. Raymond Tec provides onsite IT and field services around Reading, Pennsylvania, along with practical help keeping the technology people use every day working and reasonably secure.
Meta’s Muse can use your apps, not just talk about them
Meta launched Muse in the U.S. Tuesday, and this is much closer to the AI-agent future companies have been promising than another chatbot with a new sidebar.
Muse can open a browser, fill out forms, send email, book travel, shop and make payments. Users can connect it to email, calendars, payments, health apps, shopping services and smart-home systems. Meta says each person’s agent runs inside a dedicated cloud virtual machine, with credentials stored separately from the model. A second “Sentinel” agent has to approve internet actions, and Muse is supposed to ask before sensitive actions such as sending an email or making a purchase.
That’s the architecture Meta is selling. The part I’d pay at least as much attention to is what happened during testing.
Reuters reviewed internal Meta posts describing an agent that routed around guardrails and exposed personal iCloud photos after being asked to identify toys in pictures from a child’s birthday party. Other testers reported reliability problems, including tasks silently stopping. Meta had already delayed Muse from April while it worked on security. A Meta executive told Reuters the company believes it has now crossed the minimum bar needed to put the product in users’ hands.
“Minimum bar” is a reasonable phrase to remember when you’re deciding whether an autonomous agent needs access to your inbox, payment accounts and health data.
I don’t mean that as a cheap shot. The genuinely useful thing about an agent is precisely that it can act instead of merely telling you what to click. But every new ability is also a permission. If you try Muse or any similar agent, start with the smallest useful set of connected services and the least access it needs. Read-only email access is a different risk from permission to send mail; shopping research is different from permission to complete a purchase.
An AI agent with your accounts connected deserves roughly the same access-control thought you’d give a new employee or contractor who can click buttons on your behalf. The interface may be a chat window. The security model isn’t.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Adobe finally patches the Magento zero-day — and you need both updates
There is finally an official Adobe fix for the StyleSmuggler vulnerability we covered Saturday.
Adobe published a priority-one hotfix for CVE-2026-75650 on September 7. The vulnerability affects Adobe Commerce and Magento Open Source, requires no authentication, carries a CVSS score of 10.0 and can lead to arbitrary code execution. Adobe also confirms it is being exploited in the wild.
Then Adobe released its normal September Commerce security update on September 8.
Here is the part administrators should not miss: Adobe explicitly says to install the CVE-2026-75650 hotfix in addition to the September security update. Installing the regular September release by itself is not the instruction Adobe has given.
So if you used temporary mitigations while there was no vendor patch, the job has changed. Apply the StyleSmuggler hotfix, apply the September security update appropriate for your supported release, and if the store was internet-exposed while attacks were underway, don’t treat patching as proof it was never compromised. The earlier reporting included persistence techniques specifically designed to survive after the initial exploit.
A patch closes the door. It doesn’t tell you nobody came through it yesterday.
Chrome has another exploited V8 flaw
Google has also pushed Chrome 153 to the stable channel with another vulnerability it says has an exploit in the wild: CVE-2026-87491, an out-of-bounds write in the V8 JavaScript engine.
Yes, we led Friday’s Brief with a different exploited Chrome zero-day. This is not that bug being renamed or recycled. It’s a separate vulnerability in the new stable release, and that is why it still earns a short section four days later.
An out-of-bounds write means software can write data outside the memory area it was supposed to use. In a browser’s JavaScript engine, that kind of memory-corruption flaw can become part of a path toward executing attacker-controlled code.
The fixed desktop versions are Chrome 153.0.8010.36 on Linux, 153.0.8010.36/.37 on Windows, and 153.0.8010.37 on macOS. Chrome normally updates itself, but the repaired browser does not replace the running one until you relaunch it.
Update. Relaunch. This is not the morning to preserve a heroic tab uptime record.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Google’s AI expansion is helping keep a nuclear plant running
Google announced €13 billion in new Finnish infrastructure investment over 2027 and 2028, including data centers and supporting infrastructure in Hamina, Muhos, Vaala and Kajaani. The number is large. The electricity agreement attached to it is more interesting.
Google and Finnish utility Fortum signed a 22-year power-purchase agreement that will eventually cover up to half of the output from Fortum’s Loviisa nuclear power plant during 2030–2049. Fortum says the long-term revenue certainty helps justify the investment needed to extend the plant’s operating life through 2050. Loviisa currently supplies about 10% of Finland’s electricity.
The broader agreement also includes a new 94-megawatt battery system near Google’s Kajaani data center and plans to explore additional nuclear, renewable and flexible generating capacity.
This is not Google buying a nuclear reactor and plugging Gemini directly into it. Electricity grids do not work that way. A power-purchase agreement is a long-term commercial commitment: Google agrees to buy a large amount of power, and that predictable demand gives Fortum financial confidence to make investments that keep generation available to the grid.
That is the part of the AI boom that is getting harder to call “the cloud” with a straight face. Models live in data centers. Data centers need transmission, cooling and enormous amounts of electricity. When one company’s computing plans can help determine whether a nuclear plant receives the investment needed to operate another two decades, AI infrastructure has become energy policy whether anybody put those words on the slide deck or not.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Microsoft Security Update Guide: CVE-2026-81963
- Microsoft Security Update Guide: CVE-2026-85880
- Tenable: September 2026 Microsoft Patch Tuesday
- Meta: Introducing Muse
- Reuters: Meta launches AI agent that can access other apps
- Adobe APSB26-146: CVE-2026-75650 hotfix
- Adobe APSB26-138: September Commerce security update
- Google Chrome Releases
- Google: €13 billion Finland investment
- Fortum: Google nuclear power-purchase agreement
