SB2026090866 - Privilege escalation in Microsoft Windows update stack
Published: September 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Insecure link following (CVE-ID: CVE-2026-81963) Exploited
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows update stack. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the SYSTEM user account.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.