Prevent Ransomware Blog

CISA Confirms Windows Flaw Is Being Used in Ransomware Attacks

Written by Tony Chiappetta | Aug 21, 2026, 9:00:00 AM

Another Windows vulnerability. Another patch. So why is CISA now warning that ransomware gangs are actually exploiting it?

This is where a vulnerability stops being an IT problem and becomes a business risk.

The latest warning reported by BleepingComputer involves a Windows vulnerability that can allow an attacker to elevate privileges and gain SYSTEM-level control. CISA has now confirmed the vulnerability is being used in ransomware attacks.

So what exactly happened?

The vulnerability, CVE-2025-60710, affects Windows 11 and Windows Server 2025 and involves Windows Task Host, a legitimate Windows component.

Microsoft patched the vulnerability in November 2025. CISA later added it to its Known Exploited Vulnerabilities Catalog after confirming active exploitation. Now CISA has taken the warning further by identifying the vulnerability as being used in ransomware campaigns.

An attacker needs some initial local access, but that is precisely why this matters. Once inside with basic user permissions, successful exploitation can provide SYSTEM privileges, giving the attacker extensive control over an unpatched machine.

In other words, getting into the network may only be step one. Privilege escalation can turn limited access into something far more dangerous.

Why should business leaders care?

Because attackers do not need every part of their attack to succeed. They need enough pieces to succeed.

A stolen credential, phishing attack, vulnerable application or compromised third party may provide the initial foothold. A privilege escalation vulnerability can then help an attacker gain greater control, disable defenses, steal credentials, move laterally and ultimately deploy ransomware.

The 2026 Verizon Data Breach Investigations Report found that 31% of breaches now begin with exploitation of software vulnerabilities, making vulnerabilities the leading initial access vector. It also found ransomware involved in 48% of breaches.

CISA's numbers make the connection even clearer. Since November 2021, it has identified 383 actively exploited vulnerabilities in Microsoft products, 112 of which have also been exploited in ransomware attacks.

Isn't patching the answer?

Patching is essential. Organizations should apply Microsoft's security update for CVE-2025-60710 if they have not already done so.

But patching alone is not a complete security strategy.

Businesses operate thousands of applications, endpoints, servers and third-party systems. New vulnerabilities are continuously discovered. There is inevitably a period between vulnerability discovery, patch availability, testing and deployment.

And zero-day vulnerabilities have no patch when attackers first begin exploiting them.

The question therefore becomes: What protects the business when something gets through?

Isn't that what EDR is supposed to do?

EDR remains an important security layer, but Detect and Respond assumes suspicious activity can be recognized quickly enough to stop it.

Attackers increasingly use stolen credentials, legitimate Windows utilities, living-off-the-land techniques and trusted applications to make malicious activity look more like normal activity. They also attempt to tamper with or disable endpoint security tools.

That creates a dangerous race between the attacker and detection.

Modern ransomware can move quickly once sufficient privileges are obtained. If detection occurs after credentials have been stolen, defenses disabled, systems accessed or encryption started, responding successfully may still leave the organization facing downtime, recovery costs and potentially stolen data.

According to IBM's 2025 Cost of a Data Breach Report, the average U.S. data breach reached a record $10.22 million.

The cost is not simply the ransom. It can include business interruption, restoration, lost productivity, legal expenses, regulatory exposure, customer notification and reputational damage.

So what needs to change?

Organizations should begin thinking beyond Detect and Respond toward Isolation and Containment.

The objective is not to predict every attack. It is to restrict what applications and processes are allowed to do before malicious activity can cause damage.

That means preventing unauthorized execution, containing potentially dangerous processes, restricting access to sensitive resources, limiting attacker movement and reducing the blast radius when another security control fails.

This is the philosophy behind AppGuard, a proven endpoint protection solution with a 10-year track record focused on prevention through Isolation and Containment.

Rather than waiting for malicious behavior to be identified, the objective is to prevent untrusted or unauthorized activity from reaching the point where ransomware can execute, spread or encrypt critical resources.

Detection still matters. But organizations need controls designed around the assumption that eventually something will get through the first line of defense.

What Should Businesses Do Next?

Business leaders should assume detection will occasionally fail and ask what prevents damage when it does.

Prioritize patches for vulnerabilities known to be actively exploited, especially those in CISA's Known Exploited Vulnerabilities Catalog. Add prevention layers that restrict endpoint execution and attacker movement. Segment critical systems so one compromised endpoint cannot easily become an enterprise-wide incident.

Review privileged accounts and third-party access. Test what happens when EDR is bypassed, disabled or delayed. Make sure incident response and recovery plans are current and actually tested.

Most importantly, stop measuring cybersecurity only by whether you can detect an attacker.

Start asking whether the attacker can accomplish anything even if they get in.

Business owners who want to better understand how prevention-first security can stop attacks before damage occurs should listen to our August 19th Podcast and schedule time to talk with CHIPS about how AppGuard can help prevent incidents like this through Isolation and Containment.