Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.8
CVE-2026-81963: Windows 11 and Server 2025 link handling can grant admin rights
CVE-2026-81963 · published 11 days ago · actively exploited
Summary
The Windows update component that processes links can be tricked by a local user to gain full system privileges. This means an attacker with limited access could take control of the entire machine. Apply the latest security updates from Microsoft as soon as they are available to close the gap.
What to do
- Update microsoft windows 11 version 23h2 to version 10.0.22631.7582 or later.
- Update microsoft windows 11 version 24h2 to version 10.0.26100.9445 or later.
- Update microsoft windows 11 version 25h2 to version 10.0.26200.9445 or later.
- Update microsoft windows 11 version 26h1 to version 10.0.28000.2954 or later.
- Update microsoft windows server 2025 to version 10.0.26100.33438 or later.
- Update microsoft windows server 2025 (server core installation) to version 10.0.26100.33438 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows 11 version 23h2 | < 10.0.22631.7582 |
| microsoft | windows 11 version 24h2 | < 10.0.26100.9445 |
| microsoft | windows 11 version 25h2 | < 10.0.26200.9445 |
| microsoft | windows 11 version 26h1 | < 10.0.28000.2954 |
| microsoft | windows server 2025 | < 10.0.26100.33438 |
| microsoft | windows server 2025 (server core installation) | < 10.0.26100.33438 |
| microsoft | windows | All versions |
Original advisory text
Microsoft Windows Link Following Vulnerability
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963 vendor-advisory patch
Severity
7.8
High
CVSS 3.1: 7.8 (MITRE)
Exploitation
Known exploited
Listed in the CISA KEV catalogue - exploitation confirmed in the wild.
EPSS <1%
Type
CWE-59Link Following
CWE-284Improper Access Control
Timeline
Published8 Sep 2026
Updated19 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta