CVE-2026-85880
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Description
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-85880 is a Windows security flaw that lets an attacker who can run code locally gain higher privileges; most small businesses should treat this as urgent because it’s confirmed in the U.S. CISA known-exploited list.
CVE-2026-85880 is a Windows ALPC (Advanced Local Procedure Call) local elevation of privilege vulnerability (CWE-122, CWE-908) where an authorized attacker can trigger a memory corruption condition to gain higher privileges; it is listed in CISA KEV with a 2026-09-22 remediation due date.
What to do now
- Check your Windows versions (Windows 10 and Windows Server releases listed in this report) and whether the installed build is already at or above the fixed versions for CVE-2026-85880.
- If you are on Windows 10, upgrade to 10.0.14393.9512 or 10.0.17763.9245 or 10.0.19044.7725 or 10.0.19045.7725.
- If you are on Windows Server, upgrade to the matching fixed version for your release: Windows Server 2012 (6.2.9200.26349), Windows Server 2012 R2 (6.3.9600.23397), Windows Server 2016 (10.0.14393.9512), Windows Server 2019 (10.0.17763.9245), or Windows Server 2022 (10.0.20348.5622).
- If you cannot patch within the required window, follow Microsoft/CISA mitigation guidance from the vendor security advisory and CISA KEV instructions, or discontinue use of the affected product if mitigations are unavailable.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkitsen·The Hacker News·
- 14th September – Threat Intelligence Reporten-us·Check Point Research· Exploited IDScan.net ShinyHunters
- BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Daysen-us·SecurityWeek· Exploited Google Chrome Violet Typhoon
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Weeken·The Hacker News· Exploited Google Chrome APT31
- Microsoft выпустила патчи для почти 1000 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows patch-tuesday
- September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successoren-us·Help Net Security· Exploited Windows Update Stack patch-tuesday
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Daysen·The Hacker News· Exploited Windows zero-day
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft Plugs Nearly 1,000 Security Holes – Krebs on Securityen-us·Krebs on Security· Exploited Windows zero-day
- Patch Tuesday Sets Another Record With 974 CVEsen·Dark Reading· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-85880 and every CVE in our database. Create a free account — no credit card required.
Create Free Account