CVE-2026-81963: listed in the CISA KEV catalog
CVE-2026-81963 · CVSS 7.8 HIGH · KEV 2026-09-08 · patch available
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Is CVE-2026-81963 exploited?
- Listed in the CISA KEV catalog on 2026-09-08.
- Federal remediation due 2026-09-22.
- Public exploit code: none found in monitored sources.
Which products and versions are affected?
- Microsoft · Windows 11 version 23H2 · >= 10.0.22631.0, < 10.0.22631.7582
- Microsoft · Windows 11 Version 24H2 · >= 10.0.26100.0, < 10.0.26100.9445
- Microsoft · Windows 11 Version 25H2 · >= 10.0.26200.0, < 10.0.26200.9445
- Microsoft · Windows 11 version 26H1 · >= 10.0.28000.0, < 10.0.28000.2954
- Microsoft · Windows Server 2025 · >= 10.0.26100.0, < 10.0.26100.33438
- Microsoft · Windows Server 2025 (Server Core installation) · >= 10.0.26100.0, < 10.0.26100.33438
- Microsoft · Windows 11 Version 25H2 for ARM64-based Systems · < 10.0.26200.9445
- Microsoft · Windows 11 Version 25H2 for x64-based Systems · < 10.0.26200.9445
- Microsoft · Windows 11 Version 23H2 for ARM64-based Systems · < 10.0.22631.7582
- Microsoft · Windows 11 Version 23H2 for x64-based Systems · < 10.0.22631.7582
- Microsoft · Windows 11 Version 26H1 for ARM64-based Systems · < 10.0.28000.2954
- Microsoft · Windows 11 version 26H1 for x64-based Systems · < 10.0.28000.2954
Is there a patch?
What PlainSec published about CVE-2026-81963
Primary sources
What this record does not say
KEV and EPSS are re-checked daily. Record last updated 2026-09-09.