All news & advisories
Actively exploited

CVE-2026-85880: Actively Exploited Vulnerability

CVE-2026-85880 CVSS 7.8 CISA KEV · actively exploited
Who it affects
See the summary below.
What to do
Patch immediately — prioritise internet-facing systems.

CVE-2026-85880 Advisory

Severity: HIGH (CVSS 7.8)
KEV Status: Actively Exploited

Affected Products

  • Microsoft Defender Business

Vulnerability Details

Heap-based buffer overflow in Windows ALPC mechanism allows authorized attackers to execute local privilege escalation.

Remediation

Action Required: Prioritize patching due to active exploitation in the wild.

Data as of September 9, 2026. Sources: nvd.nist.gov, msrc.microsoft.com, cisa.gov. Figures are pulled from public vendor and security data and refreshed automatically.
Back to all news & advisories