CTIPilot

Windows ALPC heap-based buffer overflow EoP / AppContainer sandbox escape to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, legacy line (Windows 10, Server 2012-2022)

cve · CVE-2026-85880

Coverage timeline
1
first 2026-09-09 → last 2026-09-09
Peak priority
high
1 high
Sources cited
5
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
3
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-09-09/windows-september-2026-two-exploited-lpe-zero-days-kev · ATT&CK page ↗

Story timeline

  1. 2026-09-09September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)
    trending-vulnerabilitiesMicrosoft names two exploited Windows privilege-escalation zero-days, splitting the newest and legacy build lines

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • msrc.microsoft.com2 (40%)
  • bleepingcomputer.com1 (20%)
  • cisa.gov1 (20%)
  • zerodayinitiative.com1 (20%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Windows ALPC heap-based buffer overflow EoP / AppContainer sandbox escape to SYSTEM (CVSS 7.8), actively exploited zero-day, CISA KEV 2026-09-08, legacy line (Windows 10, Server 2012-2022) (1)

2026-09-09 · view entry permalink →

HIGHCVE-2026-81963 +1exploitedNATOA1

September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)

Microsoft's September 2026 Patch Tuesday marked exactly two of its roughly 1,170 fixed CVEs as exploited in the wild, and both are local privilege-escalation bugs that raise an existing low-privilege foothold to SYSTEM rather than remote-entry vectors (Microsoft MSRC, 2026-09-08; Zero Day Initiative, 2026-09-08). CVE-2026-81963 (CVSS 7.8) is an improper-link-resolution flaw in the Windows Update Stack: "Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally" (Microsoft MSRC, 2026-09-08); it affects the newest generation, Windows Server 2025 and Windows 11 (23H2 through 26H1), and Microsoft's own CVSS temporal metric records a functional exploit (E:F). CVE-2026-85880 (CVSS 7.8) is a heap-based buffer overflow in Windows ALPC, the core local inter-process-communication mechanism, which Microsoft describes explicitly as a sandbox escape: "An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required" (Microsoft MSRC, 2026-09-08); it affects only the legacy/long-support line, Windows 10 and Windows Server 2012 through 2022, and not Windows 11 or Server 2025 (BleepingComputer, 2026-09-08). The two zero-days split cleanly across the newest and legacy Windows generations, so a mixed estate needs both September cumulative updates to close the exposure.

Neither Microsoft nor the crediting researchers (its own Threat Intelligence Center with Romain Deperne for the Update Stack bug; Volexity and Proofpoint for the ALPC bug) published IOCs, a named intrusion cluster, or exploitation-chain detail, and ZDI notes the scope of exploitation is unknown: "This is the first bug being exploited in the wild, but we know little about how broadly that exploitation is. The bug itself is a privilege escalation in the Update Stack, which is worrisome, but I doubt the automatic update process itself is compromised. More likely is that this bug is being combined with a code execution bug to spread malware or ransomware. Patch this one quickly" (Zero Day Initiative, 2026-09-08). Because both are post-foothold escalation primitives, the actionable telemetry class is process-creation and privilege-token events that follow a lower-integrity code-execution event on the same host: a Windows Update service-context process performing file operations through a symbolic link, or a sandboxed AppContainer process acquiring a higher-integrity or SYSTEM token, correlated with a preceding lower-privilege, non-installer execution. No workaround exists for either bug class, so the September cumulative updates are the only mitigation; CISA added both to its Known Exploited Vulnerabilities catalog on 2026-09-08 (CISA, 2026-09-08). The KEV remediation date is a US-agency compliance deadline; the operational driver for the Swiss federal, cantonal and communal AD and endpoint estate is the confirmed active exploitation, which makes both fixes a prioritized rollout rather than a routine Patch Tuesday item.

Triage: both bugs manifest only after an attacker already runs code on the host, so the signal is a privilege transition, not an initial-access event: a low-integrity or AppContainer-sandboxed process acquiring a SYSTEM or higher-integrity token with no legitimate installer or servicing context is the discriminator. Routine software installation and Windows servicing also elevate to SYSTEM, so correlate the token change with a preceding low-privilege, non-installer execution rather than alerting on elevation alone.

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required.

Microsoft MSRC 2026-09-08

This is the first bug being exploited in the wild, but we know little about how broadly that exploitation is. The bug itself is a privilege escalation in the Update Stack, which is worrisome, but I doubt the automatic update process itself is compromised. More likely is that this bug is being combined with a code execution bug to spread malware or ransomware. Patch this one quickly.

Zero Day Initiative (Trend Micro) 2026-09-08
vulnerability09 Sep 17:45Zmulti-sourceOpen finding ↗