CVE-2026-81963, a CVSS 7.8 link-following vulnerability in the Windows Update Stack, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 8, 2026 — the same day as a separate Windows elevation-of-privilege flaw, CVE-2026-85880. NVD’s vector shows a locally-exploitable flaw requiring low privileges and no user interaction, with high impact across confidentiality, integrity, and availability.
What the vulnerability does
NVD tracks CVE-2026-81963 under CWE-59 (Improper Link Resolution Before File Access, “link following”) and CWE-284 (Improper Access Control). Per NVD’s description, improper link resolution before file access in the Windows Update Stack allows an authorized (already locally logged-in) attacker to elevate privileges locally — a classic symlink/junction-style attack pattern, where a process with elevated permissions follows a file-system link controlled by a lower-privileged user into a location it shouldn’t have access to.
Why it’s on KEV
CISA’s September 8 KEV addition requires federal civilian agencies to remediate under BOD 26-04. Microsoft’s advisory is available through the MSRC Update Guide, linked from NVD’s reference data.
What we don’t yet have
CVSS scoring and the vulnerability description trace to NVD alone; confidence on severity is marked medium pending a second independent source. No EPSS score is ingested for this CVE, and NVD’s product tagging doesn’t specify affected Windows versions or builds beyond the general “Windows” tag.
Why this matters
The Windows Update Stack runs with elevated privileges by design — it has to, in order to install updates system-wide — which makes a privilege-escalation bug specifically inside it more consequential than an equivalent bug in a lower-privileged component, since it’s already positioned to touch the highest-value parts of the OS. As with CVE-2026-85880, this is a local rather than remote flaw, meaning it’s most dangerous as a second stage chained after initial access. The two Windows CVEs sharing the same September 8 KEV addition date, both local-privilege-escalation bugs, should be patched together — organizations applying Microsoft’s monthly update cycle should confirm both specific fixes are included rather than assuming a general “latest cumulative update” covers both without checking.
Frequently Asked Questions
What is CVE-2026-81963? A CVSS 7.8 improper link-resolution vulnerability in the Windows Update Stack that allows a locally-authenticated attacker to elevate privileges.
Is CVE-2026-81963 being actively exploited? Yes — CISA added it to the Known Exploited Vulnerabilities catalog on September 8, 2026.
What should Windows administrators do? Apply Microsoft’s fix per the MSRC Update Guide advisory for CVE-2026-81963, and prioritize alongside CVE-2026-85880, added to KEV the same day.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 15, 2026. See more vulnerability intelligence.