Microsoft Windows Update Stack Link-Following Privilege Escalation
“Windows Update Stack link-following flaw lets a local attacker escalate to SYSTEM. CVSS 7.8, actively exploited, on CISA KEV.”
- Vendor
- Microsoft
- Product
- Windows
- CVSS
- 7.8
- EPSS (exploit probability)
- N/A
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
Windows Update Stack contains an improper link resolution vulnerability (link following) that allows a local attacker to escalate privileges to SYSTEM level.
Patched September 8, 2026 as part of Microsoft’s record September Patch Tuesday, which addressed 974 CVEs total. CISA added CVE-2026-81963 to its Known Exploited Vulnerabilities catalog the same day. Federal agencies must apply mitigations by September 22, 2026 per BOD 26-04.
Like CVE-2026-85880, this flaw is not directly remotely exploitable: local access is a required precondition. Both CVEs are standard post-compromise privilege escalation tools, and CISA’s active-exploitation tag on both confirms they are in use in real intrusions.
For full Patch Tuesday context, see Microsoft Patches Record 974 Vulns, 2 Zero-Days.