{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/skype-for-business/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*","cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*","cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-85880"},{"cvss":7.8,"id":"CVE-2026-81963"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows","Office 2016","SQL Server","SharePoint Server","Azure","Skype for Business","Exchange Server","Authenticator"],"_cs_severities":["critical"],"_cs_tags":["vulnerability-management","patch-tuesday","windows","privilege-escalation"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft's September 2026 Patch Tuesday release is a record-breaking update addressing 974 distinct vulnerabilities across its product ecosystem. Of critical concern are two zero-day vulnerabilities (CVE-2026-85880 and CVE-2026-81963) that are confirmed to be under active exploitation in the wild. Both flaws allow local attackers to escalate their privileges to System. Additionally, the release addresses 20 potentially wormable vulnerabilities that enable unauthenticated remote code execution (RCE) without user interaction, increasing the risk of widespread automated exploitation within enterprise networks.\u003c/p\u003e\n\u003cp\u003eThe update covers a wide range of products including Windows, Office (specifically 2016), SQL Server, SharePoint Server, Azure, Skype for Business, and Exchange Server. Security teams are advised to prioritize remediation based on reachability and exposure, specifically for the 20 wormable RCE flaws and the two actively exploited zero-days.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of the zero-day vulnerabilities allows local attackers to achieve System-level privilege escalation, granting full control over the compromised host. The 20 identified wormable vulnerabilities pose a significant threat to organizational integrity, as they allow for unauthenticated RCE, potentially facilitating the rapid spread of malware or ransomware across internal network segments without user intervention. The broad scope of affected products, including critical infrastructure components like Exchange and SharePoint, necessitates an urgent patching cadence to mitigate the elevated risk of unauthorized access and lateral movement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize immediate patching of the two exploited zero-days (CVE-2026-85880 and CVE-2026-81963) across all affected Windows endpoints.\u003c/li\u003e\n\u003cli\u003eReview the 20 identified wormable RCE vulnerabilities for systems that are internet-facing or have high network exposure and apply security updates as the highest priority.\u003c/li\u003e\n\u003cli\u003eApply the latest Servicing Stack Updates (SSU) to Windows Server 2012, 2012 R2, Windows 10 (1607), and Windows Server 2016 immediately to ensure system integrity.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual process escalation attempts or unexpected updates to the Windows Update Stack components that could indicate exploitation of CVE-2026-81963.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T20:04:20Z","date_published":"2026-09-08T20:04:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-microsoft-patch-tuesday/","summary":"Microsoft's September 2026 update cycle addresses 974 vulnerabilities, including two privilege-escalation zero-days actively exploited in the wild and 20 potentially wormable RCE flaws.","title":"Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days","url":"https://feed.craftedsignal.io/briefs/2026-09-microsoft-patch-tuesday/"}],"language":"en","title":"CraftedSignal Threat Feed - Skype for Business","version":"https://jsonfeed.org/version/1.1"}