CVE-2026-81963
Windows Update Stack link following lets local attackers elevate privileges (CVE-2026-81963)
Microsoft's Windows Update Stack has a high-severity local elevation-of-privilege flaw, listed as exploited by CISA KEV and Microsoft. Apply the September 2026 updates for Windows 11 and Windows Server 2025.
What happened
An authenticated attacker with low privileges on a Windows device can exploit improper link resolution before file access in the Windows Update Stack. Successful exploitation gives the attacker SYSTEM-level control over the target, with high impact to confidentiality, integrity and availability. The CVSS vector also indicates the attack is local, low complexity, and requires no user interaction.
CISA has listed CVE-2026-81963 in the Known Exploited Vulnerabilities catalog, CISA's SSVC assessment marks exploitation as active, and Microsoft's advisory also records exploitation. The flaw was published on 8 September 2026 and has a CISA due date of 22 September 2026.
Who is affected
Affected products and versions before the fixed builds are:
- Windows 11 version 23H2: 10.0.22631.0 through before 10.0.22631.7582
- Windows 11 version 24H2: 10.0.26100.0 through before 10.0.26100.9445
- Windows 11 version 25H2: 10.0.26200.0 through before 10.0.26200.9445
- Windows 11 version 26H1: 10.0.28000.0 through before 10.0.28000.2954
- Windows Server 2025: 10.0.26100.0 through before 10.0.26100.33438
- Windows Server 2025 (Server Core installation): 10.0.26100.0 through before 10.0.26100.33438
These are Windows 11 client and Windows Server 2025 deployments. The Windows Update Stack is a core servicing component present on all of them.
What to do now
- Apply the September 2026 security update for your version:
- Windows 11 23H2: 10.0.22631.7582 (KB5122880)
- Windows 11 24H2: 10.0.26100.9445 (KB5124008)
- Windows 11 25H2: 10.0.26200.9445 (KB5124008)
- Windows 11 26H1: 10.0.28000.2954 (KB5124012)
- Windows Server 2025 and Server Core: 10.0.26100.33438 (KB5122871)
- Prioritise systems using CISA KEV guidance. The due date is 22 September 2026; CISA's required action references BOD 26-04 prioritisation and forensics triage requirements.
- There is no vendor workaround listed. Restrict local account privileges and review privileged group membership on any machine that cannot be updated immediately, but treat the update as the only complete remediation.
Beyond the patch
Because CISA and Microsoft both list this vulnerability as exploited, detection and response matter as much as the patch. Our Managed Detection & Response (MDR) service watches for post-exploitation activity following a local privilege escalation, and Supply Chain Defense & Third-Party Risk helps your team track vendor patch cycles and deadlines such as the CISA KEV due date, so updates like this are scheduled before they become urgent.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Windows 11 version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 23H2 | 10.0.22631.0 – < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 | 10.0.26100.0 – < 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 | 10.0.26200.0 – < 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 26H1 | 10.0.28000.0 – < 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2025 | 10.0.26100.0 – < 10.0.26100.33438 | 10.0.26100.33438 (Server Core installation) 10.0.26100.33438 |
| Windows Server 2025 (Server Core installation) | 10.0.26100.0 – < 10.0.26100.33438 | 10.0.26100.33438 |