CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft · Windows
Listed by CISA as exploited in the wild since 8 Sep 2026. Below: exploitation status, EPSS and every published CVSS, each with its source, then affected versions and references.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
Description
as written by CISA (KEV catalog)
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
Required action
CISA KEV
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products and versions
CVE record · microsoft
Microsoft · Windows 10 Version 1607
- affected: from 10.0.14393.0 before 10.0.14393.9512
Microsoft · Windows 10 Version 1809
- affected: from 10.0.17763.0 before 10.0.17763.9245
Microsoft · Windows 10 Version 21H2
- affected: from 10.0.19044.0 before 10.0.19044.7725
Microsoft · Windows 10 Version 22H2
- affected: from 10.0.19045.0 before 10.0.19045.7725
Microsoft · Windows Server 2012
- affected: from 6.2.9200.0 before 6.2.9200.26349
Microsoft · Windows Server 2012 (Server Core installation)
- affected: from 6.2.9200.0 before 6.2.9200.26349
Microsoft · Windows Server 2012 R2
- affected: from 6.3.9600.0 before 6.3.9600.23398
Microsoft · Windows Server 2012 R2 (Server Core installation)
- affected: from 6.3.9600.0 before 6.3.9600.23398
Microsoft · Windows Server 2016
- affected: from 10.0.14393.0 before 10.0.14393.9512
Microsoft · Windows Server 2016 (Server Core installation)
- affected: from 10.0.14393.0 before 10.0.14393.9512
Microsoft · Windows Server 2019
- affected: from 10.0.17763.0 before 10.0.17763.9245
Microsoft · Windows Server 2019 (Server Core installation)
- affected: from 10.0.17763.0 before 10.0.17763.9245
Microsoft · Windows Server 2022
- affected: from 10.0.20348.0 before 10.0.20348.5622
Status words (affected, unaffected, unknown) and version bounds are copied from the record. An upper bound such as “before 7.1.0” usually marks the first fixed version; confirm in the vendor advisory before planning an upgrade.
References
CISA KEV notes and CVE record
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-85880
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2026-85880
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
EPSS over the last 30 days
See also: all Microsoft entries in KEV · the full KEV catalog
Related entries
Other Microsoft entries in KEV
- CVE-2026-65660Microsoft SharePoint Code Injection Vulnerability
- CVE-2026-81963Microsoft Windows Link Following Vulnerability
- CVE-2019-1068Microsoft SQL Server Remote Code Execution Vulnerability
- CVE-2026-55040Microsoft SharePoint Weak Authentication Vulnerability
- CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Added in the same week (see the week)
- CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
- CVE-2026-42016JFrog Artifactory Incorrect Authorization Vulnerability
- CVE-2026-42018JFrog Artifactory Improper Authentication Vulnerability
- CVE-2026-85706GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- CVE-2026-86060MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
- CVE-2026-67277MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
Questions about CVE-2026-85880
Is CVE-2026-85880 being exploited?
Yes, according to CISA. CVE-2026-85880 was added to the Known Exploited Vulnerabilities catalog on 8 Sep 2026, which CISA does only with reliable evidence of exploitation in the wild. The catalog field for ransomware campaign use says "Unknown".
What is the deadline to remediate CVE-2026-85880?
CISA set 22 Sep 2026 as the due date for US Federal Civilian Executive Branch agencies. The date is binding only for those agencies; other organisations can read it as a measure of urgency.
What is the EPSS score of CVE-2026-85880?
3.62%, in the 89th percentile, in the FIRST EPSS model of 2 Oct 2026. It estimates the probability of exploitation activity in the following 30 days. For a CVE already in KEV the score is secondary: exploitation has been observed.
How severe is CVE-2026-85880?
microsoft.com rates it 7.8 HIGH (CVSS 3.1). These are the published assessments as of 3 Oct 2026; this site does not rescore.
Which product does CVE-2026-85880 affect?
Microsoft Windows, as named in the CISA catalog. The affected versions listed in the CVE record are on this page; the vendor advisory in the references is the authority on fixed versions.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.