important2 findings, 11 signals, 6 noted5 min read

Attackers are exploiting a Windows ALPC sandbox escape to SYSTEM; researchers also demonstrated account takeover from an unanswered WeChat call, and a crafted message can execute code through Outlook’s Reading Pane.

Containment, an unanswered ring and passive mail preview can each now end in attacker code execution or SYSTEM.

Priority findings2
01
High
Privilege — Windows
Confirmed
CVE-2026-85880

Attackers are exploiting a Windows ALPC heap overflow to escape low-privilege sandboxes and reach SYSTEM.

Existing AppContainer execution is enough to reach the vulnerable path.

Affects

Supported Microsoft Windows client and server systems using the built-in ALPC inter-process communication mechanism.

What it enables

Local sandbox escape and SYSTEM privilege escalation

Attacker obtains low-privilege or AppContainer code executionCrafted ALPC activity triggers a heap-based buffer overflowExecution crosses the AppContainer or user boundaryAttacker reaches SYSTEM privileges
Why this matters

The broken boundary is containment itself: code that was already restricted can cross the user or AppContainer boundary and become SYSTEM, and exploitation is active.

Detail and 5 sources
Required access

Existing low-privilege code execution, including execution inside an AppContainer sandbox

Affected versions

Supported Windows client and server releases identified in Microsoft's September 2026 advisory, Windows 10 version 1607 before build 14393.9512, Windows 10 version 1809 before build 17763.9245, Windows 10 version 21H2 before build 19044.7725, Windows 10 version 22H2 before build 19045.7725, Windows Server 2012 before build 9200.26349, Windows Server 2012 R2 before build 9600.23397, Windows Server 2016 before build 14393.9512, Windows Server 2019 before build 17763.9245, Windows Server 2022 before build 20348.5622

An attacker begins with low-privilege or AppContainer code execution, triggers the heap overflow with crafted ALPC activity and crosses into SYSTEM.

A fix is published and reaches end-of-life hardware. We do not know whether pre-fix images remain accepted or whether revocation is complete.

Evidence
Microsoft marked exploitation detectedCrowdStrike documented the AppContainer-to-SYSTEM path and heap-overflow primitivePublic proof of concept or incident artifacts
Share this finding
02
High
Zero-click — WeChat
Confirmed

An incoming WeChat call from an existing contact can execute code and take over the recipient’s account without being answered.

The phone only has to ring; an existing contact is the gate.

Affects

WeChat, Tencent’s messaging and calling application on Android and iOS.

What it enables

Zero-click WeChat account takeover and contact-to-contact worm propagation

Control a WeChat account already listed in the victim’s contactsPlace a WeChat call to the victimThe recipient’s VoIP stack processes attacker-controlled data while the phone is ringingMemory corruption yields code execution inside WeChatRead and send messages, place calls as the victim and call further contacts to repeat the chain
Why this matters

A caller already trusted as a contact can turn one compromised account into the next calling point without action from the recipient.

Detail and 3 sources
Required access

An attacker-controlled WeChat account already present in the victim’s contacts, with internet reachability to place a call

Affected versions

WeChat 8.0.76 for Android (tested), WeChat 8.0.75 for iOS (tested), WeChat 8.0.76 for Android (demonstrated), WeChat 8.0.75 for iOS (demonstrated)

Proof of concept

Demonstrated by the researcher

While the phone rings, WeChat processes attacker-controlled VoIP data. Memory corruption yields application-context code execution, including the ability to read and send messages and place calls as the victim.

Researchers demonstrated the chain from a Pixel to an iPhone and onward to another Pixel without either call being answered. Tencent confirmed the finding and deployed client and server mitigations.

Mitigation coverage reaches end-of-life hardware, but pre-fix image acceptance and revocation completeness remain unresolved.

Evidence
Calif demonstrated propagation from a Pixel to an iPhone and back to another Pixel without answering either callTencent confirmed the remote-code-execution finding and deployed client and server mitigationsPublic exploit source or a trigger artifact is available
Share this finding
Signals11
important · Privilege — Windows Update

Attackers are exploiting Windows Update Stack link following to turn a standard local foothold into SYSTEM.

