PT-2026-88151 · Microsoft · Windows+13

CVE-2026-85880

·

Published

2026-09-08

·

Updated

2026-09-12

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Microsoft’s September patch set includes CVE-2026-85880, that includes heap buffer overflow in Windows ALPC which is already exploited for SYSTEM!
ALPC hadn’t seen a patched zero-day since 2023. Low-privilege AppContainer → sandbox escape + elevation with no extra interaction.
Interesting thing is the component that stayed quiet for years produced an in-the-wild EoP.
#WindowsInternals #PrivilegeEscalation #Cybersecurity

Fix

LPE

Use of Uninitialized Resource

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14306
CVE-2026-85880

Affected Products

Windows
Windows 10 1607
Windows 10 1809
Windows 10 21H2
Windows 10 22H2
Windows 10 Version 1607
Windows 10 Version 1809
Windows 10 Version 21H2
Windows 10 Version 22H2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016
Windows Server 2019
Windows Server 2022