CVE-2026-81963: Why a Windows Update Stack Flaw Matters More Than Its 7.8 Score
Microsoft fixed a record 974 vulnerabilities in September Patch Tuesday, two already exploited. CVE-2026-81963 in Windows Update Stack (CVSS 7.8) allows local privilege escalation to SYSTEM; CISA added it to the exploited vulnerabilities catalog with a September 22 deadline.
- Patch Tuesday closed 974 CVEs — Microsoft's largest release
- CVE-2026-81963 in Windows Update Stack allows privilege escalation to SYSTEM
- CISA added both exploited vulnerabilities to KEV on September 8
- About 20 vulnerabilities rated wormable with CVSS 9.8 by ZDI
Read next
Security