Insecure link following in Microsoft Windows and Windows Server - CVE-2026-81963

 

Insecure link following in Microsoft Windows and Windows Server - CVE-2026-81963

Published: September 8, 2026


Vulnerability identifier: #VU147470
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-81963
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an insecure link following issue in Windows update stack. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the SYSTEM user account.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2026-81963

Install updates from vendor's website.

Microsoft Windows - addressed in versions 11 23H2 10.0.22631.7582, 11 24H2 10.0.26100.9445, 11 25H2 10.0.26200.9445, 11 26H1 10.0.28000.2954
Windows Server - update to 2025 10.0.26100.33438

External References

Related Security Bulletins