Affects

Microsoft Windows 11 and Windows Server 2025, desktop and server operating systems.

Low-privilege code on an affected Windows 11 or Windows Server 2025 host can arrange a link condition that redirects the updater’s privileged file access and yields SYSTEM.

Detail and 5 sources
important · Wi-Fi — Android

A nearby Wi-Fi peer can execute code in Android’s Wi-Fi component without user interaction.

Affects

Android phones and other Android devices using the platform wpa_supplicant Wi-Fi Direct implementation.

A crafted Wi-Fi Direct provisioning-discovery bootstrap request reaches p2p_process_prov_disc_bootstrap_req(), causes a heap out-of-bounds write and can execute code in the Wi-Fi component.

Detail and 2 sources

Google published per-branch fixes and affected ranges. We do not know whether old images remain accepted, revocation is complete or end-of-life devices are covered.

important · Bluetooth — Android

A nearby Bluetooth peer can reach code execution in Android’s Bluetooth process without user interaction.

Affects

Android's system Bluetooth stack on phones, tablets and other Android devices

Crafted SDP data reaches heap-buffer overflows in Android’s request-processing and attribute-building paths, which Google classifies as no-interaction remote code execution.

Detail and 2 sources

Bluetooth radio reachability is required, but we do not know whether the attacker must first pair or establish a connection. Android OSV provides per-version fixes.

This remains Secondary because the published fix was not read for this brief.

important · Bluetooth — Pairing

A nearby Bluetooth peer can make Android skip pairing without user consent.

Affects

Android's system Bluetooth service on phones, tablets and other Android devices

A logic error in AdapterService.handleBondStateChanged lets a bond-state transition bypass pairing consent and produce remote privilege escalation without interaction.

Detail and 2 sources

Radio reachability is required, but the initiating state and precise transport are not public. The September 5 patch level addresses the affected Android families.

important · Edge — SAP Cluster

An unauthenticated SAP Message Server caller can become a trusted cluster node and execute code across every application server.

Affects

SAP NetWeaver Message Server on ABAP systems using affected 9.x kernels, including S/4HANA and S/4HANA Cloud Private Edition deployments.

A crafted registration packet sent to public port 36NN makes the Message Server trust an attacker-controlled address as an internal application-server component.

Detail and 2 sources

That trust propagates across the cluster, allowing the attacker to reach SAP Gateways, invoke RFC-callable external programs and execute commands as the SAP operating-system administrator.

important · Edge — SAP Kernel

A client-controlled SAP tracing passport can execute operating-system commands before authentication.

Affects

SAP kernel-based business systems, including SAP S/4HANA, ERP/ECC, NetWeaver AS ABAP, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO and Solution Manager.

Affected HTTP(S), SAP GUI and RFC listeners pass a client-supplied Extended Passport into shared kernel code before authentication and authorization checks.

Detail and 3 sources

A crafted passport can take control of the receiving process and run operating-system commands as the SAP installation owner.

important · Boot chain — Cisco UCS

A low-privilege Cisco account or physical console access can turn an embedded UCS UEFI shell into a Secure Boot bypass.

Affects

Cisco UCS servers and UCS-based compute, security, management, analytics, and network-edge appliances running vulnerable BIOS or firmware releases with UEFI Secure Boot enabled.

A user with KVM credentials, or anyone at the physical console, can enter the embedded shell and use its memory-write commands to overwrite Secure Boot-related values.

Detail and 5 sources
important · Physical — Windows RNDIS

Unauthenticated RNDIS traffic can execute code across supported Windows releases, but the physical-versus-routed boundary is undisclosed.

Affects

Supported Windows desktop and server releases implementing RNDIS, Microsoft's network-device protocol commonly associated with USB peripherals and tethering.

Malformed input reaching an active RNDIS interface can trigger a heap overflow and execute code on the Windows host.

Detail and 2 sources

We do not know whether the cheapest attacker position is a routed peer, a LAN peer or a malicious attached or tethered device.

