๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-81963: Microsoft Windows Link Following Vulnerability
Summary
A link following vulnerability (a bug where a program incorrectly follows symbolic links, which are shortcuts to files, allowing attackers to access unintended locations) exists in Microsoft Windows Update Stack that lets a local attacker (someone with access to the computer) gain SYSTEM privileges (the highest level of control on Windows). This vulnerability is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions from Microsoft, following CISA's BOD 26-04 guidance on patching priorities. If mitigations are unavailable, discontinue use of the product for cloud services. Organizations must evaluate their systems' internet exposure and adhere to BOD 26-04 patching guidelines by the due date of 2026-09-22.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
September 7, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81963
First tracked: September 8, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%