LATEST View all updates

CVE-2026-85880 Windows ALPC Zero-Day: Affected Windows 10 and Server Builds

CVE-2026-85880 is actively exploited; check affected Windows 10 and Server builds and patch eligibility.

Editorial cybersecurity image of Windows 10 and server systems being checked for the CVE-2026-85880 fix

Signal Brief

  • CVE-2026-85880 is actively exploited, but Microsoft describes it as a local privilege-escalation flaw requiring prior low-level access.
  • The affected estate includes Windows 10 and Windows Server 2012 through Server 2022, not Windows 11 or Server 2025.
  • Windows 10 users must verify both the fixed build and whether their servicing or ESU state can receive the September 2026 update.
  • A patched build confirms current remediation state but does not prove the endpoint was never compromised before patching.

CVE-2026-85880 is an actively exploited Windows Advanced Local Procedure Call vulnerability with Microsoft security fixes available. The affected estate is mainly older Windows client and server branches, including Windows 10 and Windows Server 2012 through Server 2022. Microsoft describes the flaw as a local privilege-escalation issue requiring prior low-level access, so it should not be treated as a remote unauthenticated Windows vulnerability.

Is your Windows system affected by CVE-2026-85880?

Check the installed Windows release and OS build against Microsoft’s fixed-build threshold. Windows 10 1607, 1809, 21H2 and 22H2 are in scope, along with Windows Server 2012, 2012 R2, 2016, 2019 and 2022. Microsoft’s affected-product data for this CVE does not list Windows 11 or Windows Server 2025.

A device below the fixed threshold remains inside Microsoft’s affected version range. A device at or above that threshold is beyond the vulnerable build range identified in the September 2026 advisory data.

Infographic listing key fixed Windows 10 and Server build thresholds for CVE-2026-85880
Compare the installed Windows build with Microsoft's fixed threshold and verify servicing eligibility where required.

Which Windows builds are affected?

Windows release Vulnerable when below September fix or fixed build
Windows 10 1607 14393.9512 KB5123099 / build 14393.9512
Windows 10 1809 17763.9245 KB5122876 / build 17763.9245
Windows 10 21H2 19044.7725 KB5122878 / build 19044.7725
Windows 10 22H2 19045.7725 KB5122878 / build 19045.7725
Windows Server 2012 9200.26349 Verify current Microsoft servicing package and build 9200.26349 or later
Windows Server 2012 R2 9600.23397 Verify current Microsoft servicing package and build 9600.23397 or later
Windows Server 2016 14393.9512 KB5123099 / build 14393.9512
Windows Server 2019 17763.9245 KB5122876 / build 17763.9245
Windows Server 2022 20348.5622 KB5122882 / build 20348.5622

Server Core variants are also affected where Microsoft lists the corresponding server release. Later cumulative security updates can supersede the original September package, so the most durable verification method is to confirm that the installed build is at or above Microsoft’s fixed threshold.

Is CVE-2026-85880 remotely exploitable?

No remote unauthenticated attack path was established in the reviewed Microsoft evidence. Microsoft’s scoring specifies a local attack vector, low privileges required and no user interaction once the attacker has the necessary local execution context.

The vulnerability is therefore a privilege-escalation step. It should not be presented as the mechanism that gives an attacker initial remote access to a Windows endpoint.

What can successful exploitation achieve?

Current Microsoft- and CISA-backed reporting describes successful exploitation as allowing a lower-privileged local attacker to elevate privileges, potentially up to SYSTEM. Current reporting also describes an AppContainer escape scenario, but TPS has not established that AppContainer is the only possible exploitation context.

Is Windows 11 affected by CVE-2026-85880?

Microsoft’s affected-product data for CVE-2026-85880 does not list Windows 11 or Windows Server 2025. Those newer branches should not be added to this CVE’s affected table merely because they are Windows products.

This is also why CVE-2026-85880 should not be confused with CVE-2026-81963, a separate actively exploited Windows Update Stack vulnerability affecting newer Windows branches.

