Multiple Vulnerabilities Discovered in Microsoft Windows 10 Versions 1809 and 21H2
Article Content
- •Multiple vulnerabilities in Windows 10 versions 1809 and 21H2 disclosed on March 10, 2026.
- •Attackers can exploit these vulnerabilities to elevate privileges or disclose sensitive information.
- •No active exploitation reported as of June 16, 2026, but immediate attention is advised.
On March 10, 2026, Microsoft disclosed multiple vulnerabilities affecting Windows 10 versions 1809 and 21H2. These include use-after-free vulnerabilities, improper authentication, and out-of-bounds read issues, allowing attackers to elevate privileges or disclose sensitive information. Specifically, vulnerabilities in the Windows Authentication Methods and Graphics Component were noted, with CVEs such as CWE-416 and CWE-200 identified. The vulnerabilities could impact both local and network security, with unauthorized actors potentially exploiting them to gain elevated access or cause denial of service. The issues affect various components, including the Windows Accessibility Infrastructure and SMB Server. As of June 16, 2026, there is no indication of active exploitation, but the vulnerabilities are significant enough to warrant immediate attention from system administrators.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…