๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Summary
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability (a memory safety flaw where data overflows a buffer's allocated space, allowing attackers to run unintended code) that allows an attacker to elevate privileges locally (gain higher-level access on a system they've already partially compromised). This vulnerability is actively being exploited in real-world attacks.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions from Microsoft, following CISA's BOD 26-04 guidance for patching prioritization. If mitigations are unavailable, follow BOD 26-04 guidance for cloud services or discontinue use of the product. See Microsoft Security Response Center (https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85880) for specific patching details. The patch deadline is 2026-09-22.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
September 7, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85880
First tracked: September 8, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%