INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Windows Task Host flaw now exploited in ransomware attacks

| 2026-08-18 10:32 CRITICAL HIGH
Executive Summary AI-generated
The Windows Task Host vulnerability, identified as CVE-2025-60710, has been exploited by ransomware gangs in recent weeks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the issue on August 18, with Microsoft patching the flaw earlier that day. This vulnerability affects Windows 11 and Server 2025 devices, which were patched in November 2025. Ransomware gangs have been using this exploit to launch attacks since April, when CISA flagged it as actively exploited. The agency has warned of ongoing attacks and advised users to apply mitigations per vendor instructions or discontinue use if available.
Technical Mitigations AI-generated
* Apply Microsoft SharePoint Patch Tuesday updates (July 2026) to systems running SharePoint Enterprise Server 2016 and SharePoint Server 2019. * Use a secure authentication mechanism, such as OAuth or OpenID Connect, instead of JWT token validation pipeline for sensitive applications. * Implement additional security controls, such as two-factor authentication or IP blocking, on Microsoft SharePoint servers exposed online (Shadowserver). * Regularly update and patch all Microsoft products, including Windows and Office, to ensure you have the latest security fixes and patches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-55040CVE-2026-55040 CVE-2026-45659CVE-2026-45659 CVE-2025-60710CVE-2025-60710 CVE-2026-33825CVE-2026-33825
Target & Sectors
Global Scope
Incident Timeline
‎November 2021
Threat actors used a vulnerability in Microsoft SharePoint to target various products, including 112 different items.
tactic Ransomware
general_metric 383 exploited vulnerabilities
general_metric 112 products
general_metric 14 agency
‎November 2025
Threat actors exploited a link following weakness in Windows to target affected devices.
infrastructure Windows
tactic Privilege Escalation
vulnerability CVE-2025-60710
organisation Microsoft
tactic T1584.004 - Server
general_metric 11 Windows
‎April 13
Threat actors used a known vulnerability in Microsoft SharePoint to target Federal Civilian Executive Branch agencies.
vulnerability CVE-2025-60710
attribution Federal Civilian Executive Branch
attribution FCEB
‎July 1
Threat actors exploited the T1588.006 vulnerability in Microsoft SharePoint, compromising targeted systems within three days of discovery on July 1.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
‎July 15
Microsoft's CVE-2026-55040 exploit was likely used to target U.S. network defenders on July 15.
vulnerability CVE-2026-55040
‎July 2026
Microsoft released security patches for the T1584.004 vulnerability in its SharePoint Enterprise Server 2016 and 2019 versions on July 2026.
organisation Microsoft
tactic T1584.004 - Server
organisation SharePoint Enterprise
‎2026/08/11
Ransomware gangs began using a high-severity Microsoft SharePoint remote code execution vulnerability yesterday.
tactic Ransomware
attribution CISA
tactic Remote Code Execution
‎2026/08/12
Rapid7's exploit code was used in attacks targeting its honeypots on or around August 12, 2026.
‎2026/08/18
Microsoft's CVE-2025-60710 vulnerability was exploited in the incident.
organisation CVE-2025-60710
organisation BleepingComputer
‎2026/08/18
Ransomware gangs are exploiting a high-severity Windows Task Host vulnerability (CVE-2026-45659) and a Microsoft SharePoint remote code execution vulnerability (CVE-2026-33825).
infrastructure Windows
organisation Windows Task Host
organisation Microsoft SharePoint
organisation DLL
organisation Windows Antimalware Scan Interface
organisation Microsoft Defender Antivirus
organisation Microsoft
organisation SharePoint Enterprise
organisation SharePoint
organisation CVE-2026
organisation Shadowserver
infrastructure 8,500 SharePoint servers
organisation BOD
organisation The Blue Report 2026
organisation JWT
organisation the @rapid7 POC
organisation PoC
organisation SharePoint Central Administration
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
8,500
Sharepoint Servers
Intelligence Sources
BleepingComputer 2026-08-12
BleepingComputer 2026-08-18