Vulnerability record · CVE-2026-81963 · published 8 September 2026
CVE-2026-81963: Windows Update Stack link-following privilege escalation
Microsoft · Windows 11 23h2
Windows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284). A local attacker with low privileges can exploit this to gain elevated rights on affected Windows 11 and Windows Server 2025 systems.
Description
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 high severity with confirmed KEV listing and a short remediation deadline, though exploitation requires local low-privileged access and EPSS is low.
What it is
Windows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284). A local attacker with low privileges can exploit this to gain elevated rights on affected Windows 11 and Windows Server 2025 systems.
Impact
An attacker gains full compromise of confidentiality, integrity and availability at the elevated level, effectively local privilege escalation to SYSTEM or administrator.
Attack surface
Reached locally; the CVSS vector AV:L/PR:L/UI:N indicates an authorized low-privileged local user is required and no user interaction is needed. No network or remote vector is described.
Exploitation
CISA added this to KEV on 2026-09-08 with a remediation due date of 2026-09-22, indicating known exploitation, though EPSS 30-day probability is low at 0.00631 (48.6th percentile) and no ransomware use is documented.
What to do
- Apply the Microsoft update from the MSRC advisory for CVE-2026-81963 to all affected Windows 11 23H2/24H2/25H2/26H1 and Windows Server 2025 systems.
- Prioritize patching per CISA BOD 26-04 guidance and meet the 2026-09-22 KEV due date.
- Restrict local interactive logon and privileged account use on affected hosts to reduce the low-privileged foothold needed.
- If mitigations are unavailable, follow CISA guidance to discontinue use of the affected product.
- Audit and harden file system link handling and permissions in Windows Update Stack paths.
Detection
- Monitor for unexpected creation or modification of symbolic links or junctions in Windows Update directories.
- Alert on processes accessing Windows Update Stack files with unusual parent processes or elevated tokens.
- Correlate local privilege escalation events (e.g., token or process creation anomalies) with update service activity.
- Review host telemetry for post-exploitation behavior on systems pending the KEV remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-81963 to the Known Exploited Vulnerabilities catalog on 8 September 2026 as "Microsoft Windows Link Following Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 22 September 2026.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963 | US Government Resource |
Track CVE-2026-81963 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-81963), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.