CVE-2026-81963

Published Sep 8, 2026

Last updated 7 hours ago

Overview

Description
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows Link Following Vulnerability
Exploit added on
Sep 8, 2026
Exploit action due
Sep 22, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-59

Social media

Hype score
Not currently trending
  1. PATCH NOW: Microsoft fixed 974 CVEs, including 2 actively exploited zero-days: CVE-2026-85880 (ALPC) and CVE-2026-81963 (Windows Update Stack). Prioritize internet-facing and legacy Windows systems. https://t.co/Spu5IVoOht

    @Techsico_IT

    9 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Patch Tuesday September 2026: Microsoft fixed 974 CVEs, including two vulnerabilities exploited as zero-days (CVE-2026-85880 and CVE-2026-81963) https://t.co/jPeMod7ljD https://t.co/emjI691xA8

    @StetsonCG

    9 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Microsoft patched 966 CVEs yesterday, a record. Two exploited, both local EoP (ALPC CVE-2026-85880, Update Stack CVE-2026-81963): foothold to SYSTEM. Those first, every endpoint. Then DNS Server CVE-2026-69730 (9.8) on DCs. AI found the haystack. Triage is still yours. https://t.

    @vkhoetsyan

    9 Sept 2026

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Microsoft'un Eylül 2026 Salı yaması rekor kırdı: 974 CVE, bunlardan 2'si (CVE-2026-81963 & CVE-2026-85880) aktif istismar ediliyor. İkisi de SYSTEM yetkisine yükseltme sağlıyor. Sistemlerinizi hemen güncelleyin. #PatchTuesday #CyberSecurity #cvealert

    @mcsudann

    9 Sept 2026

    64 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 2 Windows zero-days are being actively exploited in the wild right now (CVE-2026-85880 and CVE-2026-81963). Both allow local sandbox escape to SYSTEM privileges without user interaction. Patch your systems immediately.

    @TirupMehta

    9 Sept 2026

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Microsoft's Patch Tuesday disclosed 973 bugs, including two actively exploited flaws, CVE-2026-81963 and CVE-2026-85880. CISA says federal agencies must patch by Sept. 22. #Microsoft #Windows #CISA https://t.co/IuFLIf5420

    @TweetThreatNews

    9 Sept 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Microsoft、2026年9月Patch Tuesdayでサイバー攻撃への悪用済み ゼロデイ 脆弱性 2件を修正 CVE-2026-81963・CVE-2026-85880 https://t.co/h0hwoiWqjf #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    @securityLab_jp

    8 Sept 2026

    169 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. マイクロソフトの定例更新。過去最高の脆弱性974件が修正。Windowsで723件、Officeで222件。ゼロデイはWindows ALPCのCVE-2026-85880とWindows Update StackのCVE-2026-81963。 https://t.co/vpzzxfM6ym 要注意なのはCVE-2026-55007(Exchange Server

    @__kokumoto

    8 Sept 2026

    851 Impressions

    2 Retweets

    2 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  9. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - Adobe Commerce/Magento: CVE-2026-75650(対処期限3日) - Windows: CVE-2026-81963, CVE-2026-85880 - N-able N-central: CVE

    @__kokumoto

    8 Sept 2026

    715 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Microsoft's September Patch Tuesday fixes two actively exploited Windows privilege-escalation zero-days: CVE-2026-81963 in Windows Update Stack and CVE-2026-85880 in Windows ALPC. #Cybersecurity #PatchTuesday https://t.co/U7kHsDzlaz

    @Divinmentis

    8 Sept 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880) https://t.co/LNs1nBSmWN https://t.co/7JHLuLIrln

    @TechMash365

    8 Sept 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Microsoft’s September Patch Tuesday is a monster drop — reports put it near a record ~974 CVEs across the catalog, with two actively exploited local EoP zero-days: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Update Stack (both path to SYSTEM). Windows 11 cumulat

    @sabatage

    8 Sept 2026

    285 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Microsoft September 2026 Patch Tuesday fixes a record 966 flaws, including two exploited zero-days: CVE-2026-81963 (Windows Update Stack EoP to SYSTEM) and CVE-2026-85880 (Windows ALPC EoP to SYSTEM). 105 Critical, 81 of them RCE. Microsoft ties the volume jump to AI-powered

    @XavierRiveraX

    8 Sept 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. News: Microsoft Sep 2026 Patch Tuesday is its largest ever: 966 flaws and 2 actively exploited zero-days. CVE-2026-81963 (Update Stack EoP to SYSTEM) and CVE-2026-85880 (ALPC EoP to SYSTEM). Patch Windows now. https://t.co/5jlF58ibty

    @snakeyesV1

    8 Sept 2026

    121 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Microsoft's September Patch Tuesday fixes 973 CVEs, its largest ever, and two are Windows zero-days already under attack, both local privilege escalation at CVSS 7.8: CVE-2026-85880 in ALPC and CVE-2026-81963 in the Windows Update stack. https://t.co/QIZVcgobE7

    @ITr0ckstar

    8 Sept 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Microsoft's September 2026 Patch Tuesday fixes two zero-day flaws, CVE-2026-81963 and CVE-2026-85880, both exploited in the wild. #PatchTuesday #ZeroDay #Microsoft #Windows #CyberSecurity #CVE #Infosec #VulnerabilityManagement https://t.co/zwhv2ceQpe

    @Daily_CyberSec

    8 Sept 2026

    338 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations