INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Windows Task Host flaw now exploited in ransomware attacks
| 2026-08-18 10:32 CRITICAL HIGHExecutive Summary AI-generated
The Windows Task Host vulnerability, identified as CVE-2025-60710, has been exploited by ransomware gangs in recent weeks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the issue on August 18, with Microsoft patching the flaw earlier that day. This vulnerability affects Windows 11 and Server 2025 devices, which were patched in November 2025. Ransomware gangs have been using this exploit to launch attacks since April, when CISA flagged it as actively exploited. The agency has warned of ongoing attacks and advised users to apply mitigations per vendor instructions or discontinue use if available.
Technical Mitigations AI-generated
* Apply Microsoft SharePoint Patch Tuesday updates (July 2026) to systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
* Use a secure authentication mechanism, such as OAuth or OpenID Connect, instead of JWT token validation pipeline for sensitive applications.
* Implement additional security controls, such as two-factor authentication or IP blocking, on Microsoft SharePoint servers exposed online (Shadowserver).
* Regularly update and patch all Microsoft products, including Windows and Office, to ensure you have the latest security fixes and patches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-55040CVE-2026-55040
CVE-2026-45659CVE-2026-45659
CVE-2025-60710CVE-2025-60710
CVE-2026-33825CVE-2026-33825
Target & Sectors
Global Scope
Incident Timeline
November 2021
Threat actors used a vulnerability in Microsoft SharePoint to target various products, including 112 different items.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, the agency has flagged
383 actively exploited vulnerabilities in various Microsoft products
, 112 of which have also been exploited in ransomware attacks.
Since November 2021, the cybersecurity agency has flagged
14 actively exploited Microsoft SharePoint vulnerabilities
, with eight of them also exploited in ransomware attacks.
general_metric
383 exploited vulnerabilities
Since November 2021, the agency has flagged
383 actively exploited vulnerabilities in various Microsoft products
, 112 of which have also been exploited in ransomware attacks.
general_metric
112 products
Since November 2021, the agency has flagged
383 actively exploited vulnerabilities in various Microsoft products
, 112 of which have also been exploited in ransomware attacks.
general_metric
14 agency
Since November 2021, the cybersecurity agency has flagged
14 actively exploited Microsoft SharePoint vulnerabilities
, with eight of them also exploited in ransomware attacks.
November 2025
Threat actors exploited a link following weakness in Windows to target affected devices.
Click on any entity below to view its context and source!
infrastructure
Windows
Tracked as
CVE-2025-60710
, this Windows privilege escalation security flaw was patched by Microsoft
in November 2025
and stems from a
link following
weakness that affects Windows 11 and Windows Server 2025 devices.
tactic
Privilege Escalation
Tracked as
CVE-2025-60710
, this Windows privilege escalation security flaw was patched by Microsoft
in November 2025
and stems from a
link following
weakness that affects Windows 11 and Windows Server 2025 devices.
vulnerability
CVE-2025-60710
Tracked as
CVE-2025-60710
, this Windows privilege escalation security flaw was patched by Microsoft
in November 2025
and stems from a
link following
weakness that affects Windows 11 and Windows Server 2025 devices.
organisation
Microsoft
Tracked as
CVE-2025-60710
, this Windows privilege escalation security flaw was patched by Microsoft
in November 2025
and stems from a
link following
weakness that affects Windows 11 and Windows Server 2025 devices.
tactic
T1584.004 - Server
Tracked as
CVE-2025-60710
, this Windows privilege escalation security flaw was patched by Microsoft
in November 2025
and stems from a
link following
weakness that affects Windows 11 and Windows Server 2025 devices.
general_metric
11 Windows
Tracked as
CVE-2025-60710
, this Windows privilege escalation security flaw was patched by Microsoft
in November 2025
and stems from a
link following
weakness that affects Windows 11 and Windows Server 2025 devices.
April 13
Threat actors used a known vulnerability in Microsoft SharePoint to target Federal Civilian Executive Branch agencies.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-60710
While it didn't share any details regarding ongoing attacks and Microsoft has yet to update its
security advisory
to confirm in-the-wild exploitation, CISA
added
CVE-2025-60710 to its
list of actively exploited vulnerabilities
on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems.
attribution
Federal Civilian Executive Branch
While it didn't share any details regarding ongoing attacks and Microsoft has yet to update its
security advisory
to confirm in-the-wild exploitation, CISA
added
CVE-2025-60710 to its
list of actively exploited vulnerabilities
on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems.
attribution
FCEB
While it didn't share any details regarding ongoing attacks and Microsoft has yet to update its
security advisory
to confirm in-the-wild exploitation, CISA
added
CVE-2025-60710 to its
list of actively exploited vulnerabilities
on April 13 and gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems.
July 1
Threat actors exploited the T1588.006 vulnerability in Microsoft SharePoint, compromising targeted systems within three days of discovery on July 1.
Click on any entity below to view its context and source!
attribution
Known Exploited
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
tactic
T1588.006 - Vulnerabilities
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
attribution
KEV
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
attribution
Federal Civilian Executive Branch
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
attribution
FCEB
"
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV)
on July 1
, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.
July 15
Microsoft's CVE-2026-55040 exploit was likely used to target U.S. network defenders on July 15.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-55040
Likely based on Microsoft's exploitability assessment, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
warned network defenders
on July 15 to secure their SharePoint servers against potential CVE-2026-55040 attacks.
July 2026
Microsoft released security patches for the T1584.004 vulnerability in its SharePoint Enterprise Server 2016 and 2019 versions on July 2026.
Click on any entity below to view its context and source!
organisation
Microsoft
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
tactic
T1584.004 - Server
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
organisation
SharePoint Enterprise
Microsoft patched the vulnerability as part of the July 2026 Patch Tuesday updates, when it warned customers to patch systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019.
2026/08/11
Ransomware gangs began using a high-severity Microsoft SharePoint remote code execution vulnerability yesterday.
Click on any entity below to view its context and source!
tactic
Ransomware
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
attribution
CISA
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
tactic
Remote Code Execution
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
2026/08/12
Rapid7's exploit code was used in attacks targeting its honeypots on or around August 12, 2026.
2026/08/18
Microsoft's CVE-2025-60710 vulnerability was exploited in the incident.
Click on any entity below to view its context and source!
organisation
CVE-2025-60710
The U.S. cybersecurity agency has not yet shared any information about attacks targeting CVE-2025-60710, and a Microsoft spokesperson was not immediately available for comment when BleepingComputer reached out earlier today.
organisation
BleepingComputer
The U.S. cybersecurity agency has not yet shared any information about attacks targeting CVE-2025-60710, and a Microsoft spokesperson was not immediately available for comment when BleepingComputer reached out earlier today.
2026/08/18
Ransomware gangs are exploiting a high-severity Windows Task Host vulnerability (CVE-2026-45659) and a Microsoft SharePoint remote code execution vulnerability (CVE-2026-33825).
Click on any entity below to view its context and source!
infrastructure
Windows
Windows Task Host flaw now exploited by ransomware gangs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
organisation
Windows Task Host
Windows Task Host flaw now exploited by ransomware gangs.
organisation
Microsoft SharePoint
Microsoft SharePoint flaw now exploited in ransomware attacks.
Hackers leverage new Microsoft SharePoint exploit in attacks.
organisation
DLL
Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
organisation
Windows Antimalware Scan Interface
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
organisation
Microsoft Defender Antivirus
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
organisation
Microsoft
It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.
organisation
SharePoint Enterprise
It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.
organisation
SharePoint
Tracked as
CVE-2026-45659
, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.
Tracked as
CVE-2026-55040
, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.
organisation
CVE-2026
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
"Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused warned.
organisation
Shadowserver
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
"
Internet threat watchdog Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online.
infrastructure
8,500 SharePoint servers
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
"
Internet threat watchdog Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online.
organisation
BOD
"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
JWT
Tracked as
CVE-2026-55040
, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.
organisation
the @rapid7 POC
"Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots," Defused warned.
organisation
PoC
A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday, is already being used in attacks.
organisation
SharePoint Central Administration
It also recommended blocking external access to SharePoint Central Administration and restricting farm and database communication to the required systems.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Windows Task Host flaw now exploited by ransomware gangs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
Tracked as
CVE-2025-60710
, this Windows privilege escalation security flaw was patched by Microsoft
in November 2025
and stems from a
link following
weakness that affects Windows 11 and Windows Server 2025 devices.
Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
Metrics
infrastructure
8,500
Sharepoint Servers
"
Internet threat watchdog Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online.
Internet security watchdog group Shadowserver currently tracks
over 8,500 Microsoft SharePoint servers
exposed online, with
over 200 of them
unpatched against the CVE-2026-45659 vulnerability.
Intelligence Sources
BleepingComputer
2026-08-11
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer
BleepingComputer
2026-08-12
Hackers leverage new Microsoft SharePoint exploit in attacks
BleepingComputer
BleepingComputer
2026-08-18
CISA: Windows Task Host flaw now exploited by ransomware gangs
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-19T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
Windows Task Host
entity
13x
timeline
Temporal Reference
November 2025
date
10x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
4x
tactic
Cyber Operation Type
Ransomware
tactic
4x
vulnerability
Exploited CVE
CVE-2025-60710
cve
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
Contextual Telemetry
Context Block
10 METRICS
infrastructure
Affected Product
Windows
software
general metric
Windows
11
windows
general metric
Exploited Vulnerabilities
383
exploited vulnerabilities
general metric
Products
112
products
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Agency
14
agency
infrastructure
Sharepoint Servers
8,500
sharepoint servers
general metric
Reverse Proxy
7
reverse proxy
general metric
Unpatched
200
unpatched
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.