What it is
CVE-2026-85880 is a vulnerability affecting Microsoft Windows 10 Version 1607 and 12 other products. Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Vulnerability report
Windows 10 Version 1607
Microsoft / Windows 10 Version 1607 · affected before 10.0.14393.9512
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-85880 is a vulnerability affecting Microsoft Windows 10 Version 1607 and 12 other products. Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Microsoft / Windows 10 Version 1607 affected before 10.0.14393.9512.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Tenable Blog
Independent exploitation attestation added to the Previdian record.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Microsoft CVRF First | 2026-09-08 07:00 UTC |
| Tenable Blog | 2026-09-08 18:07 UTC |
| CISA | 2026-09-08 18:40 UTC |
| CVE | 2026-09-08 19:01 UTC |
| CyberInsider | 2026-09-08 19:36 UTC |
| Rapid7 | 2026-09-08 21:44 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS
0.6%
Recent mention · NCSC Security Advisories
Microsoft heeft 666 kwetsbaarheden verholpen in Windows. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. Microsoft heeft voor Windows 666 kwetsbaarheden verholpen....
Read full advisoryRecent mention · NCSC Security Advisories
NCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft WindowsNCSC Security Advisories · 09 Sep 2026
Microsoft heeft 666 kwetsbaarheden verholpen in Windows. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. Microsoft heeft voor Windows 666 kwetsbaarheden verholpen. De 32 ernstigste kwetsbaarheden bevinden zich in meerdere Windows componenten en hebben een CVSS score van 9.0 en hoger toegewezen gekregen. Kwaadwillenden met toegang tot deze componenten kunnen zonder voorafgaande authenticatie mogelijk code uitvoeren of zich toegang verschaffen tot het kwetsbare systeem. Deze...
Recent mention · TheRegister
Microsoft breaks Patch Tuesday record with 974-CVE delugeTheRegister · 09 Sep 2026
Adobe also brought goodies to the patch party and they deserve immediate attention
Recent mention · Cisco Talos Blog
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Blog · 08 Sep 2026
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Recent mention · Rapid7
Patch Tuesday - September 2026Rapid7 · 08 Sep 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the...
Recent mention · CyberInsider
Microsoft releases Windows security update addressing 723 flawsCyberInsider · 08 Sep 2026
Microsoft has released its September 2026 security updates, fixing two Windows elevation-of-privilege vulnerabilities that attackers are already exploiting in the wild. The company’s broader Patch Tuesday release addresses 974 CVEs across its products, including 723 affecting Windows. The two actively exploited flaws are tracked as CVE-2026-85880 and CVE-2026-81963. Microsoft says neither vulnerability was publicly disclosed … The post Microsoft releases Windows security update addressing 723 flaws appeared first on CyberInsider.
Recent mention · Tenable Blog
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)Tenable Blog · 08 Sep 2026
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 101 rated critical and 824 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain ServicesActive Directory Federation Services (AD FS)Audio Video Control Transport ProtocolAzure...
Timeline
Exploitation attested by an external source
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Exploitation attested by an external source
Vulnerability disclosed publicly
High-confidence, third-party attested exploitation
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-85880
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-85880",
"confidence": "Confirmed",
"cvss_score": 7.8,
"cvss_estimated": false,
"epss_score": 0.00572,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}