Local users can gain SYSTEM privileges

CVE-2026-81963, a Windows Update Stack vulnerability fixed on September 8, 2026, is being actively exploited. It is rated Important with a CVSS score of 7.8 and was added to CISA's Known Exploited Vulnerabilities catalog on the same day.

A locally authenticated attacker with low privileges can gain SYSTEM privileges through improper link following. No additional user interaction is required. The attacker needs existing local access; the flaw does not provide direct, unauthenticated network access. It increases the impact of an initial compromise of a user account or endpoint.

Affected systems and September updates

Affected products are Windows 11 versions 23H2, 24H2, 25H2 and 26H1, and Windows Server 2025, including Server Core. The following September 8 security updates are available for supported editions:

  • Windows 11 23H2: KB5122880.
  • Windows 11 24H2 and 25H2: KB5124008; OS builds 26100.9445 and 26200.9445, respectively.
  • Windows 11 26H1: KB5124012; OS build 28000.2954.
  • Windows Server 2025: KB5122871; OS build 26100.33438.

Install the cumulative security update for the relevant operating system, or a subsequent update that includes this fix. A restart is required. An approved update in the management platform or a completed download does not establish that protection is effective.

Verify restarts and functionality during rollout

Prioritize affected devices with suspicious activity and systems where unprivileged users can execute programs. After restarting, check the installed KB, OS build and update errors in the central inventory. Track pending restarts and failed installations through to completion.

Documented issues with the September updates include Remote Desktop Services instability and unavailable Plan9 host folder shares in HCS-managed Linux VMs, such as those used by WSL. Test these functions in a short pilot where relevant and review the known issues for each applicable KB.

Signs of compromise also require incident triage and isolation where appropriate. The update closes the vulnerability; it does not remove access already gained or reverse subsequent changes.