← Back to blog
Blog Detail

CVE-2026-81963: Microsoft Windows Link Following Flaw Added to CISA KEV

CISA added CVE-2026-81963, a Windows Update Stack link following vulnerability, to the KEV catalog on 2026-09-08 with a 2026-09-22 due date. Patch Windows endpoints and verify Update Stack components today.

Trusteed Team
Trusteed Editorial
Written On
Sep 18, 2026
Category
CTEM
Read Time
4 min read
  • CVE-2026-81963
  • KEV
  • CISA
  • Microsoft
  • Windows
  • Windows Update Stack
  • privilege escalation
  • CWE-59
  • CWE-284
  • BOD 26-04

CVE-2026-81963: Microsoft Windows Link Following Flaw Added to CISA KEV

TL;DR

CISA added CVE-2026-81963, a link following vulnerability in the Microsoft Windows Update Stack, to the Known Exploited Vulnerability (KEV) catalog on 2026-09-08. Federal civilian agencies must remediate by 2026-09-22, and all defenders should treat Windows endpoints as priority patch targets this cycle. Apply Microsoft's update guidance, confirm the Update Stack components are patched, and document closure per BOD 26-04.

What is this vulnerability?

  • CVE ID: CVE-2026-81963
  • Vendor / Product: Microsoft / Windows (Windows Update Stack)
  • Vulnerability name: Microsoft Windows Link Following Vulnerability
  • Weakness class: CWE-59 (Improper Link Resolution Before File Access / 'Link Following') and CWE-284 (Improper Access Control)
  • Impact: A local, authorized attacker can escalate privileges up to SYSTEM.
  • CVSS: 7.8 (HIGH), vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, per Microsoft.
  • CISA KEV status: Yes — added 2026-09-08.
  • CISA due date: 2026-09-22.
  • Known ransomware use: Unknown at time of cataloging.

In plain terms, the Windows Update Stack can be tricked into following a link it should not resolve, letting a low-privileged local user reach SYSTEM. Because the attack requires local access, the practical risk is post-compromise escalation: an attacker who already has a foothold on a host can use this to gain full control of that endpoint.

KEV vs CVSS vs EPSS

Signal What it measures How to use it for this CVE
CISA KEV Confirmed in-the-wild exploitation Authoritative trigger. Treat as exploited; remediate by 2026-09-22.
CVSS Theoretical severity of the flaw 7.8 HIGH with local attack vector (AV:L). Prioritize hosts where local access is plausible (VDI, RDS, shared endpoints).
EPSS Probability of exploitation in the next 30 days 0.00631 (percentile ~0.486). Low predictive score, but KEV status overrides EPSS for prioritization.

A low EPSS score does not downgrade a KEV entry. KEV reflects observed exploitation; EPSS reflects modeled likelihood. When they disagree, KEV wins for patch scheduling.

Step-by-step remediation

  1. Inventory. Enumerate Windows endpoints and servers, and identify which build levels include the Windows Update Stack. Include VDI, RDS, and any host where non-admin users can run code.
  2. Patch. Apply Microsoft's update for CVE-2026-81963 per the MSRC update guide. Follow CISA BOD 26-04 guidance for prioritizing security updates based on risk.
  3. Mitigate where patching is delayed. If a host cannot be patched immediately, apply vendor-provided mitigations or isolate the asset. For cloud services, follow BOD 26-04 guidance or discontinue use of the affected product if mitigations are unavailable.
  4. Verify. Confirm the update is installed and the affected Update Stack components reflect the patched build. Re-scan to validate.
  5. Assess exposure. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Even for a local-vector flaw, exposure context drives scheduling.
  6. Ticket closure. Record patch evidence, verification output, and any compensating controls. Retain artifacts consistent with CISA's Forensics Triage Requirements under BOD 26-04.

FAQ

Is CVE-2026-81963 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerability catalog on 2026-09-08.

What is the CISA due date? 2026-09-22. Federal civilian agencies must remediate by that date; other organizations should align to it as a practical deadline.

Is this vulnerability internet-facing? The CVSS vector is AV:L (local), so exploitation requires local access to the target host. That does not eliminate risk — it means the flaw is most dangerous as a privilege-escalation step after an initial foothold. Evaluate each asset's exposure per BOD 26-04.

Is there a ransomware tie? Known ransomware use is listed as Unknown in the source intel. Treat KEV status as sufficient reason to prioritize regardless.

What is the CVSS score and severity? 7.8, HIGH, per Microsoft (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

What is the EPSS score? 0.00631, at the ~48.6th percentile. Low modeled likelihood, but KEV status takes precedence for scheduling.

Related resources

Join Our Newsletter

Trusteed keeps you informed: emerging risks, platform updates, and practical guides for faster defense.