CVE-2026-85880

HIGH

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVSS v3.1 Score

7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Complexity
LOW
Privileges
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Published: 9/8/2026Modified: 9/9/2026

Related Intelligence (5)

CRITICALZero Day

Attackers are weaponizing the gap between Chromium fixes and Chrome patches

A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team , espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to allow them to launch targeted spear phishing campaigns. Proofpoint, which researched the new attack method along with G

CVE-2026-85046CVE-2026-87491
CSO Online
CRITICALZero Day

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release . The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer action. Excluded are 174 third-party/open-source CVEs and 23 Chromium/Edge CVEs, as well as nine Microsoft mitigated vulnerab

CVE-2026-85880CVE-2026-81963
CSO Online
MEDIUMVulnerability

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and d

CVE-2026-69730CVE-2026-69829
Krebs on Security
CRITICALRansomware

Patch Tuesday - September 2026

Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published

CVE-2026-85880CVE-2026-81963
Rapid7
HIGHVulnerability

CISA KEV: Microsoft Windows — Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

CVE-2026-85880Microsoft Windows
CISA KEV

References (2)