RaqibCTI
CVE

CVE-2026-85880

P2
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft · Windows
Date added (CISA)
2026-09-08
Remediation due
2026-09-22
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • msgbox.execampaignCorrelated cluster2026-09-21
  • CVE-2026-85880campaignCorrelated cluster2026-09-09
  • CVE-2026-81963campaignCorrelated cluster2026-09-08

ATT&CK mapping

No ATT&CK mapping yet
The CTID Mappings Explorer hasn't published an exploitation/impact technique mapping for this CVE yet.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2026-85880: Microsoft Windows Heap-Based Buffer Overflow Vulnerability · RaqibCTI