Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively exploited in the wild, necessitating immediate attention from security teams.
On February 10, 2026, Microsoft released a security update addressing 59 vulnerabilities, including six zero-day flaws that were actively exploited prior to the patch. The vulnerabilities affect various Microsoft products, with three of them being security feature bypass flaws, allowing attackers to...
Microsoft has released a patch for CVE-2026-21525, a vulnerability in the RasMan component that can crash Windows VPN services and disrupt remote access. This flaw has been actively exploited, prompting its addition to the CISA KEV list on February 10, 2026.
Microsoft has addressed a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service, identified as CVE-2026-21525. This flaw, which allowed attackers to cause denial-of-service conditions on unpatched systems, was actively exploited prior to its disclosure. The vulnerab...