CVE-2026-85880

Published Sep 8, 2026

Last updated 5 hours ago

Overview

Description
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Exploit added on
Sep 8, 2026
Exploit action due
Sep 22, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-122

Social media

Hype score
Not currently trending
  1. 🔥 CyberForge CVE of the Day #047 🚨 CVE-2026-85880 — Windows ALPC AppContainer Escape to SYSTEM Imagine hostile code locked inside a low-privilege Windows AppContainer. The sandbox restricts its token and the resources it can reach. Then the process reaches Windows ALPC

    @lee1981b

    9 Sept 2026

    192 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Patch Tuesday September 2026: Microsoft fixed 974 CVEs, including two vulnerabilities exploited as zero-days (CVE-2026-85880 and CVE-2026-81963) https://t.co/jPeMod7ljD https://t.co/emjI691xA8

    @StetsonCG

    9 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Microsoft patched 966 CVEs yesterday, a record. Two exploited, both local EoP (ALPC CVE-2026-85880, Update Stack CVE-2026-81963): foothold to SYSTEM. Those first, every endpoint. Then DNS Server CVE-2026-69730 (9.8) on DCs. AI found the haystack. Triage is still yours. https://t.

    @vkhoetsyan

    9 Sept 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Microsoft'un Eylül 2026 Salı yaması rekor kırdı: 974 CVE, bunlardan 2'si (CVE-2026-81963 & CVE-2026-85880) aktif istismar ediliyor. İkisi de SYSTEM yetkisine yükseltme sağlıyor. Sistemlerinizi hemen güncelleyin. #PatchTuesday #CyberSecurity #cvealert

    @mcsudann

    9 Sept 2026

    58 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 2 Windows zero-days are being actively exploited in the wild right now (CVE-2026-85880 and CVE-2026-81963). Both allow local sandbox escape to SYSTEM privileges without user interaction. Patch your systems immediately.

    @TirupMehta

    9 Sept 2026

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Microsoft's Patch Tuesday disclosed 973 bugs, including two actively exploited flaws, CVE-2026-81963 and CVE-2026-85880. CISA says federal agencies must patch by Sept. 22. #Microsoft #Windows #CISA https://t.co/IuFLIf5420

    @TweetThreatNews

    9 Sept 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-85880: Microsoft Windows ALPC Heap Overflow Enables Local Privilege Escalation Microsoft has addressed CVE-2026-85880, a high-severity ALPC heap buffer overflow allowing local attackers to… Full write-up → link in bio #cybersecurity #infosec #cve #kev #microsoft ht

    @HotaSamit

    9 Sept 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Microsoft、2026年9月Patch Tuesdayでサイバー攻撃への悪用済み ゼロデイ 脆弱性 2件を修正 CVE-2026-81963・CVE-2026-85880 https://t.co/h0hwoiWqjf #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    @securityLab_jp

    8 Sept 2026

    163 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. マイクロソフトの定例更新。過去最高の脆弱性974件が修正。Windowsで723件、Officeで222件。ゼロデイはWindows ALPCのCVE-2026-85880とWindows Update StackのCVE-2026-81963。 https://t.co/vpzzxfM6ym 要注意なのはCVE-2026-55007(Exchange Server

    @__kokumoto

    8 Sept 2026

    758 Impressions

    2 Retweets

    2 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  10. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - Adobe Commerce/Magento: CVE-2026-75650(対処期限3日) - Windows: CVE-2026-81963, CVE-2026-85880 - N-able N-central: CVE

    @__kokumoto

    8 Sept 2026

    680 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Microsoft's September Patch Tuesday fixes two actively exploited Windows privilege-escalation zero-days: CVE-2026-81963 in Windows Update Stack and CVE-2026-85880 in Windows ALPC. #Cybersecurity #PatchTuesday https://t.co/U7kHsDzlaz

    @Divinmentis

    8 Sept 2026

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880) https://t.co/LNs1nBSmWN https://t.co/7JHLuLIrln

    @TechMash365

    8 Sept 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Microsoft’s September Patch Tuesday is a monster drop — reports put it near a record ~974 CVEs across the catalog, with two actively exploited local EoP zero-days: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Update Stack (both path to SYSTEM). Windows 11 cumulat

    @sabatage

    8 Sept 2026

    279 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Microsoft September 2026 Patch Tuesday fixes a record 966 flaws, including two exploited zero-days: CVE-2026-81963 (Windows Update Stack EoP to SYSTEM) and CVE-2026-85880 (Windows ALPC EoP to SYSTEM). 105 Critical, 81 of them RCE. Microsoft ties the volume jump to AI-powered

    @XavierRiveraX

    8 Sept 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. News: Microsoft Sep 2026 Patch Tuesday is its largest ever: 966 flaws and 2 actively exploited zero-days. CVE-2026-81963 (Update Stack EoP to SYSTEM) and CVE-2026-85880 (ALPC EoP to SYSTEM). Patch Windows now. https://t.co/5jlF58ibty

    @snakeyesV1

    8 Sept 2026

    117 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Microsoft's September Patch Tuesday fixes 973 CVEs, its largest ever, and two are Windows zero-days already under attack, both local privilege escalation at CVSS 7.8: CVE-2026-85880 in ALPC and CVE-2026-81963 in the Windows Update stack. https://t.co/QIZVcgobE7

    @ITr0ckstar

    8 Sept 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild. #PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement https://t.co/zwhv2ceQpe

    @Daily_CyberSec

    8 Sept 2026

    331 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations