logo

CISA flags Windows Task Host vulnerability as exploited in attacks

ID: 386742c1-93c1-538d-b72c-4aa4329505a7

STIX ID: report--386742c1-93c1-538d-b72c-4aa4329505a7

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-04-15

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warned U.S. federal agencies to urgently patch a Windows Task Host privilege escalation vulnerability (CVE-2025-60710) affecting Windows 11 and Windows Server 2025 that allows local, low-complexity attacks to gain SYSTEM privileges; Microsoft patched it in November 2025, CISA added it to its catalog of actively exploited vulnerabilities and required FCEB agencies to apply fixes within two weeks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.