Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4734 articles · 212596 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-85880KEVEXPLOITEDPATCHED
microsoft · windows 10 version

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

Description

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
microsoftwindows 10 version10.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880(vendor-advisory, patch)

Related News (5 articles)

Tier D
Dark Reading56m ago
Patch Tuesday Sets Another Record With 974 CVEs
→ No new info (linked only)
Tier D
SecurityWeek3h ago
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
→ No new info (linked only)
Tier C
Qualys Blog3h ago
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
→ No new info (linked only)
Tier B
CCCS Canada3h ago
Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1
→ No new info (linked only)
Tier A
Microsoft MSRC8h ago
CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.0.14393.951210.0.17763.924510.0.19044.772510.0.19045.77256.2.9200.263496.3.9600.2339710.0.20348.5622
CWECWE-122, CWE-908
PublishedSep 8, 2026
Last enriched4h ago
Trending Score143🔥
Source articles6
Independent6
Info Completeness3/14
Missing: vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-81963EXPKEV
Windows Update Stack Elevation of Privilege Vulnerability
Trending: 139
HIGHCVE-2026-63520EXPKEV
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 73
CRITICALCVE-2026-70352
Azure AI Language Elevation of Privilege Vulnerability
Trending: 63
CRITICALCVE-2026-69276
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability
Trending: 60
CRITICALCVE-2026-69491
Microsoft DirectMusic Remote Code Execution Vulnerability
Trending: 60

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 8, 2026
Added to CISA KEV
Sep 8, 2026
Discovered by ZDM
Sep 8, 2026
Actively Exploited
Sep 8, 2026
Patch Available
Sep 8, 2026