CISA_KEV · SEPTEMBER 2026 · CONFIRMED

CVE-2026-81963: Microsoft Windows Update Stack Privilege Escalation

Severity
HIGH
Affected component
microsoft (other)
Patched version
Not yet available
CVE-2026-81963

A high severity vulnerability in the Microsoft Windows Update Stack allows a local attacker to escalate privileges up to SYSTEM. This vulnerability is being actively exploited.

What happened

The Microsoft Windows Update Stack contains a link following vulnerability, tracked as CVE-2026-81963, that allows a local attacker to escalate privileges up to SYSTEM. This vulnerability has been confirmed to be actively exploited in the wild. The issue was first flagged on 2026-09-08T00:00:00+00:00 and confirmed on 2026-09-08T19:12:19.595985+00:00. The affected component is microsoft (other), but no authoritative version range has been published yet.

To assess your exposure, check if your systems are running any Microsoft software that relies on the Windows Update Stack. Given the severity and active exploitation, it is crucial to apply the latest Windows updates as soon as possible.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If microsoft is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are running any Microsoft software that relies on the Windows Update Stack, you may be affected. However, no authoritative version range has been published yet.

What should I do right now?

Apply the latest Windows updates to mitigate the risk of exploitation. Monitor the primary sources for updates on the vulnerability and any additional patches that may be released.

Has this been exploited in the wild?

Yes, this vulnerability is being actively exploited.

Sources

Join the 0Day waitlist →

← Back to all threats