Knox CVE Database
/
CVE-2026-81963
High
7.8

CVE-2026-81963: Microsoft Windows Link Following Vulnerability

Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

Added to the CISA KEV catalog:
September 8, 2026

Overview

The Windows Update Stack in several Windows 11 and Windows Server 2025 builds contains a link-following flaw that a local attacker with standard user credentials can exploit to gain SYSTEM-level privileges. By planting a malicious symbolic link or directory junction at a path the Update Stack's privileged process later accesses, the attacker redirects that process to arbitrary files or directories, bypassing the access control boundary between a low-privileged user and SYSTEM. Affected builds span Windows 11 versions 23H2 through 26H1 and Windows Server 2025.

Vulnerability details

Affected vendor
Microsoft
Affected product
Windows
Weakness type (CWE)
CWE-59, CWE-284

Link-following vulnerabilities (CWE-59) arise when a privileged process resolves a filesystem symbolic link or directory junction without first verifying that the resolved target is the intended one. In the Windows Update Stack, a SYSTEM-level process accesses a filesystem path during update operations. Because it does not validate whether that path has been replaced by an attacker-controlled link before performing the file operation, the access control boundary between a low-privileged user account and SYSTEM-owned resources collapses (CWE-284). The attacker does not need to exploit memory corruption or interact with the network; the flaw is entirely within local filesystem semantics.


An attacker who holds a standard user account on the target system plants a crafted symbolic link or directory junction at the filesystem path the Windows Update Stack's privileged process will later resolve. When that process follows the link, it reads, writes, or creates files at the attacker-chosen target location under SYSTEM authority. The preconditions are modest: local access, low-privileged credentials, and the ability to create symbolic links or junctions at the relevant path. No user interaction beyond the attacker's own actions is required. The outcome is full local privilege escalation to SYSTEM, with complete control over confidentiality, integrity, and availability of the local system.

Severity and impact

7.8
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor Windows Security event logs for process creation events where a SYSTEM-privileged process (such as a Windows Update worker) accesses file paths outside its expected working directories, particularly paths writable by standard users.
  • Audit filesystem junction and symbolic link creation events (e.g., via object access auditing on sensitive directories) for links created by low-privileged accounts that point to system-owned file paths, especially shortly before or during an update operation.
  • Review Windows Update activity logs for update operations that fail with access errors or that touch unexpected file paths, which may indicate a redirected file operation caused by a planted link.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 22, 2026

Additional hardening

  • Apply the vendor-supplied security updates: Windows 11 23H2 build 10.0.22631.7582 or later, Windows 11 24H2/25H2 build 10.0.26100.9445 or later, and Windows Server 2025 build 10.0.26100.33438 or later. See References for the full version boundary list.
  • Restrict the ability of standard user accounts to create symbolic links and directory junctions by configuring the 'Create symbolic links' user right (SeCreateSymbolicLinkPrivilege) via Group Policy to allow only administrators and explicitly trusted accounts.
  • Apply the principle of least privilege: audit local accounts on affected systems and remove unnecessary local logon rights, reducing the pool of accounts that could plant a malicious link before a privileged Update Stack operation.
  • Where feasible, limit interactive and remote local logon access to affected systems to administrators only until the patch is applied, reducing the attacker's ability to establish the required local foothold.

Key dates

Published (NVD)
September 8, 2026
Added to CISA KEV
September 8, 2026
Remediation deadline
September 22, 2026
Last updated
September 9, 2026

References

Frequently asked questions

Does CVE-2026-81963 affect my FedRAMP authorization?

If Microsoft Windows runs inside your authorization boundary, CVE-2026-81963 is a direct concern for your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog and set a remediation deadline of September 22, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it during review.

How does Knox help me handle CVE-2026-81963?

Knox does not patch Microsoft Windows on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-81963 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-81963. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the visibility to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-81963 isn't remediated by September 22, 2026?

If CVE-2026-81963 is not remediated by September 22, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing the item out before that deadline keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.