CVE-2026-69874
Windows ALPC Elevation of Privilege Vulnerability
Description
Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowThis is a Windows local privilege escalation bug (it helps someone who already has a legitimate way to run code on the machine gain higher privileges). If your business runs affected Windows versions, you should patch soon—especially on systems exposed to untrusted or semi-trusted users.
CVE-2026-69874 is a Windows ALPC local elevation of privilege due to an untrusted pointer dereference, where a local authorized attacker can exploit the ALPC mechanism to gain higher privileges on affected Windows 10/11 and Windows Server versions.
What to do now
- Check which devices run Windows 10/11 or Windows Server 2019/2022/2025 and identify their exact build versions.
- Verify whether your environment includes any users, devices, or services considered "authorized" to run code (for example, endpoints where untrusted staff, contractors, or third-party tools can execute code).
- Patch Windows to a fixed version: Windows 10 10.0.17763.9245 or 10.0.19044.7725 or 10.0.19045.7725; Windows 11 10.0.22631.7582 or 10.0.26100.9445 or 10.0.26200.9445 or 10.0.28000.2954; Windows Server 2019 10.0.17763.9245; Windows Server 2022 10.0.20348.5622; Windows Server 2025 10.0.26100.33438.
- After patching, confirm devices show the updated build and that Windows Update/servicing remains enabled so the fix stays applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69874 and every CVE in our database. Create a free account — no credit card required.
Create Free Account