Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-85880

Microsoft Windows ALPC Heap Buffer Overflow Privilege Escalation

“Windows ALPC contains a heap buffer overflow allowing AppContainer sandbox escape to local privilege escalation. CVSS 7.8, actively exploited, on CISA KEV.”

cat cve-2026-85880.json
Vendor
Microsoft
Product
Windows
CVSS
7.8
EPSS (exploit probability)
N/A
Status
kev
CISA patch-by (BOD 22-01)
Published

Windows Advanced Local Procedure Call (ALPC) contains a heap-based buffer overflow that allows privilege escalation from within a low-privilege AppContainer. An attacker who has already achieved code execution inside an AppContainer sandbox can trigger the overflow to escape the sandbox boundary and escalate privileges on the local system.

Patched September 8, 2026 as part of Microsoft’s record September Patch Tuesday, which addressed 974 CVEs total. CISA added CVE-2026-85880 to its Known Exploited Vulnerabilities catalog the same day. Federal agencies must apply mitigations by September 22, 2026 per BOD 26-04.

The flaw is not remotely exploitable on its own: local code execution is a required precondition. In active intrusions, that precondition is typically already met before privilege escalation is needed.

For full Patch Tuesday context, see Microsoft Patches Record 974 Vulns, 2 Zero-Days.