Windows zero-days under attack
Every Windows flaw CISA confirms is being exploited, as it is added, with our news on Patch Tuesday fixes. What to update and when.
Log in – next time you'll see what's new since your visit.
Timeline
Patch Tuesday 2026: Record Fixes, Zero-Days and Next Dates
Patch Tuesday is Microsoft's monthly update day, the second Tuesday. September 2026 set a record with over 960 fixes and 2 zero-days. Dates and steps.
Article →CVE-2026-81963 added to CISA's exploited list: Microsoft Windows Link Following Vulnerability
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
2-Spyware: exploited vulnerability →CVE-2026-85880 added to CISA's exploited list: Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2026-68820 added to CISA's exploited list: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2008-4250 added to CISA's exploited list: Microsoft Windows Buffer Overflow Vulnerability
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
2-Spyware: exploited vulnerability →CVE-2026-32202 added to CISA's exploited list: Microsoft Windows Protection Mechanism Failure Vulnerability
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
2-Spyware: exploited vulnerability →CVE-2023-36424 added to CISA's exploited list: Microsoft Windows Out-of-Bounds Read Vulnerability
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
2-Spyware: exploited vulnerability →CVE-2025-60710 added to CISA's exploited list: Microsoft Windows Link Following Vulnerability
Microsoft Windows contains a link following vulnerability that allows for privilege escalation Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2008-0015 added to CISA's exploited list: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
2-Spyware: exploited vulnerability →CVE-2026-21510 added to CISA's exploited list: Microsoft Windows Shell Protection Mechanism Failure Vulnerability
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
2-Spyware: exploited vulnerability →CVE-2026-21519 added to CISA's exploited list: Microsoft Windows Type Confusion Vulnerability
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2026-21525 added to CISA's exploited list: Microsoft Windows NULL Pointer Dereference Vulnerability
Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
2-Spyware: exploited vulnerability →CVE-2026-21533 added to CISA's exploited list: Microsoft Windows Improper Privilege Management Vulnerability
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2026-21513 added to CISA's exploited list: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
2-Spyware: exploited vulnerability →CVE-2026-20805 added to CISA's exploited list: Microsoft Windows Information Disclosure Vulnerability
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
2-Spyware: exploited vulnerability →CVE-2025-62221 added to CISA's exploited list: Microsoft Windows Use After Free Vulnerability
Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2025-62215 added to CISA's exploited list: Microsoft Windows Race Condition Vulnerability
Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.
2-Spyware: exploited vulnerability →CVE-2025-59287 added to CISA's exploited list: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
2-Spyware: exploited vulnerability →CVE-2025-33073 added to CISA's exploited list: Microsoft Windows SMB Client Improper Access Control Vulnerability
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.
2-Spyware: exploited vulnerability →CVE-2025-24990 added to CISA's exploited list: Microsoft Windows Untrusted Pointer Dereference Vulnerability
Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.
2-Spyware: exploited vulnerability →CVE-2025-59230 added to CISA's exploited list: Microsoft Windows Improper Access Control Vulnerability
Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2013-3918 added to CISA's exploited list: Microsoft Windows Out-of-Bounds Write Vulnerability
Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
2-Spyware: exploited vulnerability →CVE-2011-3402 added to CISA's exploited list: Microsoft Windows Remote Code Execution Vulnerability
Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page.
2-Spyware: exploited vulnerability →CVE-2021-43226 added to CISA's exploited list: Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2025-33053 added to CISA's exploited list: Microsoft Windows External Control of File Name or Path Vulnerability
Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files.
2-Spyware: exploited vulnerability →CVE-2025-32701 added to CISA's exploited list: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2025-30397 added to CISA's exploited list: Microsoft Windows Scripting Engine Type Confusion Vulnerability
Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.
2-Spyware: exploited vulnerability →CVE-2025-32709 added to CISA's exploited list: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.
2-Spyware: exploited vulnerability →CVE-2025-30400 added to CISA's exploited list: Microsoft Windows DWM Core Library Use-After-Free Vulnerability
Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2025-32706 added to CISA's exploited list: Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2025-24054 added to CISA's exploited list: Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
2-Spyware: exploited vulnerability →CVE-2025-29824 added to CISA's exploited list: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2025-24991 added to CISA's exploited list: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability
Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.
2-Spyware: exploited vulnerability →CVE-2025-24993 added to CISA's exploited list: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability
Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.
2-Spyware: exploited vulnerability →CVE-2025-24984 added to CISA's exploited list: Microsoft Windows NTFS Information Disclosure Vulnerability
Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
2-Spyware: exploited vulnerability →CVE-2025-24985 added to CISA's exploited list: Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability
Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.
2-Spyware: exploited vulnerability →CVE-2025-26633 added to CISA's exploited list: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2025-24983 added to CISA's exploited list: Microsoft Windows Win32k Use-After-Free Vulnerability
Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
2-Spyware: exploited vulnerability →CVE-2018-8639 added to CISA's exploited list: Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2025-21391 added to CISA's exploited list: Microsoft Windows Storage Link Following Vulnerability
Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.
2-Spyware: exploited vulnerability →CVE-2025-21418 added to CISA's exploited list: Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2025-21335 added to CISA's exploited list: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2025-21333 added to CISA's exploited list: Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2025-21334 added to CISA's exploited list: Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2024-35250 added to CISA's exploited list: Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability
Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
2-Spyware: exploited vulnerability →CVE-2024-49138 added to CISA's exploited list: Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
2-Spyware: exploited vulnerability →CVE-2024-43451 added to CISA's exploited list: Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.
2-Spyware: exploited vulnerability →CVE-2024-49039 added to CISA's exploited list: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2024-30088 added to CISA's exploited list: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2024-43573 added to CISA's exploited list: Microsoft Windows MSHTML Platform Spoofing Vulnerability
Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality.
2-Spyware: exploited vulnerability →CVE-2024-43572 added to CISA's exploited list: Microsoft Windows Management Console Remote Code Execution Vulnerability
Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.
2-Spyware: exploited vulnerability →CVE-2024-43461 added to CISA's exploited list: Microsoft Windows MSHTML Platform Spoofing Vulnerability
Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112.
2-Spyware: exploited vulnerability →CVE-2024-38014 added to CISA's exploited list: Microsoft Windows Installer Improper Privilege Management Vulnerability
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2024-38217 added to CISA's exploited list: Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
2-Spyware: exploited vulnerability →CVE-2024-38106 added to CISA's exploited list: Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition.
2-Spyware: exploited vulnerability →CVE-2024-38178 added to CISA's exploited list: Microsoft Windows Scripting Engine Memory Corruption Vulnerability
Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.
2-Spyware: exploited vulnerability →CVE-2024-38193 added to CISA's exploited list: Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2024-38213 added to CISA's exploited list: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.
2-Spyware: exploited vulnerability →CVE-2024-38107 added to CISA's exploited list: Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability
Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2018-0824 added to CISA's exploited list: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
2-Spyware: exploited vulnerability →CVE-2024-38080 added to CISA's exploited list: Microsoft Windows Hyper-V Privilege Escalation Vulnerability
Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
2-Spyware: exploited vulnerability →CVE-2024-38112 added to CISA's exploited list: Microsoft Windows MSHTML Platform Spoofing Vulnerability
Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.
2-Spyware: exploited vulnerability →CVE-2024-26169 added to CISA's exploited list: Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. Used in ransomware attacks.
2-Spyware: exploited vulnerability →CVE-2024-30040 added to CISA's exploited list: Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
2-Spyware: exploited vulnerability →CVE-2022-38028 added to CISA's exploited list: Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
2-Spyware: exploited vulnerability →