The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs are exploiting a significant vulnerability in the Windows Task Host system, tracked as CVE-2025-60710. This high-severity flaw, affecting Windows 11 and Windows Server 2025, allows local attackers with basic user permissions to escalate their privileges to SYSTEM level. Microsoft patched this vulnerability in November 2025, but it poses a threat to unpatched devices. CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and provided Federal Civilian Executive Branch agencies with a two-week window to secure their systems. CISA warns that such vulnerabilities are frequent attack vectors for malicious actors and urges organizations to apply mitigations or discontinue the use of affected products. Additionally, CISA noted that ransomware groups are also exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), confirmed to be actively exploited in early July. Since November 2021, CISA has identified 383 actively exploited vulnerabilities across various Microsoft products, with 112 being used in ransomware attacks.