CVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-81963Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 48% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-81963 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedNCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl
- unknownexploitedMicrosoft Monthly Security Update (September 2026)hkcert
- unknownexploitedSecurity Alert: Microsoft Releases September 2026 Security Updatesjpcert
- unknownexploitedMultiples vulnérabilités dans Microsoft Windows (09 septembre 2026)cert-fr-avis
- unknownexploitedMicrosoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1cccs
- highexploitedCVE-2026-81963: Improper link resolution before file access ('link following') in Windows Update Stack allows …nvd
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-81963: Microsoft Windows Link Following Vulnerabilitycisa-kev
Recent advisories for Windows Update Stack
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highexploitedCVE-2026-81963: Improper link resolution before file access ('link following') in Windows Update Stack allows …nvd · 2026-09-08
More from Microsoft Security Response Center
- mediumCVE-2026-18924: HTTP/2 server push UAF2026-09-08
- highCVE-2026-69630: Windows Win32k Elevation of Privilege Vulnerability2026-09-08
- unknownCVE-2026-83616: xmldom: Processing Instruction Target Injection Bypasses requireWellFormed2026-09-08
- unknownCVE-2026-85062: Colord: Slow rejection of oversized malformed color strings2026-09-08
- mediumCVE-2026-80834: crypto: sun8i-ce - Remove crypto_rng interface2026-09-08