Windows Update Stack CVE-2026-81963: The Link-Following Zero-Day That Finishes the Job

By George Bailey   Published: 09/09/26   Updated: 09/09/26   3 min read

What Changed

Microsoft’s September 2026 Patch Tuesday—972 CVEs, a new monthly record—included two confirmed in-the-wild zero-days. One is the ALPC elevation of privilege BlueMoon already chains (CVE-2026-85880). The other is CVE-2026-81963, a link-following and improper access control bug in the Windows Update Stack. An authenticated local attacker with low privileges abuses how the update stack resolves links and lands at SYSTEM. No user interaction is required. CISA added the CVE to KEV on September 8.

Affected trains include Windows 11 versions 23H2, 24H2, 25H2, and 26H1, plus Windows Server 2025 (including Server Core). CrowdStrike and national CERTs flag it as the Update Stack elevation of privilege to prioritize first—not because a 7.8 outscores Netlogon 9.8 remote code execution bugs in the same release, but because Exploitation Detected outranks the base score for triage order.

Why This Matters Operationally

Local elevation-of-privilege bugs are easy to underrate until you remember the modern intrusion script: phishing or a browser exploit for a foothold, then escalate. The Update Stack is present on essentially every supported Windows endpoint and server, runs elevated during patch operations, and is the same machinery you would use to push the fix. An attacker who owns that path owns the eviction process. Commodity post-exploitation kits historically love reliable user-to-SYSTEM primitives; an Update Stack link-follower is exactly that class.

Pair this with BlueMoon’s browser-to-LPE narrative and September’s broader critical remote code execution list—Netlogon, DNS, DHCP, MSMQ, SSTP, Hyper-V escapes—and the month is not “one zero-day.” It is a reminder that foothold conversion and domain-controller services both need same-week attention.

What Defenders Should Verify First

Source Context

Ship the September cumulatives, prove they landed, and treat “local only” as “stage two of every foothold you already fear.”

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.