CVE-2026-85880, a CVSS 7.8 heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026. NVD’s vector shows a locally-exploitable flaw requiring low privileges and no user interaction, with high impact to confidentiality, integrity, and availability once triggered.
What the vulnerability does
NVD tracks CVE-2026-85880 under CWE-122 (Heap-Based Buffer Overflow) and CWE-908 (Use of Uninitialized Resource). Per NVD’s description, the flaw is a heap-based buffer overflow in Windows ALPC — the interprocess communication mechanism Windows components use internally — that allows an authorized (i.e., already locally logged-in) attacker to elevate privileges locally.
Why it’s on KEV
CISA’s September 8 KEV addition requires federal civilian agencies to remediate under BOD 26-04. Microsoft’s own advisory is available through the MSRC Update Guide, linked from NVD’s reference data.
What we don’t yet have
CVSS scoring and the vulnerability description trace to NVD alone in our pipeline; confidence on severity is marked medium pending a second independent source. We don’t have an EPSS score ingested for this CVE, and NVD’s data doesn’t specify which Windows versions or builds are affected beyond the general “Windows” product tag — administrators should confirm applicability against Microsoft’s own advisory for their specific build.
Why this matters
Because this is a local-privilege-escalation flaw rather than a remote one, it’s not exploitable on its own from outside a system — its real-world danger is as the second stage of an attack chain, turning an attacker’s initial low-privilege foothold (via phishing, a separate remote vulnerability, or a malicious insider) into full local control. CVE-2026-85880 was added to KEV the same day as CVE-2026-81963, a separate Windows local-privilege-escalation flaw — two distinct Windows elevation-of-privilege bugs landing on KEV simultaneously means attackers likely have working exploit chains that pair either with a remote initial-access vector, and both should be prioritized together in the same patch cycle.
Frequently Asked Questions
What is CVE-2026-85880? A CVSS 7.8 heap-based buffer overflow in the Windows ALPC subsystem that allows a locally-authenticated attacker to elevate privileges.
Is CVE-2026-85880 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 8, 2026.
What should Windows administrators do? Apply Microsoft’s fix per the MSRC Update Guide advisory for CVE-2026-85880, and prioritize alongside CVE-2026-81963, added to KEV the same day.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 10, 2026. See more vulnerability intelligence.