Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4691 articles · 212580 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-81963KEVEXPLOITEDPATCHED
microsoft · windows 11 version 23h2

Windows Update Stack Elevation of Privilege Vulnerability

Description

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
microsoftwindows 11 version 23h210.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 10.0.26100.0, 10.0.26100.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963(vendor-advisory, patch)

Related News (3 articles)

Tier C
Qualys Blog2h ago
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
→ No new info (linked only)
Tier B
CCCS Canada2h ago
Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1
→ No new info (linked only)
Tier A
Microsoft MSRC7h ago
CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.0.22631.758210.0.26100.944510.0.26200.944510.0.28000.295410.0.26100.33438
CWECWE-59, CWE-284
PublishedSep 8, 2026
Last enriched3h ago
Trending Score135🔥
Source articles4
Independent4
Info Completeness3/14
Missing: vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85880EXPKEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Trending: 138
HIGHCVE-2026-63520EXPKEV
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 73
CRITICALCVE-2026-70352
Azure AI Language Elevation of Privilege Vulnerability
Trending: 64
CRITICALCVE-2026-69276
Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability
Trending: 60
CRITICALCVE-2026-69491
Microsoft DirectMusic Remote Code Execution Vulnerability
Trending: 60

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 8, 2026
Added to CISA KEV
Sep 8, 2026
Discovered by ZDM
Sep 8, 2026
Actively Exploited
Sep 8, 2026
Patch Available
Sep 8, 2026