• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-81963: local privilege escalation in Microsoft Windows

A local, authorized attacker can exploit a link-following flaw in the Windows Update Stack to elevate privileges to SYSTEM on affected Windows builds (CVE-2026-81963). The issue impacts multiple Windows 11 branches and Windows Server 2025 builds; affected ranges include 10.0.22631.0 through versions before 10.0.22631.7582, 10.0.26100.0 through before 10.0.26100.9445/33438, 10.0.26200.0 through before 10.0.26200.9445, and 10.0.28000.0 through before 10.0.28000.2954. An attacker requires local (authorized) access; no user interaction is required.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00393
CWE
CWE-59
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent patching is warranted: CISA added this vulnerability to the Known Exploited Vulnerabilities catalog with a remediation deadline, so prioritize installing the vendor fixes listed for the affected builds immediately.

What is CVE-2026-81963?

A local, authorized attacker can exploit a link-following flaw in the Windows Update Stack to elevate privileges to SYSTEM on affected Windows builds (CVE-2026-81963). The issue impacts multiple Windows 11 branches and Windows Server 2025 builds; affected ranges include 10.0.22631.0 through versions before 10.0.22631.7582, 10.0.26100.0 through before 10.0.26100.9445/33438, 10.0.26200.0 through before 10.0.26200.9445, and 10.0.28000.0 through before 10.0.28000.2954. An attacker requires local (authorized) access; no user interaction is required. The weakness is classified as CWE-59 (Link Following).

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows are affected?

BRANCHAFFECTEDFIXED
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.758210.0.22631.7582
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.944510.0.26100.9445
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.944510.0.26200.9445
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.295410.0.28000.2954
Windows Server 2025 10.x10.0.26100.0 – before 10.0.26100.3343810.0.26100.33438
Windows Server 2025 (Server Core installation) 10.x10.0.26100.0 – before 10.0.26100.3343810.0.26100.33438

Is CVE-2026-81963 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-08, and U.S. federal agencies were required to remediate it by 2026-09-22.

How to fix CVE-2026-81963

  1. Install Microsoft updates that move affected builds to the fixed releases (for example 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, or 10.0.26100.33438 as applicable).
  2. Prioritize deployment according to CISA’s guidance and your organization’s exposure and risk assessments.
  3. Limit local account privileges and reduce the number of users with the ability to run or install updates until systems are patched.
  4. Monitor endpoints for unusual local privilege escalation activity and follow vendor forensics guidance.

Frequently asked questions

Is CVE-2026-81963 being actively exploited?

CISA added CVE-2026-81963 to its Known Exploited Vulnerabilities catalog on 2026-09-08, and U.S. federal agencies were required to remediate it by 2026-09-22.

Which Windows versions are affected by CVE-2026-81963?

Windows 11 builds across multiple branches and Windows Server 2025 builds in the ranges listed in vendor advisories are affected, including 10.0.22631.0 up to before 10.0.22631.7582 and other similar ranges shown by Microsoft.

Is there a patch for CVE-2026-81963?

Yes. Microsoft published updates that fix affected builds; fixed build examples include 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, 10.0.28000.2954, and 10.0.26100.33438.

Does CVE-2026-81963 require authentication?

Yes. The vulnerability requires a local, authorized attacker on affected Windows systems to exploit the link-following flaw.

References