CISA has added CVE-2026-85880 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Microsoft Windows and is a heap-based buffer overflow in Windows Advanced Local Procedure Call that enables local privilege escalation.
The flaw is a memory-safety vulnerability that an attacker can exploit locally to elevate privileges. NVD assigns it a CVSS score of 7.8, rated High. Microsoft has made a patch available through its security advisory.
CISA’s KEV listing confirms that attackers are actively exploiting the vulnerability. The supplied data does not confirm use in ransomware campaigns. CISA requires remediation by 22 September 2026.
CISA requires organisations to apply mitigations in accordance with Microsoft’s instructions and ensure compliance with BOD 26-04, “Prioritising Security Updates Based on Risk”, and its Forensics Triage Requirements. FCEB agencies are directly affected by this requirement. Organisations must also assess each asset’s internet exposure and follow applicable BOD 26-04 patching guidance for cloud services, or discontinue use where mitigations are unavailable. All organisations should review their exposure and apply the available update.
See the NVD entry and CISA KEV catalogue for full details.