CVE-2026-81963High· 7.8▾ Abyssal⚠ Exploited in the wild0dayPoC availableImproper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.1 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 22, 2026
Last analysed / modified upstream
0.6%
Added to the CISA catalog on Sep 8, 2026. Federal remediation due Sep 22, 2026. View catalog ↗
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
windows_11_23h2 < 10.0.22631.7582windows_11_24h2 < 10.0.26100.9445windows_11_25h2 < 10.0.26200.9445windows_11_26h1 < 10.0.28000.2954windows_server_2025 < 10.0.26100.33438Upgrade past the affected range:
windows_11_23h2 10.0.22631.7582windows_11_24h2 10.0.26100.9445windows_11_25h2 10.0.26200.9445windows_11_26h1 10.0.28000.2954windows_server_2025 10.0.26100.33438Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-69425Medium· 4.7Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.
CVE-2026-69379High· 7.0Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-83944Critical· 10.0Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-83999High· 7.0Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83990High· 7.8Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.