CVE-2026-81963

high

Description

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

From the Tenable Blog

September 2026 Microsoft Patch Tuesday | Tenable®
September 2026 Microsoft Patch Tuesday | Tenable®

Published: 2026-09-08

Microsoft patched 964 CVEs in September, the most ever in a Patch Tuesday release in its history, including two zero-day vulnerabilities exploited in the wild.

References

Details

Source: Mitre, NVD

Published: 2026-09-08

Updated: 2026-09-09

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00631