CVE-2026-85880 (Windows ALPC heap overflow) and CVE-2026-81963 (Windows Update Stack) were added to CISA’s Known Exploited Vulnerabilities catalog after confirmed active exploitation. Both allow an already-authenticated local attacker to escalate to SYSTEM privileges. The federal remediation deadline for both is today, and fixes have been available since Microsoft’s September Patch Tuesday.
