AI analysis
CVE-2026-85360 is a use-after-free (CWE-416) memory-safety flaw in the Windows kernel. An attacker with valid low-privileged local access must execute code that triggers the flawed kernel memory handling (rated high attack complexity, suggesting a timing- or race-sensitive trigger), causing the kernel to reference freed memory. Successful exploitation elevates the attacker's privileges locally, typically to SYSTEM, giving full control of the affected machine. It affects a broad range of supported Windows 10 and Windows 11 client builds as well as Windows Server 2012 through 2022, so nearly any Windows endpoint or server in an organization's fleet may be in scope. No public proof-of-concept, no CISA KEV listing, and a low EPSS (0.2%, 14th percentile) indicate exploitation is not known at publication, though the flaw was disclosed amid Microsoft's September 2026 Patch Tuesday, which fixed 973 vulnerabilities including two exploited zero-days.
What to do: Apply Microsoft's September 2026 cumulative security updates for each affected Windows 10, Windows 11, and Windows Server build via Windows Update, WSUS, or your patch-management platform, and verify the OS build number after installation. No workaround is practical for a kernel use-after-free, so patching is the primary mitigation; prioritize multi-user workstations, VDI hosts, and servers where low-privileged users or local code execution occur. Track Microsoft advisories for updates on exploitation status, since only two zero-days were reported as exploited in this Patch Tuesday cycle and this flaw is not confirmed among them.
Affected
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 10 | 22H2 |
| microsoft Windows 11 | 23H2 |
| microsoft Windows 11 | 24H2 |
| microsoft Windows 11 | 25H2 |
| microsoft Windows 11 | 26H1 |
| microsoft Windows Server | 2012 |
| microsoft Windows Server | 2016 |
| microsoft Windows Server | 2019 |
| microsoft Windows Server | 2022 |
Estimated exposure
mass≈1 billion+ Windows 10/11 devices plus enterprise Windows Server deployments — The affected builds span nearly all supported Windows 10 and Windows 11 client versions plus Windows Server 2012–2022, against a widely cited installed base of roughly 1.4 billion Windows 10/11 devices, so the potential footprint is on the…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.