CVE-2026-81963: Microsoft Windows Update Stack Privilege Escalation
- Severity
- HIGH
- Affected component
- microsoft (other)
- Patched version
- Not yet available
A high severity vulnerability in the Microsoft Windows Update Stack allows a local attacker to escalate privileges up to SYSTEM. This vulnerability is being actively exploited.
What happened
The Microsoft Windows Update Stack contains a link following vulnerability, tracked as CVE-2026-81963, that allows a local attacker to escalate privileges up to SYSTEM. This vulnerability has been confirmed to be actively exploited in the wild. The issue was first flagged on 2026-09-08T00:00:00+00:00 and confirmed on 2026-09-08T19:12:19.595985+00:00. The affected component is microsoft (other), but no authoritative version range has been published yet.
To assess your exposure, check if your systems are running any Microsoft software that relies on the Windows Update Stack. Given the severity and active exploitation, it is crucial to apply the latest Windows updates as soon as possible.
What to do about it
- Apply the latest Windows updates to mitigate the risk of exploitation.
- Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
- No official fix has been published yet for the specific component microsoft (other). Continue to monitor the sources below for updates.
How 0Day would have caught this
microsoft is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are running any Microsoft software that relies on the Windows Update Stack, you may be affected. However, no authoritative version range has been published yet.
What should I do right now?
Apply the latest Windows updates to mitigate the risk of exploitation. Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.
Has this been exploited in the wild?
Yes, this vulnerability is being actively exploited.
Sources
- NCSC-2026-0347 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Azure
- NCSC-2026-0348 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Dynamics
- NCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server
- NCSC-2026-0350 [1.00] [M/H] Kwetsbaarheden verholpen in SQL Server
- NCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Tools
- NCSC-2026-0352 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Office
- NCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windows
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities