Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: wormable (2 articles)Clear

Microsoft's record Patch Tuesday fixes 974 flaws and two exploited Windows zero-days

Microsoft shipped its largest-ever Patch Tuesday, fixing a record 974 vulnerabilities, including two Windows zero-days already exploited in attacks. Both zero-days are local privilege-escalation flaws that let an attacker gain SYSTEM access: CVE-2026-85880 is a heap buffer overflow in the Advanced Local Procedure Call component that can let code in a low-privilege sandbox escape and elevate, and CVE-2026-81963 is a link-following flaw in the Windows Update Stack. The release also includes about 20 potentially wormable flaws, remotely exploitable without authentication, across services like DNS, DHCP, SMB, and Active Directory, plus critical fixes in Exchange, SharePoint, SQL Server, and Kerberos. The sheer volume makes prioritization essential.

Check
Prioritize the two exploited zero-days and the roughly 20 wormable, internet-facing flaws in this month's update, deploying them first, then work through the rest based on exposure and asset criticality.
Affected
Windows and Microsoft server environments across the board (CVE-2026-85880, CVE-2026-81963, and others); the exploited zero-days give local attackers SYSTEM privileges, while wormable flaws in core network services could spread remotely without authentication.
Fix
Apply the September updates promptly, patching exploited and wormable issues first, watch for privilege-escalation activity these flaws enable when chained with initial access, and test large rollouts given the release size.

Bluetooth flaw gives root on Unitree humanoid robots and can spread between them

A researcher disclosed two root remote code execution chains in the Unitree G1 humanoid robot, one reachable over Bluetooth from nearby without any pairing. Tracked as CVE-2026-76639 and CVE-2026-76640, the Bluetooth chain abuses a gap in Unitree's cloud service, which handed over another robot's key material to any free account without checking ownership, then used a buffer overflow in the Wi-Fi provisioning code to run code as root on the robot's control computer. The researcher demonstrated that a compromised robot can spread the exploit to another within Bluetooth range, making it wormable. There is no confirmed fixed firmware for the on-robot flaws, though the cloud ownership check was tightened.

Check
Owners of Unitree G1 robots should watch for firmware updates addressing these flaws, keep the robots off untrusted networks, and be aware that a nearby compromised unit could attack others over Bluetooth.
Affected
Unitree G1 humanoid robots (CVE-2026-76639, CVE-2026-76640); an attacker within Bluetooth range can chain a cloud key-recovery gap and a buffer overflow to gain root, and the exploit can spread robot to robot.
Fix
Isolate robots on segmented networks, limit physical and radio proximity by untrusted parties, apply firmware fixes when a confirmed release appears, and treat cyber-physical devices as full computers requiring patching.