CVE-2026-85880
HIGH · 7.8 KEV EPSS 0.6%KEV-listed, confirmed in-the-wild exploitation, urgent vendor patching, active defender triage.
What: Heap-based buffer overflow in Windows ALPC allowing local privilege escalation (CVSS 7.8 HIGH); affects authorized attackers on Windows systems.
Why it matters: KEV-listed as exploited in-the-wild zero-day as of 2026-09-08. Microsoft patched it same day in Patch Tuesday alongside CVE-2026-81963; multiple vendor advisories (Tenable, Talos, Krebs) confirm active exploitation. Part of larger LPE chains targeting older Windows builds; requires initial foothold but escalates to SYSTEM.
Where it's seen: Patch Tuesday coverage across security blogs and news outlets; exploit chains documented involving Chromium V8 RCE + Windows kernel LPE; defender alerts on Bluesky discussing triage priority and mitigation.
RISK: CRITICAL — Exploited zero-day, KEV-listed, weaponized in real attack chains, high-value LPE primitive.
Description
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVSS 3.1 breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Local
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High