CISA added CVE-2026-81963 to its Known Exploited Vulnerabilities (KEV) catalogue on 8 September 2026. The vulnerability affects Microsoft Windows and is named the Microsoft Windows Link Following Vulnerability. It allows a local attacker to escalate privileges to SYSTEM through the Windows Update Stack.
The flaw is a local privilege-escalation vulnerability caused by improper link following. An attacker must already have local access to the affected Windows system, but successful exploitation can provide SYSTEM-level privileges. The vulnerability has a CVSS score of 7.8 and is rated HIGH. Microsoft has made a patch available.
CISA’s KEV listing confirms that attackers are actively exploiting CVE-2026-81963. The available data does not confirm use in ransomware campaigns; ransomware use is listed as unknown. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 22 September 2026.
CISA requires organisations to apply mitigations in accordance with Microsoft’s instructions, while ensuring compliance with CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Stakeholders must assess each asset’s internet exposure and follow the applicable BOD 26-04 patching guidance, including for cloud services, or discontinue use where mitigations are unavailable. FCEB agencies are directly subject to this requirement, but all organisations should review their exposure and apply the available update.
See the NVD entry and CISA KEV catalogue for full details.