HIGH 7.8 NVD ACTIVELY EXPLOITED
CVE-2026-81963
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Affected Products
- microsoft/windows_11_23h2
- microsoft/windows_11_24h2
- microsoft/windows_11_25h2
- microsoft/windows_11_26h1
- microsoft/windows_server_2025
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963
This high severity vulnerability with a CVSS score of 7.8 was published on 2026-09-08 via NVD. ⚠ This vulnerability is in the CISA Known Exploited Vulnerabilities (KEV) catalog — it is being actively exploited in the wild. Affected: microsoft/windows_11_23h2, microsoft/windows_11_24h2, microsoft/windows_11_25h2 and 2 more.
Risk Timeline
CVE Disclosed2026-09-08 · 2 days ago
CISA KEV — Actively ExploitedU.S. federal agencies required to patch · confirmed threat-actor activity
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-65801 | Microsoft Exchange Online Elevation of Privilege Vulnerability | CRITICAL | 10.0 |
| CVE-2026-69836 | Microsoft Entra ID Remote Code Execution Vulnerability | CRITICAL | 10.0 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.