ZeroDayAlert

CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

Microsoft Windows Added to KEV 2026-09-08 Federal due 2026-09-22 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects Microsoft Windows systems running the Advanced Local Procedure Call (ALPC) component. The heap-based buffer overflow allows a locally authenticated attacker to elevate their privileges on the affected machine. The record does not specify which Windows versions or editions are vulnerable, nor does it detail the conditions under which exploitation occurs.

How to check whether this touches you

  • Inventory whether you operate Windows endpoints, servers or hybrid cloud instances anywhere in your estate.
  • Determine whether unprivileged user access to affected systems is controlled — this is a local privilege escalation, so it requires an attacker to have login capability first.
  • Check Microsoft's official security advisory for CVE-2026-85880 to confirm which Windows versions are affected and whether your deployed editions fall within that scope.
  • Query patch management records or endpoint telemetry to confirm the current Windows build number on each system; backported patches exist, so absence of a major version bump does not prove unpatched state.

What to do

  1. Consult Microsoft's security bulletin for CVE-2026-85880 and cross-reference it against your Windows inventory to establish which systems require patching.
  2. If you cannot patch by the federal remediation due date of 22 September 2026, begin by restricting login access to critical systems — disable local user accounts not needed for service operation, enforce multi-factor authentication where available, and monitor failed authentication attempts.
  3. Apply patches as they become available, prioritising systems with highest-value data or those accessible from less-trusted networks first; follow CISA BOD 26-04 risk-based guidance if your organisation is subject to it.
  4. Enable logging of process execution and privilege escalation events on Windows systems, and retain those logs for forensic inspection.
  5. If you operate cloud services that include Windows instances, evaluate whether the cloud provider has patched the underlying platform or whether you must patch instances yourself.

If you find you were exposed

Check your audit logs and Windows Event Viewer records for failed and successful privilege escalation attempts predating the advisory date. Focus particularly on systems where local user activity was heavier in the months before disclosure. Log retention is your constraint — if your organisation routinely purges security logs after 30 days, forensic visibility beyond that window will be lost. Escalate any signs of suspicious privilege elevation to your incident response team for triage.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-85880 is being exploited. It cannot tell you whether Windows is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →