CVE-2026-81963
Microsoft · Published September 8, 2026
7.8
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows 11 23h2 < 10.0.22631.7582
- Windows 11 24h2 < 10.0.26100.9445
- Windows 11 25h2 < 10.0.26200.9445
- Windows 11 26h1 < 10.0.28000.2954
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H