News

Windows Update Stack follows links to SYSTEM

Louis Stowasser
Louis Stowasser
Sunday 13 September 2026
Windows Update Stack follows links to SYSTEM
Windows Update Stack follows links to SYSTEM

CVE-2026-81963 is an actively exploited elevation-of-privilege flaw in the Windows Update Stack: the Windows operating-system machinery that installs updates and services components. It is not a standalone tool that an administrator chooses to deploy. It is present on affected Windows 11 endpoints and Windows Server 2025 machines, putting managed corporate PCs as well as servers running application, file, web, identity, virtualisation and storage workloads in scope.

Microsoft published the issue on September 8, 2026 and rates it Important, with a 7.8 CVSS v3.1 base score. The affected product list is specific: Windows 11 23H2, 24H2, 25H2 and 26H1, plus Windows Server 2025 and Server Core. It does not list Windows 10, Windows Server 2022, or older server releases, so broad claims that every supported Windows release is affected should not drive triage.

A local file redirection becomes SYSTEM

The Update Stack performs privileged operating-system maintenance. The flaw is improper link resolution before file access: in plain terms, it can follow a filesystem link without safely checking where that link finally points before accessing the target. A local attacker can use that mismatch to steer a privileged operation toward a file or location it should not handle.

An attacker needs an already authorized, low-privileged account and local access; no user interaction is required. Successful exploitation raises that account to SYSTEM, the highly privileged Windows security context. This makes it especially useful after initial access: a foothold obtained through another route can be converted into control broad enough to change system files, security settings, services or credentials.

Microsoft identifies the underlying classes as improper link resolution and improper access control, but its advisory does not name the affected function, file operation, or link type. Nor is there a published Microsoft source diff or verified binary-diff analysis to show the corrected check. That limitation matters: generic examples of link-following bugs should not be treated as an exploit recipe for this specific issue.

Exploitation is confirmed; public code is not

Microsoft marks CVE-2026-81963 as exploited, and CISA added it to the Known Exploited Vulnerabilities catalogue on September 8 with a September 22 remediation deadline. Microsoft’s temporal vector records functional exploit maturity, and its advisory says the bug was not publicly disclosed before the update. The vendor record is therefore enough to treat this as an urgent local escalation path, not a theoretical defect.

A public proof of concept has not been confirmed as of September 13, 2026. One aggregator labels a PoC available without identifying or linking code, while searches of common public exploit repositories found none. Active exploitation and functional exploit maturity are established; publicly obtainable exploit code is not. No attacker, victim, sector, malware family, initial-access method or exploitation volume has been publicly identified.

It was one of two exploited Windows zero-days addressed in the September release, alongside CVE-2026-85880; other fixes included CVE-2026-68839. That context should not dilute this CVE’s priority: its value to an intruder lies in taking a constrained local identity to SYSTEM.

Apply the matching cumulative update

Patches arrived in the September 8 cumulative updates, but there is no universal fixed build. Deploy KB5122880 for Windows 11 23H2, KB5124008 for 24H2 or 25H2, KB5124012 for 26H1, and KB5122871 for Windows Server 2025. Teams should verify the corresponding minimum builds—22631.7582, 26100.9445, 26200.9445, 28000.2954 and 26100.33438 respectively—rather than assuming that an unrelated update closes the gap.

Prioritise machines where ordinary users, contractors or service accounts can log on locally, then confirm installation and reboot completion through your normal update controls. For organisations with large mixed Windows estates, SecAlerts monitors an organisation's actual software stack and alerts on new vulnerabilities affecting the products it runs; that is useful here because the affected branches and fixes differ. Until patched, reduce unnecessary local access and investigate suspicious privilege changes, but don’t mistake those measures for a substitute for the cumulative update.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203