Insecure link following in Microsoft Windows and Windows Server - CVE-2026-81963
Published: September 8, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows update stack. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the SYSTEM user account.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Windows Server
How to mitigate CVE-2026-81963
Windows Server - update to 2025 10.0.26100.33438