Skip to content

CVE-2026-24291

CVE

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
March 10, 2026
Last Seen
September 10, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively exploited in the wild, necessitating immediate attention from security teams.

A critical vulnerability, CVE-2026-41089, was identified in Windows Netlogon, allowing unauthenticated attackers to exploit a stack buffer overflow. This vulnerability enables attackers to execute arbitrary code at the NT AUTHORITY\SYSTEM level, posing a severe risk to Active Directory environments....

Researchers at MDSec have disclosed a critical Elevation of Privilege vulnerability in Microsoft Windows, identified as 'RegPwn' and tracked as CVE-2026-24291. This vulnerability allows low-privileged users to gain full SYSTEM access by exploiting the handling of registry configurations for Windows...

Two vulnerabilities have been identified in the Windows Accessibility Infrastructure (ATBroker.exe) on March 10, 2026. CVE-2026-25186 allows unauthorized information disclosure, while CVE-2026-24291 enables privilege escalation for authorized attackers. Both vulnerabilities pose significant risks to...

Public Exploits

Checking GitHub for proof-of-concept code…