Windows 10 patch eligibility matters

For Windows 10 21H2 and 22H2, Microsoft maps the September fixed builds to KB5122878. However, a fixed build existing does not mean every Windows 10 installation is automatically entitled to receive that update.

Microsoft’s September guidance applies to supported servicing states including relevant Extended Security Updates and LTSC editions. Ordinary Windows 10 22H2 free support ended in October 2025, so administrators should verify the device’s current support or ESU state before assuming that Windows Update will deliver the September 2026 security fix.

How should you verify the CVE-2026-85880 patch?

1. Identify the Windows release

Run winver or use the system information controls available on the endpoint to identify the exact Windows release.

2. Record the OS build

Compare the installed build with Microsoft’s fixed threshold for that release.

3. Check servicing eligibility

For Windows 10 and legacy Windows Server branches, confirm that the device is still in a supported servicing or ESU state that can receive current security updates.

4. Install a current supported update

If the device is below the fixed threshold, deploy the current Microsoft-supported cumulative security update through the organisation’s normal update-management process.

5. Verify the resulting build

Restart where required and confirm that the endpoint is now at or above the fixed build. Update history or enterprise inventory can provide secondary deployment evidence.

Does installing the patch prove the endpoint was never compromised?

No. A fixed build establishes the system’s current remediation state. It does not prove that exploitation did not occur before the update was installed.

Organisations with evidence or suspicion of earlier compromise should handle that as a separate incident-response question using endpoint telemetry, authentication records, EDR data and any later Microsoft, CISA or CERT guidance.

Are there CVE-specific indicators of compromise?

TPS did not verify a reliable public set of unique indicators, attacker artefacts or exploitation signatures attributable specifically to CVE-2026-85880 during this review.

The absence of published CVE-specific indicators should not be treated as proof that an affected endpoint is clean.

Is ransomware using CVE-2026-85880?

TPS did not verify a named ransomware operation or threat actor using CVE-2026-85880. Exploitation is confirmed through CISA KEV, but ransomware linkage remains unresolved.

What is CISA’s remediation deadline?

CISA lists a September 22, 2026 remediation due date for organisations subject to the applicable U.S. federal vulnerability-remediation directive.

That date should not be presented as a general legal deadline for Indian companies, private organisations or ordinary Windows users. Other operators should use their own risk-based patching requirements while treating known exploitation as a strong remediation priority.

What should endpoint teams do now?

  • inventory Windows 10 and Windows Server 2012 through 2022 systems;
  • compare installed builds with Microsoft’s fixed thresholds;
  • verify servicing or ESU eligibility on older Windows branches;
  • deploy a current supported cumulative security update where needed;
  • confirm the resulting post-update build;
  • do not classify CVE-2026-85880 as a remote unauthenticated Windows exploit;
  • separate current patch-state verification from historical compromise investigation;
  • monitor Microsoft, CISA and relevant national CERT guidance for exploitation details or new indicators.

What happens next?

This article should be updated if Microsoft revises the affected-product table, CISA publishes additional exploitation context, a validated exploit chain or IOC set becomes available, CERT-In issues material India-relevant guidance, or Microsoft changes servicing eligibility for affected legacy Windows branches.

TPS should maintain this same URL for material CVE-2026-85880 developments.

Verification note

TPS reviewed Microsoft’s CVE-2026-85880 vulnerability data, CISA known-exploitation status, Microsoft September 2026 Windows servicing information and current security reporting. The affected/fixed build boundaries and local privilege-escalation prerequisite are supported; attacker attribution, ransomware use, exploitation prevalence and unique CVE-specific indicators remain unresolved.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led article for informational and editorial guidance. CVE-2026-85880 is confirmed exploited, but Microsoft describes it as a local privilege-escalation flaw requiring prior low-level access; attacker attribution, ransomware use and CVE-specific compromise indicators remain unresolved. Windows 10 patch availability can also depend on current servicing or ESU eligibility. Verify Microsoft, CISA and your organisation's current endpoint-security guidance before consequential remediation or incident-response action.