CVE-2026-85880 Advisory
Severity: HIGH (CVSS 7.8)
KEV Status: Actively Exploited
Affected Products
- Microsoft Defender Business
Vulnerability Details
Heap-based buffer overflow in Windows ALPC mechanism allows authorized attackers to execute local privilege escalation.
Remediation
- Apply security updates from Microsoft: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880
- Reference CISA KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85880
Action Required: Prioritize patching due to active exploitation in the wild.