CISA added CVE-2026-85880, a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem, to the Known Exploited Vulnerabilities catalog on 2026-09-08, confirming active exploitation in the wild.
What Is It
A heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. Microsoft assigned the flaw CWE-122 (heap-based buffer overflow) and CWE-908 (use of uninitialized resource), with a CVSS 3.1 base score of 7.8 (HIGH) under the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
The vector is local, requires low privileges, and needs no user interaction; a standard post-compromise privilege escalation primitive. Impact is total across confidentiality, integrity, and availability.
Why It Matters
CISA's KEV listing confirms active exploitation. The agency's SSVC assessment scores the exploitation state as active, technical impact as total, and automatable as no: consistent with a local escalation step used after an attacker already has code execution on a host, rather than an internet-facing entry point. Known ransomware campaign use is listed as Unknown.
ALPC is a core Windows IPC mechanism, but the exposure here is bounded by the builds actually enumerated in the NVD record: Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2012 R2, 2016, 2019, and 2022. Windows 11 and Windows Server 2025 do not appear in that list. In enterprises still running a meaningful Windows 10 fleet or older server estate, that can still amount to a large share of endpoints and servers; environments standardized on Windows 11 and current server builds may have little or no exposure under the published affected-version data. Confirm against your own inventory rather than assuming universal coverage.
What's Vulnerable
Per the NVD record, affected builds include:
- Windows 10 1607 and Server 2016; before 10.0.14393.9512
- Windows 10 1809 and Server 2019; before 10.0.17763.9245
- Windows 10 21H2 and 22H2; before 10.0.19044.7725 / 10.0.19045.7725
- Windows Server 2012 and Server Core; before 6.2.9200.26349
- Windows Server 2012 R2 and Server Core; before 6.3.9600.23397
- Windows Server 2022: before 10.0.20348.5622
Affected platforms span 32-bit, x64, and ARM64 systems.
Patch Status
Patched builds are available from Microsoft; apply the vendor updates listed above. CISA set a remediation due date of 2026-09-22 and requires federal agencies to apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk). Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This entry is not flagged for forensic triage, so the additional triage steps in the BOD 26-04 implementation guidance do not apply here. Stakeholders are responsible for evaluating each asset's internet exposure.
Sources
- Microsoft MSRC Update Guide; https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85880
- NVD, CVE-2026-85880, https://nvd.nist.gov/vuln/detail/CVE-2026-85880
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk