ZeroDayAlert

CVE-2026-81963: Microsoft Windows Link Following Vulnerability

Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

Microsoft Windows Added to KEV 2026-09-08 Federal due 2026-09-22 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Microsoft Windows systems with the Windows Update Stack component are vulnerable to privilege escalation by local attackers. The vulnerability allows an attacker with local access to gain SYSTEM-level permissions. The record does not specify which Windows versions or editions are affected, nor does it indicate whether this affects Windows Server, client installations, or both.

How to check whether this touches you

  • Inventory all Windows systems in your environment, noting their edition and role (desktop, laptop, server).
  • Determine which machines permit local logon by non-administrative users, or which run services that execute code in unprivileged contexts.
  • Cross-reference your Windows versions against the patch bulletin when available; version fingerprints (via winver or Get-ComputerInfo) are a signal of exposure but do not account for backported fixes or hotfixes already installed.
  • Check Windows Update logs and installed KB articles to establish your current patch state, since some organisations apply security fixes outside the main monthly cycle.

What to do

  1. Obtain the Microsoft security bulletin for CVE-2026-81963 and identify the exact versions and editions affected, along with available patches.
  2. Prioritise systems that accept remote desktop connections, host multi-tenant services, or run privileged background tasks as higher risk.
  3. Until you can patch, restrict local logon rights to administrative accounts only; disable or restrict any local accounts used for service execution.
  4. Configure audit logging to capture local logon events and privilege escalation attempts; review logs regularly for any suspicious activity predating patch application.
  5. Apply patches according to CISA BOD 26-04 guidance (federal systems have a due date of 22 September 2026; others should follow the same risk-based timeline).
  6. For cloud-hosted Windows systems, verify with your provider that patches are applied; if mitigations are unavailable, escalate to your change control board for discontinuation review.
  7. Test patches in a non-production environment first to confirm compatibility with your applications and monitoring agents.

If you find you were exposed

Exploitation of link-following vulnerabilities typically occurs when an attacker has already gained local access, so review system and application logs from at least 90 days before the patch became available. Check for unexpected privilege escalation events, SYSTEM-level processes spawned from user contexts, and changes to scheduled tasks or startup programs. Log retention limits will constrain your retrospective search; prioritise high-value targets (domain controllers, centralised services, administrative workstations) for deeper forensic analysis if your retention permits.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-81963 is being exploited. It cannot tell you whether Windows is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →