Windows ALPC CVE-2026-85880: actively exploited local privilege escalation
Published 09 Sep 2026 · Severity: high
Microsoft's 8 September 2026 security release addresses CVE-2026-85880, an actively exploited heap-based buffer overflow in Windows Advanced Local Procedure Call. CISA says an authorised local attacker can exploit it to elevate privileges. Use Microsoft's Security Update Guide to map the affected Windows product, edition and architecture to the applicable September update, prioritise systems where attackers could already run local code, and verify the fixed running build after reboot.