Chain to watch
Reach an active Windows RNDIS interface without authenticationSend malformed RNDIS input that triggers the heap overflowExecute code on the Windows hostThe public record does not establish whether delivery is routed, local-network or attached-device access.
Unverified chainRead a detailed MSRC or CSAF record or diff the fixed RNDIS driver, then test routed and attached delivery separately.
important · Cellular — Tozed Router

A rogue LTE base station can make Tozed X300 routers execute shell commands as root.

Affects

Tozed ZLT X300 and X300A 5G CPE routers, cellular gateways running an aarch64 OpenWrt-derived firmware.

After a router attaches to the rogue cellular network, the attacker can impersonate the carrier’s TR-069 server and supply IPPingDiagnostics.Host.

Detail and 2 sources

netcwmpd inserts that value into a command passed to system_by_root() without validation, producing uid 0 shell execution. The researcher reproduced the chain on owned hardware and a private LTE network.

No patch is available.

important · Mobile — Android Kernel

Android classifies a TIPC fragment-reassembly double-free as no-interaction remote kernel code execution, but stock-handset reachability remains unknown.

Affects

Android kernels containing the vulnerable Linux TIPC fragment-reassembly implementation.

Attacker-controlled fragments delivered to an enabled TIPC transport can leave a stale skb pointer that is freed twice after validation fails.

Detail and 3 sources

Google classifies the result as no-interaction kernel code execution, but no cited source establishes a reachable TIPC bearer on a factory-stock handset.

Chain to watch
Deliver attacker-controlled fragments to an enabled Android TIPC transportTrigger the fragment-reassembly double-freeReach kernel code executionA stock-handset transport and attacker-reachable bearer have not been established.
Unverified chainAudit shipping OEM kernel configurations and bearer setup, then reproduce delivery on a bootloader-locked handset.

This remains Secondary because the published fix was not read for this brief.

important · Zero-click — Email

A crafted email rendered in Outlook’s Reading Pane can execute code without a click.

Affects

Microsoft Outlook and related Office installations on Windows and macOS, including Microsoft 365 Apps and perpetual Office releases.

Outlook automatically processes the message in its Reading Pane, where a heap-based buffer overflow can produce code execution with the logged-on user’s privileges.

Detail and 5 sources
Also noted6
Bluetooth — Android
A Bluetooth peer can make current Android releases accept an encryption downgrade and disclose information.
The required bond state, downgraded algorithms and recoverable information remain unknown; the fix was not read.
ResearchOSV - Open Source Vulnerabilities
Wi-Fi — Android
Nearby EHT operation data can drive Android’s channel-width parser into an out-of-bounds read.
The record establishes process-adjacent disclosure but does not describe the extraction channel; the fix was not read.
ResearchOSV - Open Source Vulnerabilities
Boot chain — GIGABYTE
Root can preserve a redundant embedded-shell boot entry and use it to bypass Secure Boot on affected GIGABYTE motherboards.
The path begins after operating-system root compromise, and the published fix was not read.
VendorSecurity Advisory — Secure Boot Bypass via AMI Aptio UEFI BDS Module | Security & Technical Advisory - GIGABYTE Global
Physical — Siemens Relay
A boot-time physical key sequence lets a Siemens Reyrolle relay download and run unsigned network-supplied code.
The signed-code boundary fails, but exploitation requires physical access during boot and a reachable network server; the fix was not read.
Researchhttps://tenable.com/cve/CVE-2026-62654
Boot chain — Insyde
A subset of Insyde-based firmware may leave an embedded UEFI shell reachable despite Secure Boot.
Affected OEMs, models, builds and shipped fixes are not public.
ResearchCisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability - Cisco
Physical — CareCam
A hard-coded U-Boot credential lets a physical attacker rewrite firmware on one CareCam Pro model.
The path is unpatched but requires physical access to the camera.
Researchhttps://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-251-01.json
What was checked · 2 quiet
Edge devicesQuiet

SAP cluster trust injection, shared-kernel pre-authentication execution and ScreenConnect participant-role bypass changed reachable edge paths.

ResearchQuiet

The strongest research-backed changes were the WeChat call chain, the ALPC sandbox escape and passive Outlook execution.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026