HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Windows — Microsoft Windows Heap-Based Buffer Overflow Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

Analysis

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-08. Remediation due: 2026-09-22.

Indicators of Compromise (1)

CVE (1)
CVE-2026-85880
Source Attribution

Originally published by CISA KEV on Sep 8, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-78159 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut...

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it p

CVE-2026-78159
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-78006 — The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execut...

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attri

CVE-2026-78006
NIST NVD
MEDIUMVulnerability

Cylake Gets $245M to Build Cloud-Free Cybersecurity Platform

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cylake-gets-245m-to-build-cloud-free-cybersecurity-platform-image_small-1-a-32807.jpg" align=right hspace=4><b>Nir Zuk's Startup Targets Firms Unable to Send Sensitive Security Data to the Cloud</b><br>Cylake, led by Palo Alto Networks founder Nir Zuk, raised $245 million to build an on-premises cybersecurity system combining hard

Bank Info Security