CVE-2026-81963: presente nel catalogo CISA KEV
CVE-2026-81963 · CVSS 7.8 HIGH · KEV 2026-09-08 · patch disponibile
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-81963 viene sfruttato?
- Inserito nel catalogo CISA KEV il 2026-09-08.
- Scadenza di remediation federale: 2026-09-22.
- Codice di exploit pubblico: nessuno trovato nelle fonti monitorate.
Quali prodotti e versioni sono interessati?
- Microsoft · Windows 11 version 23H2 · >= 10.0.22631.0, < 10.0.22631.7582
- Microsoft · Windows 11 Version 24H2 · >= 10.0.26100.0, < 10.0.26100.9445
- Microsoft · Windows 11 Version 25H2 · >= 10.0.26200.0, < 10.0.26200.9445
- Microsoft · Windows 11 version 26H1 · >= 10.0.28000.0, < 10.0.28000.2954
- Microsoft · Windows Server 2025 · >= 10.0.26100.0, < 10.0.26100.33438
- Microsoft · Windows Server 2025 (Server Core installation) · >= 10.0.26100.0, < 10.0.26100.33438
- Microsoft · Windows 11 Version 25H2 for ARM64-based Systems · < 10.0.26200.9445
- Microsoft · Windows 11 Version 25H2 for x64-based Systems · < 10.0.26200.9445
- Microsoft · Windows 11 Version 23H2 for ARM64-based Systems · < 10.0.22631.7582
- Microsoft · Windows 11 Version 23H2 for x64-based Systems · < 10.0.22631.7582
- Microsoft · Windows 11 Version 26H1 for ARM64-based Systems · < 10.0.28000.2954
- Microsoft · Windows 11 version 26H1 for x64-based Systems · < 10.0.28000.2954
Esiste una patch?
Cosa ha pubblicato PlainSec su CVE-2026-81963
Fonti primarie
Cosa questa scheda non dice
KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-09-09.