Overview
What is CVE-2026-81963?
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Microsoft Windows Link Following Vulnerability
CISA lists CVE-2026-81963 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft Windows.
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.