Skip to content

CVE-2026-24294

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
March 10, 2026
Last Seen
June 30, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively exploited in the wild, necessitating immediate attention from security teams.

A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability arises from design flaws that were not fully addressed by the previous patch for CVE...

In April 2026, DigiCert experienced a breach due to a social engineering attack that compromised its tech support team. An attacker tricked two employees into executing a malicious screensaver file, leading to the theft of 27 code signing certificates. These certificates were subsequently used to si...

Public Exploits

Checking GitHub for proof-of-concept code…