Overview
What is CVE-2026-85880?
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CISA lists CVE-2026-85880 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft Windows.
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.