CISA_KEV · SEPTEMBER 2026 · CONFIRMED

CVE-2026-85880: Microsoft Windows Privilege Escalation Vulnerability

Severity
HIGH
Affected component
windows (other)
Patched version
Not yet available
CVE-2026-85880

A high-severity vulnerability in Microsoft Windows Advanced Local Procedure Call allows an attacker to elevate privileges locally. This threat is confirmed and has been exploited in the wild.

What happened

The vulnerability, tracked as CVE-2026-85880, is a heap-based buffer overflow in Microsoft Windows Advanced Local Procedure Call. An attacker can exploit this flaw to elevate privileges on a local system. The vulnerability was first flagged and confirmed on September 8, 2026. It is critical for system administrators and users to take immediate action to mitigate this threat.

Although the exact version range of affected Windows systems has not been authoritatively published, all users of Microsoft Windows are advised to monitor for patches and apply them as soon as they become available. The vulnerability has been actively exploited, making it imperative to address this issue promptly.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If windows is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

The exact version range of affected Windows systems has not been published. However, all users of Microsoft Windows should assume potential risk and take preventive measures.

What should I do right now?

Monitor for patches and apply them as soon as they are available. Review system logs for unusual activity and consider implementing additional security measures.

Has this been exploited in the wild?

Yes, this vulnerability has been confirmed to be exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats