The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices.
Following successful exploitation, local attackers with basic user permissions can gain SYSTEM privileges and take full control of unpatched devices.
While it didn’t share any details regarding ongoing attacks and Microsoft has yet to update its security advisory to confirm in-the-wild exploitation, CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems.
On Friday, CISA updated its Known Exploited Vulnerabilities Catalog (KEV) again, flagging the security vulnerability as being abused by ransomware gangs.
The U.S. cybersecurity agency has not yet shared any information about attacks targeting CVE-2025-60710, and a Microsoft spokesperson was not immediately available for comment when BleepingComputer reached out earlier today.
“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA warned. “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”
One week ago, CISA also warned that ransomware gangs have begun exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659) after confirming active exploitation in early July.
Since November 2021, the agency has flagged 383 actively exploited vulnerabilities in various Microsoft products, 112 of which have also been exploited in ransomware attacks.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
CISA orders feds to patch BlueHammer flaw exploited as zero-day
Microsoft working on Defender patch for ShieldBreak zero-day
Windows LegacyHive zero-day flaw gets free, unofficial patches
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Microsoft confirms GitHub is down worldwide
Anthropic confirms Claude is down in major outage affecting multiple services
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
Certighost CVE is new. The privilege behind it isn’t. Discover where yours is hiding.
Overdue a password health-check? Audit your Active Directory for free
Stop AI slopsquatting attacks. Secure open source package ingestion before it hits your build.
91% of AI Apps Appeared in 16 Months. Get Material’s OAuth Risk Report
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



