Server 2025

Winsage
August 25, 2026
Microsoft has acknowledged a significant issue with the .NET Framework updates from August 2026, causing disruptions in printing and PDF export functionalities in certain applications, particularly those using the Windows Presentation Foundation (WPF) UI framework. After installing the update, some WPF applications may encounter a System.IO.FileFormatException when printing or generating PDF/XPS content with specific fonts, including Calibri. This issue affects various platforms, including Windows 10, Windows 11, and Windows Server editions from 2012 to 2025. Microsoft has provided a temporary workaround involving the Switch.MS.Internal.TtfDelta.DisableCmapAndSbitOverflowProtection AppContext switch, but cautions that it may expose systems to vulnerabilities. This situation is reminiscent of a similar incident in February 2021, where WPF applications and Visual Studio experienced crashes after Windows 10 cumulative updates. Additionally, on the same day, Microsoft offered a workaround for another issue caused by Windows 11 updates that led to crashes in certain games.
Winsage
August 20, 2026
ShieldBreak, identified as CVE-2026-69414, is a zero-day vulnerability in the Microsoft Malware Protection Engine that allows low-privileged local attackers to escalate privileges to SYSTEM. The public proof of concept was released on August 12, 2026, and Microsoft recognized the CVE on August 14, 2026. No patch is currently available. ShieldBreak exploits an elevation-of-privilege vulnerability by manipulating file processing during the cloud-file hydration process in Microsoft Defender, allowing attackers to control processes with elevated privileges. The exploit is functional on Windows 11 25H2 and Windows Server 2025. Qualys VMDR can detect this vulnerability using a specific query, and organizations can use Qualys TruRiskâ„¢ Eliminate for mitigation until a patch is released.
Winsage
August 18, 2026
A new exploit named ShieldBreak, developed by Nightmare-Eclipse, targets Microsoft Defender by allowing privilege escalation and bypassing previous security fixes related to the RoguePlanet vulnerability. ShieldBreak operates on Windows 11 25H2, its Canary channel, and Windows Server 2025, achieving a "100% success rate." Windows 10 may also be vulnerable, but the exploit is specifically designed for Windows 11. There is currently no patch for ShieldBreak, and users are advised to disable Microsoft Defender, implement two-factor authentication, and exercise caution with suspicious online activities. Malwarebytes has recommended its Premium Security antivirus as a temporary solution.
Winsage
August 18, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs are exploiting a significant vulnerability in the Windows Task Host system, tracked as CVE-2025-60710. This high-severity flaw, affecting Windows 11 and Windows Server 2025, allows local attackers with basic user permissions to escalate their privileges to SYSTEM level. Microsoft patched this vulnerability in November 2025, but it poses a threat to unpatched devices. CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and provided Federal Civilian Executive Branch agencies with a two-week window to secure their systems. CISA warns that such vulnerabilities are frequent attack vectors for malicious actors and urges organizations to apply mitigations or discontinue the use of affected products. Additionally, CISA noted that ransomware groups are also exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), confirmed to be actively exploited in early July. Since November 2021, CISA has identified 383 actively exploited vulnerabilities across various Microsoft products, with 112 being used in ransomware attacks.
Winsage
August 17, 2026
Microsoft has announced that the mainstream end date for Windows Server 2022 is set for October 13, 2026, after which it will enter extended support until October 14, 2031. Windows Server 2022 became generally available in September 2021 and is part of the Long-Term Servicing Channel (LTSC) offering, which guarantees a decade of support. Microsoft recommends upgrading to Windows Server 2025, which will be generally available in November 2024, and will reach its end of support on November 13, 2029, with five years of extended support until November 14, 2034. A free 180-day trial of Windows Server 2025 is available. Additionally, hotpatching for Windows Server 2022 will be extended until October 2027 for Datacenter: Azure Edition systems. The free Windows 10 Extended Security Updates (ESU) program has been extended by an additional year, and Windows 11 23H2 Enterprise and Education editions will end updates on November 10, 2026, with a recommendation to upgrade to Windows 11 25H2.
Winsage
August 15, 2026
Microsoft has issued a 60-day notice regarding the end-of-life dates for several products, following a previous 90-day warning. Mainstream support for Windows Server 2022 will end on October 13, 2026, affecting all editions. Users of Windows 11 version 24H2 Home and Pro, as well as Windows 10 Enterprise LTSB 2016, will stop receiving updates. Microsoft recommends upgrading to Windows Server 2025, with an extended support phase lasting until October 14, 2031, for those unable to upgrade immediately. Windows 11 version 24H2 users must upgrade to version 25H2 to continue receiving updates, while Enterprise and Education variants will have a grace period until October 2027. Organizations using Windows 10 Enterprise LTSB 2016 should transition to Windows 11 Enterprise LTSC 2024, with Extended Security Updates available for purchase for those who remain on the older system. A 180-day evaluation build of Windows Server 2025 can be downloaded for compatibility testing.
Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Search