← Vulnerability feed

Vulnerability record · CVE-2026-85880 · published 8 September 2026

CVE-2026-85880: Windows ALPC heap buffer overflow allows local privilege escalation

Microsoft · Windows 10 1607

A heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local access on a machine elevate their privileges. The flaw affects a broad set of Windows 10 and Windows Server releases, so unpatched endpoints and servers retain a local escalation path. It matters because local privilege escalation is a standard step in post-compromise chains, turning limited access into full control of the host.

7.8 CVSS 3.1 High CISA KEV since 8 Sep 2026 EPSS 3.6% · top 10.9% CWE-122 · Heap-based buffer overflowCWE-908 · Use of uninitialized resource
7.8CVSS 3.1 base score
3.6%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
8Affected product versions listed by NVD
2References
24 Sep 2026Last modified by NVD

Description

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is a local privilege escalation with high confidentiality, integrity and availability impact and is listed in CISA KEV as exploited, though it requires existing local access and has low EPSS.

What it is

A heap-based buffer overflow in the Windows ALPC subsystem, combined with use of an uninitialized resource, lets an attacker with existing local access on a machine elevate their privileges. The flaw affects a broad set of Windows 10 and Windows Server releases, so unpatched endpoints and servers retain a local escalation path. It matters because local privilege escalation is a standard step in post-compromise chains, turning limited access into full control of the host.

Impact

An attacker who already holds a low-privileged account or code execution on the host can gain high-level read, write and execution capability, effectively taking over the system. That access can be used to disable defenses, move laterally, or deploy further payloads.

Attack surface

The vulnerability is reached locally through the ALPC interface, per the CVSS vector AV:L. It requires low privileges (PR:L) and no user interaction (UI:N), so any process or user already running on the box can attempt it.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2026-09-08 with a remediation due date of 2026-09-22, indicating exploitation in the wild. EPSS is low (0.00572, roughly the 46th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for all listed Windows 10 and Windows Server versions; treat this as the first action given the KEV listing.
  • Prioritize patching of internet-facing and high-value servers, and meet the CISA due date of 2026-09-22 for federal and aligned environments.
  • Reduce the number of accounts and processes with local interactive or service access on sensitive hosts to limit who can reach the ALPC attack surface.
  • Where patching cannot be completed immediately, isolate affected hosts and restrict local logon and service account rights as a temporary control.

Detection

  • Monitor for unexpected privilege changes or new high-integrity processes spawned from low-privileged parents on affected Windows builds.
  • Hunt for anomalous ALPC connection activity and unusual process-to-process messaging involving privileged services.
  • Alert on exploitation indicators near known ALPC abuse patterns, such as crashes in ALPC-related components followed by elevated process creation.
  • Track patch state of the listed Windows 10 and Windows Server versions and flag hosts still unpatched after the KEV due date.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-85880 to the Known Exploited Vulnerabilities catalog on 8 September 2026 as "Microsoft Windows Heap-Based Buffer Overflow Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 22 September 2026.

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-85880 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.8CVE-2015-1635Microsoft HTTP.sys remote code execution via crafted HTTP requestsHTTP.sys in multiple Windows versions fails to properly handle crafted HTTP requests, allowing remote code execution. The flaw is reachable over the …KEVEPSS 100%analysed9.0CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU input validation remote code executionHyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, allowing remote code …KEVEPSS 7.4%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed

Source: NIST National Vulnerability Database (record CVE-2026-85880), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.