Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [cve, windows, kernel, zero-day, patch-gap, state-sponsored] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, defence, critical-infrastructure] ยท au_impact: true

CVE-2026-85880 is a heap-based buffer overflow in the Windows kernel's ALPC (asynchronous local procedure call) component, used as the local privilege escalation stage of the "BlueMoon" browser exploit chain. After CVE-2026-85046 and CVE-2026-87491 compromise the Chrome V8 sandbox, this kernel flaw lets an attacker escape Chrome's sandboxed renderer process and inject code into the Chrome browser process, from which a payload of the actor's choice is deployed. It overlaps with one of the two actively exploited Windows zero-days patched in Microsoft's September 2026 Patch Tuesday release, and was added to the CISA Known Exploited Vulnerabilities catalogue.

Multiple Chinese-linked espionage groups used the identical chain, indicating shared exploit brokering or supply.

Attribute Detail
CVE CVE-2026-85880
Type Heap-based buffer overflow (Windows kernel / ALPC)
Exploited In the wild (Chrome chain, Augโ€“Sep 2026)
Chain CVE-2026-85046 + CVE-2026-87491 + CVE-2026-85880
Source Volexity โ€” Tier 1/4

Source