Microsoft Fixes Three Zero-Days on Busy Patch Tuesday
ID: 5cd09dad-ff49-5ca4-811f-d6b394468309
STIX ID: report--5cd09dad-ff49-5ca4-811f-d6b394468309
Feed Name: Infosecurity Magazine (News)
- Microsoft released security updates addressing 114 CVEs on Patch Tuesday, including three zero-days: CVE-2026-20805 (an actively exploited Desktop Window Manager information-disclosure that can weaken ASLR), CVE-2026-21265 (a secure-boot certificate expiration related bypass affecting many systems and requiring firmware/BIOS coordination), and CVE-2023-31096 (an elevation-of-privilege in Agere modem drivers whose drivers are being removed). The bulletin notes a large number of EoP, RCE, and information-disclosure fixes and emphasizes that the secure-boot issue may require hardware audits and manual firmware updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
