Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Microsoft Office 2016 to 2024 and Office 365 apps are affected by a zero-day vulnerability (CVE-2026-21509) that is currently being exploited in attacks. Microsoft has released emergency security updates to address this issue.
A use after free vulnerability in the Windows Cloud Files Mini Filter Driver allows authorized attackers to elevate privileges locally. This vulnerability is documented as CVE-2025-62221 and is referenced in CISA's BOD 22-01 and the Known Exploited Vulnerabilities Catalog for further guidance. Users...
A significant vulnerability, tracked as CVE-2025-62221, was disclosed on December 9, 2025, affecting Windows environments. This flaw poses a risk to users relying on the Windows Cloud Files Mini Filter Driver, potentially allowing unauthorized access to sensitive data.
In December 2025, Adobe released five bulletins addressing 139 unique vulnerabilities as part of its security updates. This follows the November updates, where Adobe addressed 29 unique CVEs across several products. Microsoft also provided updates during this final patch Tuesday of the year.