Windows Update Stack CVE-2026-81963: exploited path to SYSTEM

Published 09 Sep 2026 · Severity: high

Microsoft's 8 September 2026 security release addresses CVE-2026-81963, an actively exploited Windows Update Stack vulnerability. CISA describes improper link resolution before file access that lets a local attacker elevate privileges to SYSTEM. Microsoft’s affected-product matrix covers supported Windows 11 versions 23H2, 24H2, 25H2 and 26H1, plus Windows Server 2025 including Server Core; use the Security Update Guide to map each asset to its applicable September update. Prioritise systems where an attacker could already obtain local code execution, and verify the fixed build after reboot.