DIRAS TAKE
Urgent: CISA placed this defect on its Known Exploited Vulnerabilities list with a remediation deadline, so prioritize installing vendor fixes or mitigations immediately to meet that requirement.
What is CVE-2026-85880?
An authenticated local user can elevate privileges on Windows by exploiting a heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component (CVE-2026-85880). The bug affects multiple Windows branches and builds; affected releases include Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows Server 2012 and 2012 R2, and Windows Server 2016 in the build ranges listed by the vendor. An attacker needs local access with an authorized account to trigger the overflow and gain higher privileges; no network interaction or user interaction is required beyond local execution. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9245 | 10.0.17763.9245 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7725 | 10.0.19045.7725 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26349 | 6.2.9200.26349 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2012 R2 (Server Core installation) 6.x | 6.3.9600.0 – before 6.3.9600.23398 | 6.3.9600.23398 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9512 | 10.0.14393.9512 |
Is CVE-2026-85880 being exploited?
CISA added CVE-2026-85880 to the Known Exploited Vulnerabilities catalog on 2026-09-08; U.S. federal agencies were required to remediate it by 2026-09-22.
How to fix CVE-2026-85880
- Apply Microsoft updates that provide the fixed builds (for example: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 6.2.9200.26349, 6.3.9600.23398).
- If you cannot patch immediately, restrict local account access and remove or limit administrative privileges where feasible.
- Follow vendor guidance for mitigations and monitor endpoints for unusual privilege escalation activity.
Frequently asked questions
Is CVE-2026-85880 being actively exploited?
CISA added CVE-2026-85880 to its Known Exploited Vulnerabilities catalog on 2026-09-08, and federal agencies were required to remediate it by 2026-09-22.
Which Windows versions are affected by CVE-2026-85880?
Windows builds affected include Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows Server 2012 and 2012 R2, and Windows Server 2016 within the specific build ranges published by the vendor.
Is there a patch for CVE-2026-85880?
Yes. Microsoft published fixes; affected branches show fixed build numbers such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 6.2.9200.26349, and 6.3.9600.23398.
Does CVE-2026-85880 require authentication?
Yes. Exploitation requires a local authorized account to trigger the ALPC heap-based buffer overflow and elevate privileges on the Windows host.
References
- nvd.nist.gov/vuln/detail/CVE-2026-85880
- cve.org/CVERecord?id=CVE-2026-85880
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026