Windows Update Stack CVE-2026-81963: Federal KEV Due Today (September 22)

By George Bailey   Published: 09/21/26   Updated: 09/21/26   2 min read

The Update Stack elevation-of-privilege zero-day is not new — but today is the federal due date. If September’s cumulative update is not verified on Windows 11 and Server 2025 fleets, Tuesday is the day the ticket stops waiting.

What happened

CVE-2026-81963 is a link-following / improper access control bug in the Windows Update Stack. A local attacker with low privileges abuses how the stack resolves links and escalates to SYSTEM. No user interaction required. Microsoft shipped the fix in the September 2026 cumulatives; CISA added it to KEV on September 8 with a BOD 26-04 due date of September 22, 2026. Forensic triage is required.

Affected trains include Windows 11 23H2 / 24H2 / 25H2 / 26H1 and Windows Server 2025 (including Server Core). Example fixed builds cited in public guidance: 22631.7582, 26100.9445, 26200.9445, 28000.2954, and Server 2025 26100.33438 (verify against Microsoft’s update guide for your SKU).

Note: the sibling ALPC zero-day (CVE-2026-85880) shares the same KEV due date. If you patched ALPC last week but skipped Update Stack coverage on some rings, finish the pair today.

Why it matters

Local EoP is stage two of nearly every modern intrusion. The Update Stack runs elevated during patch operations and sits on essentially every supported endpoint — which means an attacker who owns that path owns the eviction process. CVSS 7.8 looks modest next to 9.8 RCEs; Exploitation Detected is why it still clears the KEV bar and why today’s clock matters.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.