Windows Update Stack: CVE-2026-81963 actively exploited
CVE-2026-81963 allows local SYSTEM privileges on Windows 11 and Windows Server 2025. Prioritize September updates, complete restarts and verify patch status.
Security Advisories
Concise analysis of relevant vulnerabilities and changes: what is affected, how serious is the risk and what should responsible teams review now?
CVE-2026-81963 allows local SYSTEM privileges on Windows 11 and Windows Server 2025. Prioritize September updates, complete restarts and verify patch status.
Microsoft has observed a campaign using fake IT support contacts over Teams. Remote access, a silent MSI installation and WinRM lead toward domain controllers and certificate authorities.
CISA has added the critical Windows IKEv2 flaw CVE-2026-33824 to the KEV catalog. Update systems and restrict UDP 500/4500 to required peers.
Microsoft has fixed an actively exploited use-after-free flaw in the Windows Ancillary Function Driver for WinSock. Prioritize the August updates across clients and servers.
Microsoft lists CVE-2026-56164 in on-premises SharePoint farms as actively exploited. Apply the July patches and migrate SharePoint 2016 and 2019.
The July 2026 Windows security updates add SHA-2 thumbprints for signed RDP file trust. Organizations should block unknown publishers, sign their own RDP files, and retire existing SHA-1 pins.
The July Windows Server updates start hardening the AD FS DKM container ACL. CVE-2026-56155 is under active exploitation; administrators should review audit events now and test remediation before October.
With Windows security updates released in or after July 2026, Microsoft removes the audit and rollback phase for CVE-2026-20833. Domain Controllers enforce RC4 hardening; remaining RC4 dependencies can cause authentication failures.
CVE-2026-45480 affects Azure Active Directory/Microsoft Entra ID and is rated as critical privilege escalation. Microsoft reports completed service-side mitigation; operators should still review privileged tenant changes and evidence limits.
CVE-2026-42904 affects the Windows TCP/IP stack and can lead to SYSTEM privileges if exploited successfully. Windows clients and servers are in scope; patch evidence and segment boundaries should be reviewed together.
The June 2026 Windows security update includes the fix for CVE-2026-45585. Teams should now document patch level, BitLocker protectors, WinRE state, and recovery key escrow for affected Windows 11 and Windows Server 2025 systems.
The June 2026 security updates address a critical remote code execution issue in Active Directory Domain Services. Windows Server 2022 and 2025 domain controllers are in scope; teams should verify patch level, completed reboots, and DC reachability.
CVE-2026-48579 affects information disclosure in Exchange Online. Microsoft rates the issue highly and has mitigated it in the service; tenant teams should still verify audit logs, permissions and unusual mailbox activity.
CVE-2026-42897 affects Outlook Web Access on on-premises Exchange servers and is being exploited. Verify that Exchange Emergency Mitigation Service rule M2.1.x is active and that OWA is not used through Internet Explorer mode.
CVE-2026-41091 and CVE-2026-45498 affect Microsoft Defender and are being exploited. Explicitly verify Malware Protection Engine and Antimalware Platform versions, especially on servers, VDI, DMZ and isolated Windows systems.
From June 2026 onward, older Secure Boot certificates start expiring. Without coordinated firmware/DBX updates you may see boot failures and BitLocker recovery events. Recommendation: inventory, pilot ring, verify recovery keys, define rollback.
May 2026 security updates address a critical remote code execution issue in Windows Netlogon. Priority: patch domain controllers and admin systems, restrict network paths to DCs, and tighten monitoring for auth/Netlogon anomalies.
Since the April 2026 Windows updates, RC4 is no longer treated as an implicit Kerberos default fallback when accounts have no explicit encryption type configuration. Inventory, AES readiness for service accounts, and a controlled cutover before the July phase now matter.
Microsoft describes a known issue where certain domain controllers in PAM environments can repeatedly restart after April updates because LSASS fails during startup. Out-of-band updates are available.