THREAT OPS › CVEs › CVE-2026-85880
CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
Vulnerability details
- Affected productsWindows
- KEV remediation due2026-09-22
Exploiting threat actors
- Earth LuscaG1006
Related reporting
- 14th September – Threat Intelligence Reportcheckpoint_research
- September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Dayssocradar_blog
- Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windowsvolexity
- Microsoft fixes record 964 flaws, including 2 exploited zero-daysmalwarebytes_blog
- Patch Tuesday - September 2026rapid7
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiestalos
- Microsoft Plugs Nearly 1,000 Security Holeskrebs
- Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1cccs_ca
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories
- Microsoft Patch Tuesday, September 2026 Security Update Reviewqualys
- The September 2026 Security Update Reviewzdi_blog
- Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)tenable
- [CISA KEV] CVE-2026-85880 — Microsoft Windows: Microsoft Windows Heap-Based Buffer Overflow Vulnerabilitycisa_kev