CVE-2026-85880
HIGH
Actively Exploited
microsoft
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022
NVDCISA KEV
CVSS Score
7.8
Severity
HIGH
Published
Sep 08, 2026
Vendor
microsoft
This vulnerability is in the CISA Known Exploited Vulnerabilities Catalog. Active exploitation has been observed. Immediate patching is recommended.
Description
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.