CVE-2026-85880: listed in the CISA KEV catalog
CVE-2026-85880 · CVSS 7.8 HIGH · KEV 2026-09-08 · patch available
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Is CVE-2026-85880 exploited?
- Listed in the CISA KEV catalog on 2026-09-08.
- Federal remediation due 2026-09-22.
- Public exploit code: none found in monitored sources.
Which products and versions are affected?
- Microsoft · Windows 10 Version 1607 · >= 10.0.14393.0, < 10.0.14393.9512
- Microsoft · Windows 10 Version 1809 · >= 10.0.17763.0, < 10.0.17763.9245
- Microsoft · Windows 10 Version 21H2 · >= 10.0.19044.0, < 10.0.19044.7725
- Microsoft · Windows 10 Version 22H2 · >= 10.0.19045.0, < 10.0.19045.7725
- Microsoft · Windows Server 2012 · >= 6.2.9200.0, < 6.2.9200.26349
- Microsoft · Windows Server 2012 (Server Core installation) · >= 6.2.9200.0, < 6.2.9200.26349
- Microsoft · Windows Server 2012 R2 · >= 6.3.9600.0, < 6.3.9600.23397
- Microsoft · Windows Server 2012 R2 (Server Core installation) · >= 6.3.9600.0, < 6.3.9600.23397
- Microsoft · Windows Server 2016 · >= 10.0.14393.0, < 10.0.14393.9512
- Microsoft · Windows Server 2016 (Server Core installation) · >= 10.0.14393.0, < 10.0.14393.9512
- Microsoft · Windows Server 2019 · >= 10.0.17763.0, < 10.0.17763.9245
- Microsoft · Windows Server 2019 (Server Core installation) · >= 10.0.17763.0, < 10.0.17763.9245
- Microsoft · Windows Server 2022 · >= 10.0.20348.0, < 10.0.20348.5622
- Microsoft · Windows 10 Version 1809 for 32-bit Systems · < 10.0.17763.9245
- Microsoft · Windows 10 Version 1809 for x64-based Systems · < 10.0.17763.9245
- Microsoft · Windows Server 2022 (Server Core installation) · < 10.0.20348.5622
- Microsoft · Windows 10 Version 21H2 for 32-bit Systems · < 10.0.19044.7725
- Microsoft · Windows 10 Version 21H2 for ARM64-based Systems · < 10.0.19044.7725
- Microsoft · Windows 10 Version 21H2 for x64-based Systems · < 10.0.19044.7725
- Microsoft · Windows 10 Version 1607 for 32-bit Systems · < 10.0.14393.9512
- Microsoft · Windows 10 Version 1607 for x64-based Systems · < 10.0.14393.9512
Is there a patch?
What PlainSec published about CVE-2026-85880
Primary sources
What this record does not say
KEV and EPSS are re-checked daily. Record last updated 2026-09-09.