CVE-2026-85880: Windows ALPC Heap Overflow Exploited
CISA confirms active exploitation of CVE-2026-85880, a heap-based buffer overflow in Microsoft Windows ALPC leading to local privilege escalation.
- Immediate impact: Microsoft Windows users face active exploitation of a heap overflow vulnerability.
- Affected systems: The vulnerability is present in Microsoft Windows Advanced Local Procedure Call component.
- Remediation: Apply vendor-provided security updates and comply with CISA BOD 26-04 guidelines.