• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-85880: local privilege escalation in Microsoft Windows

An authenticated local user can elevate privileges on Windows by exploiting a heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component (CVE-2026-85880). The bug affects multiple Windows branches and builds; affected releases include Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows Server 2012 and 2012 R2, and Windows Server 2016 in the build ranges listed by the vendor. An attacker needs local access with an authorized account to trigger the overflow and gain higher privileges; no network interaction or user interaction is required beyond local execution.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.03616
CWE
CWE-122
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA placed this defect on its Known Exploited Vulnerabilities list with a remediation deadline, so prioritize installing vendor fixes or mitigations immediately to meet that requirement.

What is CVE-2026-85880?

An authenticated local user can elevate privileges on Windows by exploiting a heap-based buffer overflow in the Advanced Local Procedure Call (ALPC) component (CVE-2026-85880). The bug affects multiple Windows branches and builds; affected releases include Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows Server 2012 and 2012 R2, and Windows Server 2016 in the build ranges listed by the vendor. An attacker needs local access with an authorized account to trigger the overflow and gain higher privileges; no network interaction or user interaction is required beyond local execution. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.924510.0.17763.9245
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.772510.0.19044.7725
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.772510.0.19045.7725
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.263496.2.9200.26349
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2012 R2 (Server Core installation) 6.x6.3.9600.0 – before 6.3.9600.233986.3.9600.23398
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512
Windows Server 2016 (Server Core installation) 10.x10.0.14393.0 – before 10.0.14393.951210.0.14393.9512

Is CVE-2026-85880 being exploited?

CISA added CVE-2026-85880 to the Known Exploited Vulnerabilities catalog on 2026-09-08; U.S. federal agencies were required to remediate it by 2026-09-22.

How to fix CVE-2026-85880

  1. Apply Microsoft updates that provide the fixed builds (for example: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 6.2.9200.26349, 6.3.9600.23398).
  2. If you cannot patch immediately, restrict local account access and remove or limit administrative privileges where feasible.
  3. Follow vendor guidance for mitigations and monitor endpoints for unusual privilege escalation activity.

Frequently asked questions

Is CVE-2026-85880 being actively exploited?

CISA added CVE-2026-85880 to its Known Exploited Vulnerabilities catalog on 2026-09-08, and federal agencies were required to remediate it by 2026-09-22.

Which Windows versions are affected by CVE-2026-85880?

Windows builds affected include Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows Server 2012 and 2012 R2, and Windows Server 2016 within the specific build ranges published by the vendor.

Is there a patch for CVE-2026-85880?

Yes. Microsoft published fixes; affected branches show fixed build numbers such as 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, 10.0.19045.7725, 6.2.9200.26349, and 6.3.9600.23398.

Does CVE-2026-85880 require authentication?

Yes. Exploitation requires a local authorized account to trigger the ALPC heap-based buffer overflow and elevate privileges on the Windows host.

References