The Update Stack elevation-of-privilege zero-day is not new — but today is the federal due date. If September’s cumulative update is not verified on Windows 11 and Server 2025 fleets, Tuesday is the day the ticket stops waiting.
What happened
CVE-2026-81963 is a link-following / improper access control bug in the Windows Update Stack. A local attacker with low privileges abuses how the stack resolves links and escalates to SYSTEM. No user interaction required. Microsoft shipped the fix in the September 2026 cumulatives; CISA added it to KEV on September 8 with a BOD 26-04 due date of September 22, 2026. Forensic triage is required.
Affected trains include Windows 11 23H2 / 24H2 / 25H2 / 26H1 and Windows Server 2025 (including Server Core). Example fixed builds cited in public guidance: 22631.7582, 26100.9445, 26200.9445, 28000.2954, and Server 2025 26100.33438 (verify against Microsoft’s update guide for your SKU).
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Note: the sibling ALPC zero-day (CVE-2026-85880) shares the same KEV due date. If you patched ALPC last week but skipped Update Stack coverage on some rings, finish the pair today.
Why it matters
Local EoP is stage two of nearly every modern intrusion. The Update Stack runs elevated during patch operations and sits on essentially every supported endpoint — which means an attacker who owns that path owns the eviction process. CVSS 7.8 looks modest next to 9.8 RCEs; Exploitation Detected is why it still clears the KEV bar and why today’s clock matters.
What to do first
- Verify September 2026 cumulatives that remediate CVE-2026-81963 are installed and running — not merely approved in WSUS/Intune.
- Prioritize endpoints that already showed suspicious local code execution, browser exploit indicators, or BlueMoon-adjacent process trees.
- Close the ALPC sibling (CVE-2026-85880) on any ring still open — same due date.
- After patch: forensic triage on hosts that were internet-exposed or showed pre-patch privilege-escalation symptoms.
Details
- CVE: CVE-2026-81963 (CVSS 7.8, CWE-59 / CWE-284)
- Impact: Elevation of Privilege → SYSTEM
- KEV: Added 2026-09-08; federal due 2026-09-22; forensic triage Yes
- Ransomware use (CISA): Unknown
- Sibling due same day: CVE-2026-85880 (Windows ALPC heap overflow)
Hunt / verify
- Inventory build numbers against the fixed builds for each train.
- Hunt SYSTEM processes spawned from standard-user sessions, especially activity touching update directories outside maintenance windows.
- Confirm Server Core and VDI golden images received the cumulative — golden-image drift is how “fleet patched” becomes fiction.
Sources
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-81963
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-81963
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.