Skip to content

CVE-2026-81963

Windows Update Stack link following lets local attackers elevate privileges (CVE-2026-81963)

High 7.8 KEV Vendor: Microsoft Published

Microsoft's Windows Update Stack has a high-severity local elevation-of-privilege flaw, listed as exploited by CISA KEV and Microsoft. Apply the September 2026 updates for Windows 11 and Windows Server 2025.

What happened

An authenticated attacker with low privileges on a Windows device can exploit improper link resolution before file access in the Windows Update Stack. Successful exploitation gives the attacker SYSTEM-level control over the target, with high impact to confidentiality, integrity and availability. The CVSS vector also indicates the attack is local, low complexity, and requires no user interaction.

CISA has listed CVE-2026-81963 in the Known Exploited Vulnerabilities catalog, CISA's SSVC assessment marks exploitation as active, and Microsoft's advisory also records exploitation. The flaw was published on 8 September 2026 and has a CISA due date of 22 September 2026.

Who is affected

Affected products and versions before the fixed builds are:

  • Windows 11 version 23H2: 10.0.22631.0 through before 10.0.22631.7582
  • Windows 11 version 24H2: 10.0.26100.0 through before 10.0.26100.9445
  • Windows 11 version 25H2: 10.0.26200.0 through before 10.0.26200.9445
  • Windows 11 version 26H1: 10.0.28000.0 through before 10.0.28000.2954
  • Windows Server 2025: 10.0.26100.0 through before 10.0.26100.33438
  • Windows Server 2025 (Server Core installation): 10.0.26100.0 through before 10.0.26100.33438

These are Windows 11 client and Windows Server 2025 deployments. The Windows Update Stack is a core servicing component present on all of them.

What to do now

  1. Apply the September 2026 security update for your version:
  • Windows 11 23H2: 10.0.22631.7582 (KB5122880)
  • Windows 11 24H2: 10.0.26100.9445 (KB5124008)
  • Windows 11 25H2: 10.0.26200.9445 (KB5124008)
  • Windows 11 26H1: 10.0.28000.2954 (KB5124012)
  • Windows Server 2025 and Server Core: 10.0.26100.33438 (KB5122871)
  1. Prioritise systems using CISA KEV guidance. The due date is 22 September 2026; CISA's required action references BOD 26-04 prioritisation and forensics triage requirements.
  2. There is no vendor workaround listed. Restrict local account privileges and review privileged group membership on any machine that cannot be updated immediately, but treat the update as the only complete remediation.

Beyond the patch

Because CISA and Microsoft both list this vulnerability as exploited, detection and response matter as much as the patch. Our Managed Detection & Response (MDR) service watches for post-exploitation activity following a local privilege escalation, and Supply Chain Defense & Third-Party Risk helps your team track vendor patch cycles and deadlines such as the CISA KEV due date, so updates like this are scheduled before they become urgent.

Affected and fixed versions

ProductAffectedFixed in
Windows 11 version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H210.0.22631.0 – < 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H210.0.26100.0 – < 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H210.0.26200.0 – < 10.0.26200.944510.0.26200.9445
Windows 11 version 26H110.0.28000.0 – < 10.0.28000.295410.0.28000.2954
Windows Server 202510.0.26100.0 – < 10.0.26100.3343810.0.26100.33438
(Server Core installation) 10.0.26100.33438
Windows Server 2025 (Server Core installation)10.0.26100.0 – < 10.0.26100.3343810.0.26100.33438

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.