CVE-2026-81963
published 2026-09-08CVE-2026-81963: Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
PriorityP185high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-22
Exploited in the wild
EPSS
0.63%
48.2th percentile
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_11_23h2 | < 10.0.22631.7582 | 10.0.22631.7582 |
| microsoft | windows_11_24h2 | < 10.0.26100.9445 | 10.0.26100.9445 |
| microsoft | windows_11_25h2 | < 10.0.26200.9445 | 10.0.26200.9445 |
| microsoft | windows_11_26h1 | < 10.0.28000.2954 | 10.0.28000.2954 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.7582 | 10.0.22631.7582 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.9445 | 10.0.26100.9445 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.9445 | 10.0.26200.9445 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2954 | 10.0.28000.2954 |
| microsoft | windows_server_2025 | < 10.0.26100.33438 | 10.0.26100.33438 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.33438 | 10.0.26100.33438 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
ghsa_unreviewed·2026-09-08
CVE-2026-81963 [HIGH] CWE-59 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
VulnCheck
Microsoft Windows Link Following Vulnerability
vulncheck·2026·CVSS 7.8
CVE-2026-81963 [HIGH] CWE-59 Microsoft Windows Link Following Vulnerability
Microsoft Windows Link Following Vulnerability
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
Affected: Microsoft Windows
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf
CISA
Microsoft Windows Link Following Vulnerability
cisa·2026-09-08·CVSS 7.8
CVE-2026-81963 [HIGH] CWE-59 Microsoft Windows Link Following Vulnerability
Vulnerability: Microsoft Windows Link Following Vulnerability
Affected: Microsoft Windows
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://msrc.microsoft.com/update-guide/en-US/vul
No detection rules found.
No public exploits indexed.
Tenable
The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails
blogs_tenable·2026-09-10
CVE-2026-81963 The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails
## The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails
Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environment
## Key takeaways
AI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don’t automatically understand your unique environment or who is allowed to do what. The “harness” is the custom-built layer that translates AI intelligence into safe, controlled actions specific to your organization.
AI requires a supervisor. Tenable treats our AI agents like untrusted insiders. Instead of relying on the AI to police itself, the harness strictly limits what the A
Hackernews
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
blogs_hackernews·2026-09-09·CVSS 7.8
CVE-2026-85880 [HIGH] Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.
These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patche
Sans Isc
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
blogs_sans_isc·2026-09-08·CVSS 7.8
CVE-2026-81963 [HIGH] September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
September 2026 Microsoft Patch Tuesday
Published: 2026-09-08. Last Updated: 2026-09-08 19:20:30 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
A few vulnerabilities worth mentioning:
Windows Update Stack Elevation of Privilege Vulnerability (CVE-2026-81963)
Microsoft reports that CVE-2026-81963 is being exploited, though it was not publicly disclosed b
Tenable
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
blogs_tenable·2026-09-08·CVSS 7.8
CVE-2026-81963 [HIGH] Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
## Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
104 Critical
860 Important
0 Moderate
0 Low
Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.
Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.
This month’s update includes patches for:
.NET
.NET and Visual Studio
ASP.NET Core
Active Directory Certificate Services (AD CS)
Active Directory Domain Services
Active Directory Federation Services (AD FS)
Audio Video Control Transport Protocol
Azure Arc
Azure CycleCloud
Azure HDInsights
BranchCache
Connected Devices Platform
Tenable
Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
blogs_tenable·2026-09-08
CVE-2026-81963 Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
## Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.
## Key takeaways
Claude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for research and evaluation, Tenable will now incorporate it within Tenable One, giving defenders access to frontier cyber reasoning to tackle complex exposure management challenges.
Tenable One Adversary View is the first i
Tenable
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
blogs_tenable·2026-09-08·CVSS 10.0
CVE-2026-75650 [CRITICAL] StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
## StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.
## Key takeaways
CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.
Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns.
Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable dete
Rapid7
Patch Tuesday - September 2026
blogs_rapid7·2026-09-08·CVSS 7.8
CVE-2026-85880 [HIGH] Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
## Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the batt
Talos
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-09-08·CVSS 8.8
CVE-2026-81963 [HIGH] Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:
CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.
CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). CVE-2026-85880 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Us
Krebs
Microsoft Plugs Nearly 1,000 Security Holes
blogs_krebs·2026-09-08·CVSS 9.8
CVE-2026-81963 [CRITICAL] Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Image: Shutterstock.com, Kirill Makarov.
This month’s patch bundle obliterates the software giant’s previous record set in July , when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three
Qualys
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
blogs_qualys·2026-09-08
CVE-2026-75650 Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for September2026
Adobe Patch for September 2026
Zero-day Vulnerabilities Patched inSeptemberPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inSeptemberPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats.
This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security fla
Crowdstrike
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
blogs_crowdstrike
CVE-2026-81963 September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs Sep 08, 2026
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks Sep 02, 2026
CrowdStrike Announces Agentic Identity Provider Sep 02, 2026
CrowdStrike Delivers the Next Evolution of the Agentic SOC Sep 02, 2026
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs Sep 08, 2026
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks Sep 02, 2026
CrowdStrike Announces Agentic Identity Provider Sep 02, 2026
CrowdStrike Delivers the Next Evolution of the Agentic SOC Sep 02, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Under
2026-09-08
Published
2026-09-08
Added to CISA KEV
Exploited in the wild