Skip to main content
QUIETLYTIC
Vulnerability

Microsoft Windows Privilege Escalation (CVE-2026-85880)

CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC allowing local privilege escalation. Added to CISA KEV Sept. 8, 2026, the same day as CVE-2026-81963.

CVE-2026-85880
Threat Level
HIGH
CVSS
7.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Microsoft Windows

CVE-2026-85880, a CVSS 7.8 heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026. NVD’s vector shows a locally-exploitable flaw requiring low privileges and no user interaction, with high impact to confidentiality, integrity, and availability once triggered.

What the vulnerability does

NVD tracks CVE-2026-85880 under CWE-122 (Heap-Based Buffer Overflow) and CWE-908 (Use of Uninitialized Resource). Per NVD’s description, the flaw is a heap-based buffer overflow in Windows ALPC — the interprocess communication mechanism Windows components use internally — that allows an authorized (i.e., already locally logged-in) attacker to elevate privileges locally.

Why it’s on KEV

CISA’s September 8 KEV addition requires federal civilian agencies to remediate under BOD 26-04. Microsoft’s own advisory is available through the MSRC Update Guide, linked from NVD’s reference data.

What we don’t yet have

CVSS scoring and the vulnerability description trace to NVD alone in our pipeline; confidence on severity is marked medium pending a second independent source. We don’t have an EPSS score ingested for this CVE, and NVD’s data doesn’t specify which Windows versions or builds are affected beyond the general “Windows” product tag — administrators should confirm applicability against Microsoft’s own advisory for their specific build.

Why this matters

Because this is a local-privilege-escalation flaw rather than a remote one, it’s not exploitable on its own from outside a system — its real-world danger is as the second stage of an attack chain, turning an attacker’s initial low-privilege foothold (via phishing, a separate remote vulnerability, or a malicious insider) into full local control. CVE-2026-85880 was added to KEV the same day as CVE-2026-81963, a separate Windows local-privilege-escalation flaw — two distinct Windows elevation-of-privilege bugs landing on KEV simultaneously means attackers likely have working exploit chains that pair either with a remote initial-access vector, and both should be prioritized together in the same patch cycle.

Frequently Asked Questions

What is CVE-2026-85880? A CVSS 7.8 heap-based buffer overflow in the Windows ALPC subsystem that allows a locally-authenticated attacker to elevate privileges.

Is CVE-2026-85880 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 8, 2026.

What should Windows administrators do? Apply Microsoft’s fix per the MSRC Update Guide advisory for CVE-2026-85880, and prioritize alongside CVE-2026-81963, added to KEV the same day.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 10, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools