TL;DR — Microsoft has confirmed that CVE-2026-85880, a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem, was exploited in the wild as a zero-day before the September 2026 patches shipped. It is a local privilege-escalation flaw: code already running with low privileges — inside a browser renderer, an AppContainer sandbox, or as a standard user — can trigger the overflow to escape the sandbox and elevate to SYSTEM, the highest privilege on a Windows box. Microsoft rates it CVSS 7.8 (High, CWE-122), it was discovered by threat-intelligence firms Volexity and Proofpoint (a hallmark of use in real, targeted attacks), and CISA added it to the Known Exploited Vulnerabilities catalog on 8 September 2026 with a 22 September federal patch deadline. It is not a remote “wormable” bug on its own — but it is exactly the escalation link attackers bolt onto a browser or phishing exploit to take over the machine.
What Is the Windows ALPC Zero-Day (CVE-2026-85880)?
Advanced Local Procedure Call (ALPC) is the high-speed inter-process communication mechanism that sits at the heart of Windows. Almost everything talks over it: sandboxed apps ask trusted system services to do work on their behalf, and the kernel arbitrates those conversations thousands of times a second. Because ALPC is the bridge between low-trust and high-trust code, a memory-safety bug in it is a prize: it is precisely the boundary an attacker needs to cross to turn a foothold into full control. CVE-2026-85880 is a heap-based buffer overflow in that subsystem, and Microsoft confirms it was exploited in the wild as a zero-day before the fix shipped.
Microsoft rates the flaw at CVSS 7.8 (High) and classifies it as CWE-122, heap-based buffer overflow. The vector, CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, tells the story: the attack is local (the attacker must already run some code on the machine), needs only low privileges and no user interaction, and yields total impact to confidentiality, integrity and availability — in other words, SYSTEM. This is the second Windows ALPC bug flagged as an actively exploited zero-day since CVE-2023-21674 in January 2023, ending a quiet spell of nearly four years for a component that attackers clearly still study closely.
How the CVE-2026-85880 Exploit Works
In plain terms: an ALPC message carries data whose length the receiving code trusts without properly checking it. By sending a carefully malformed message, an attacker makes Windows write more bytes into a heap buffer than it can hold. That overflow smashes adjacent memory, and with careful heap grooming the attacker turns the corruption into control over what the code does next — running their own instructions at the privilege level of the service that owns the ALPC endpoint, which is far higher than their own.
Technically, the root cause is CWE-122: a heap-based buffer overflow reachable across an ALPC port. The pre-condition is the key nuance for defenders to understand: this is not a remote, unauthenticated bug. An attacker must already be executing code on the target — typically inside a sandbox or AppContainer, such as a compromised browser renderer process or a document handler. From that low-trust position they craft the malformed ALPC request, trigger the overflow, corrupt the heap to hijack execution, and escape the sandbox to run as SYSTEM. That is why bugs like this rarely travel alone: they are the second stage of a chain, welded onto a browser or phishing exploit that provides the initial foothold. Consistent with responsible disclosure, neither Microsoft nor the discovering researchers have published the trigger or proof-of-concept code, so no public exploit exists at the time of writing.
Impact Nuance: A “Local” Bug That Punches Well Above 7.8
The 7.8 “High” score can lull you into deprioritising this one, and that would be a mistake. CVSS penalises the local attack vector heavily — the attacker needs prior code execution — which is exactly why elevation-of-privilege bugs so often score in the high-7s rather than the critical range. But real intrusions are chains, and a reliable local-to-SYSTEM primitive is one of the most valuable rungs on the ladder. It converts a limited foothold (a phished user, a sandboxed renderer, an unprivileged service account) into complete control: disabling security tooling, dumping credentials, and moving laterally.
Two things sharpen the point. First, the discovery credits — Volexity and Proofpoint, both threat-intelligence firms that find bugs by watching real attacks — strongly imply this was caught in targeted, hands-on-keyboard operations rather than in a lab. Second, the affected estate is enormous and long-lived: Windows 10 and Windows Server 2012 through 2022, much of it running in environments that patch slowly. (The sibling zero-day patched the same day, CVE-2026-81963 in the Windows Update Stack, covers the newer Windows 11 and Server 2025 line.) A “local” label is not a reason to wait — it is a description of where in the kill chain this bug does its damage.
Elevation-of-privilege bugs never make the front page alone — they make every other exploit worse. A 7.8 that turns a sandboxed foothold into SYSTEM is not a footnote to Patch Tuesday; it is the point of it.
Active Exploitation of CVE-2026-85880
This is confirmed in-the-wild exploitation, not a theoretical risk. Microsoft’s advisory marks CVE-2026-85880 as “Exploitation Detected” at the time it shipped the fix on 8 September 2026 — meaning attackers were using it as a zero-day before a patch existed. The flaw was reported by researchers at Volexity and Proofpoint, firms whose vulnerability discoveries typically originate from incident-response and threat-hunting work against active intrusions. Microsoft has not attributed the activity to a named threat actor and has released no campaign-specific indicators, which is common for freshly patched EoP zero-days where sharing details would aid copycats before defenders can patch.
CISA added CVE-2026-85880 to its Known Exploited Vulnerabilities (KEV) catalog on 8 September 2026, alongside the sibling Windows flaw CVE-2026-81963 and other actively exploited bugs from the same batch, and set a remediation deadline of 22 September 2026 for US federal civilian agencies under Binding Operational Directive 22-01. There is no public proof-of-concept yet, but heap-overflow EoP bugs in a core Windows component are routinely reverse-engineered from the patch within weeks — the window between “quietly used by a few” and “commodity tooling” is short.
Remediation & Mitigation: Patching the Windows ALPC Flaw
Install the September 2026 Windows updates now. The fix is delivered through the standard monthly cumulative update — there is no separate hotfix and no configuration change required. Because this is a patched, actively exploited zero-day, it should be at the top of your queue rather than folded into a routine 30-day cycle.
- Deploy the September 2026 cumulative update to every affected system — Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2012 R2, 2016, 2019 and 2022. Confirm the resulting build against Microsoft’s update guide (for example, Windows 10 22H2 should report build 19045.7725 or later, Windows Server 2016 14393.9512 or later).
- Don’t forget the servers and the stragglers. ALPC is present on every Windows install; server estates and end-of-life-adjacent Windows 10 fleets are the ones most likely to lag. Prioritise anything that runs untrusted content or is multi-user (RDS/Citrix hosts, developer workstations, VDI).
- There is no clean workaround. You cannot disable ALPC — Windows depends on it. If you genuinely cannot patch a system immediately, reduce the odds an attacker gets the local foothold this bug needs: enforce least privilege, keep browsers and Office fully updated, block macro and script-based initial access, and tighten application control (WDAC/AppLocker).
Because this was a zero-day, patching is necessary but not sufficient for exposed high-value hosts. If a machine handled untrusted content and went unpatched during the exploitation window, treat local-to-SYSTEM compromise as plausible:
- Hunt for the chain, not just the bug. An ALPC EoP is stage two — look for the stage-one delivery (suspicious browser child processes, Office spawning shells, unexpected sandboxed-process crashes) and for post-escalation behaviour (new SYSTEM services, credential-dumping, security-tool tampering).
- Rotate credentials that touched a suspect host — local admin and service-account secrets, cached domain credentials, and any tokens or keys that a SYSTEM-level attacker could have harvested; force re-authentication.
- Watch for anomalous ALPC-related crashes in the run-up to the patch as a rough hunting signal, and lean on EDR detections for sandbox-escape and privilege-escalation behaviour rather than a single file hash — no public IOCs have been released for this CVE.
Related ZeroDayHub Coverage
Local privilege escalation is the quiet workhorse of modern intrusions — rarely the headline, always in the chain. We saw the same memory-corruption-to-kernel pattern in our write-up of the Windows IKE double-free exploited in the wild (CVE-2026-33824), another Windows memory-safety bug turned into an attacker primitive. And for the initial-access half of the chain these EoP flaws depend on, our coverage of the Windows HTTP.sys unauthenticated RCE (CVE-2026-47291) shows how attackers get their first foot in the door. Put a remote entry point and a reliable local-to-SYSTEM escalation together and you have a full compromise — which is exactly why an “only 7.8” EoP still deserves an urgent patch.
Sources & Further Reading
- Microsoft Security Response Center — CVE-2026-85880: Windows ALPC Elevation of Privilege Vulnerability (advisory, CVSS, affected builds)
- SecurityWeek — Microsoft patches record vulnerabilities, including two exploited zero-days
- Malwarebytes — Microsoft fixes record flaws, including two exploited zero-days
- SOC Prime — CVE-2026-85880 & CVE-2026-81963 analysis (CVSS, CWE, affected versions, discoverers)
- Security Affairs — CISA adds Microsoft Windows, N-able and Adobe flaws to KEV (deadlines)
- NVD — CVE-2026-85880 detail record
- CISA — Known Exploited Vulnerabilities Catalog
ZeroDayHub reports on vulnerabilities for defensive purposes only. This article deliberately omits exploit code and, following the vendor’s lead, withholds trigger-level detail while patching is in progress.





Leave a Reply