type: cve ยท created: 2026-09-09 ยท updated: 2026-09-09 ยท tags: [cve, windows, elevation-of-privilege, zero-day, patch-tuesday] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, healthcare, education, defence] ยท au_impact: true
CVE-2026-81963
CVE-2026-81963 is an elevation-of-privilege vulnerability in the Windows Update Stack, one of two actively exploited zero-days patched in Microsoft's September 2026 Patch Tuesday release. It lets an attacker escalate to SYSTEM privileges on a compromised Windows host.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-81963 |
| Type | Windows Update Stack elevation-of-privilege; actively exploited zero-day |
| Credited to | Romain Deperne and MSTIC |
| Patch cycle | September 2026 Patch Tuesday (record 966 fixes) |
| Source | BleepingComputer โ Tier 2/4 |
The zero-day lets an attacker escalate to SYSTEM privileges. Its active exploitation contributed to the record Patch Tuesday volume (966 CVEs, 105 critical / 81 RCE), a step-change Microsoft ties to its AI-powered vulnerability discovery system.