CVE-2026-85880 is an actively exploited Windows Advanced Local Procedure Call vulnerability with Microsoft security fixes available. The affected estate is mainly older Windows client and server branches, including Windows 10 and Windows Server 2012 through Server 2022. Microsoft describes the flaw as a local privilege-escalation issue requiring prior low-level access, so it should not be treated as a remote unauthenticated Windows vulnerability.
Is your Windows system affected by CVE-2026-85880?
Check the installed Windows release and OS build against Microsoft’s fixed-build threshold. Windows 10 1607, 1809, 21H2 and 22H2 are in scope, along with Windows Server 2012, 2012 R2, 2016, 2019 and 2022. Microsoft’s affected-product data for this CVE does not list Windows 11 or Windows Server 2025.
A device below the fixed threshold remains inside Microsoft’s affected version range. A device at or above that threshold is beyond the vulnerable build range identified in the September 2026 advisory data.

Which Windows builds are affected?
| Windows release | Vulnerable when below | September fix or fixed build |
|---|---|---|
| Windows 10 1607 | 14393.9512 | KB5123099 / build 14393.9512 |
| Windows 10 1809 | 17763.9245 | KB5122876 / build 17763.9245 |
| Windows 10 21H2 | 19044.7725 | KB5122878 / build 19044.7725 |
| Windows 10 22H2 | 19045.7725 | KB5122878 / build 19045.7725 |
| Windows Server 2012 | 9200.26349 | Verify current Microsoft servicing package and build 9200.26349 or later |
| Windows Server 2012 R2 | 9600.23397 | Verify current Microsoft servicing package and build 9600.23397 or later |
| Windows Server 2016 | 14393.9512 | KB5123099 / build 14393.9512 |
| Windows Server 2019 | 17763.9245 | KB5122876 / build 17763.9245 |
| Windows Server 2022 | 20348.5622 | KB5122882 / build 20348.5622 |
Server Core variants are also affected where Microsoft lists the corresponding server release. Later cumulative security updates can supersede the original September package, so the most durable verification method is to confirm that the installed build is at or above Microsoft’s fixed threshold.
Is CVE-2026-85880 remotely exploitable?
No remote unauthenticated attack path was established in the reviewed Microsoft evidence. Microsoft’s scoring specifies a local attack vector, low privileges required and no user interaction once the attacker has the necessary local execution context.
The vulnerability is therefore a privilege-escalation step. It should not be presented as the mechanism that gives an attacker initial remote access to a Windows endpoint.
What can successful exploitation achieve?
Current Microsoft- and CISA-backed reporting describes successful exploitation as allowing a lower-privileged local attacker to elevate privileges, potentially up to SYSTEM. Current reporting also describes an AppContainer escape scenario, but TPS has not established that AppContainer is the only possible exploitation context.
Is Windows 11 affected by CVE-2026-85880?
Microsoft’s affected-product data for CVE-2026-85880 does not list Windows 11 or Windows Server 2025. Those newer branches should not be added to this CVE’s affected table merely because they are Windows products.
This is also why CVE-2026-85880 should not be confused with CVE-2026-81963, a separate actively exploited Windows Update Stack vulnerability affecting newer Windows branches.
Windows 10 patch eligibility matters
For Windows 10 21H2 and 22H2, Microsoft maps the September fixed builds to KB5122878. However, a fixed build existing does not mean every Windows 10 installation is automatically entitled to receive that update.
Microsoft’s September guidance applies to supported servicing states including relevant Extended Security Updates and LTSC editions. Ordinary Windows 10 22H2 free support ended in October 2025, so administrators should verify the device’s current support or ESU state before assuming that Windows Update will deliver the September 2026 security fix.
How should you verify the CVE-2026-85880 patch?
1. Identify the Windows release
Run winver or use the system information controls available on the endpoint to identify the exact Windows release.
2. Record the OS build
Compare the installed build with Microsoft’s fixed threshold for that release.
3. Check servicing eligibility
For Windows 10 and legacy Windows Server branches, confirm that the device is still in a supported servicing or ESU state that can receive current security updates.
4. Install a current supported update
If the device is below the fixed threshold, deploy the current Microsoft-supported cumulative security update through the organisation’s normal update-management process.
5. Verify the resulting build
Restart where required and confirm that the endpoint is now at or above the fixed build. Update history or enterprise inventory can provide secondary deployment evidence.
Does installing the patch prove the endpoint was never compromised?
No. A fixed build establishes the system’s current remediation state. It does not prove that exploitation did not occur before the update was installed.
Organisations with evidence or suspicion of earlier compromise should handle that as a separate incident-response question using endpoint telemetry, authentication records, EDR data and any later Microsoft, CISA or CERT guidance.
Are there CVE-specific indicators of compromise?
TPS did not verify a reliable public set of unique indicators, attacker artefacts or exploitation signatures attributable specifically to CVE-2026-85880 during this review.
The absence of published CVE-specific indicators should not be treated as proof that an affected endpoint is clean.
Is ransomware using CVE-2026-85880?
TPS did not verify a named ransomware operation or threat actor using CVE-2026-85880. Exploitation is confirmed through CISA KEV, but ransomware linkage remains unresolved.
What is CISA’s remediation deadline?
CISA lists a September 22, 2026 remediation due date for organisations subject to the applicable U.S. federal vulnerability-remediation directive.
That date should not be presented as a general legal deadline for Indian companies, private organisations or ordinary Windows users. Other operators should use their own risk-based patching requirements while treating known exploitation as a strong remediation priority.
What should endpoint teams do now?
- inventory Windows 10 and Windows Server 2012 through 2022 systems;
- compare installed builds with Microsoft’s fixed thresholds;
- verify servicing or ESU eligibility on older Windows branches;
- deploy a current supported cumulative security update where needed;
- confirm the resulting post-update build;
- do not classify CVE-2026-85880 as a remote unauthenticated Windows exploit;
- separate current patch-state verification from historical compromise investigation;
- monitor Microsoft, CISA and relevant national CERT guidance for exploitation details or new indicators.
What happens next?
This article should be updated if Microsoft revises the affected-product table, CISA publishes additional exploitation context, a validated exploit chain or IOC set becomes available, CERT-In issues material India-relevant guidance, or Microsoft changes servicing eligibility for affected legacy Windows branches.
TPS should maintain this same URL for material CVE-2026-85880 developments.
Verification note
TPS reviewed Microsoft’s CVE-2026-85880 vulnerability data, CISA known-exploitation status, Microsoft September 2026 Windows servicing information and current security reporting. The affected/fixed build boundaries and local privilege-escalation prerequisite are supported; attacker attribution, ransomware use, exploitation prevalence and unique CVE-specific indicators remain unresolved.



