๐Ÿ” CVE Alert

CVE-2026-81963

HIGH 7.8 โš ๏ธ CISA KEV

Windows Update Stack Elevation of Privilege Vulnerability

CVSS Score
7.8
EPSS Score
0.6%
EPSS Percentile
48th

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Vendor microsoft
Product windows 11 version 23h2
Ecosystems
Industries
TechnologyEnterprise
Published Sep 8, 2026
Last Updated Sep 15, 2026
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for microsoft windows 11 version 23h2

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-81963.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Microsoft / Windows 11 version 23H2
10.0.22631.0 < 10.0.22631.7582
Microsoft / Windows 11 Version 23H2
10.0.22631.0 < 10.0.22631.7582
Microsoft / Windows 11 Version 24H2
10.0.26100.0 < 10.0.26100.9445
Microsoft / Windows 11 Version 25H2
10.0.26200.0 < 10.0.26200.9445
Microsoft / Windows 11 version 26H1
10.0.28000.0 < 10.0.28000.2954
Microsoft / Windows Server 2025
10.0.26100.0 < 10.0.26100.33438
Microsoft / Windows Server 2025 (Server Core installation)
10.0.26100.0 < 10.0.26100.33438

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
msrc.microsoft.com: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81963