Microsoft's Record 973-CVE Patch Tuesday: Two SYSTEM-Level Zero-Days Under Attack
September 2026 is Microsoft's largest Patch Tuesday on record, and two of the fixes — both elevation-of-privilege bugs — are already being exploited to seize SYSTEM control on Windows machines.
PostgreSQL Patches 12-Year-Old Logical Decoding Flaw (CVE-2026-6471)
A missing authorization check in PostgreSQL's logical decoding, present since 2014, let any account with the REPLICATION attribute run arbitrary code as the database's OS user. Patches shipped August 13, 2026.
Certighost (CVE-2026-54121): Any Domain User Could Impersonate a Domain Controller
A public exploit shows how a certificate-enrollment fallback in AD CS let any authenticated domain user forge a Domain Controller identity and pull the krbtgt secret via DCSync.
GetProcessHandleFromHwnd: How One Windows API Enabled a Persistent UAC Bypass
Google Project Zero traces a public Quick Assist UAC bypass back to a poorly documented Win32 API that Microsoft only half-fixed in 2023 — and shows why fully protected processes stayed exploitable until Windows 11 24H2.