The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Windows Task Host vulnerability to its Known Exploited Vulnerabilities Catalog, confirming that ransomware gangs are now abusing the flaw. The agency first flagged the vulnerability, tracked as CVE-2025-60710, as actively exploited in April. CISA’s latest update on Friday expands that warning to specify that ransomware operators are using it in attacks. The flaw is a privilege escalation issue in Windows Task Host, a core Windows component that manages background processes.

Task Host is designed to allow DLL-based processes to run and ensure they close properly during system shutdown, preventing data corruption. The vulnerability stems from a link following weakness and affects Windows 11 and Windows Server 2025. Microsoft patched the issue in November 2025. Successful exploitation allows a local attacker with basic user permissions to gain SYSTEM privileges, giving them full control over unpatched devices.

CISA gave Federal Civilian Executive Branch (FCEB) agencies two weeks to secure their systems when it first added the vulnerability to its catalog in April. The agency has not shared any details about ongoing attacks targeting CVE-2025-60710. Microsoft has also not yet updated its security advisory to confirm in-the-wild exploitation, and a company spokesperson was not immediately available for comment. CISA warned that this type of vulnerability is a frequent attack vector for malicious actors and poses significant risks to the federal enterprise.

The agency advised applying mitigations according to vendor instructions, following applicable BOD 22-01 guidance for cloud services, or discontinuing use of the product if mitigations are unavailable. This warning comes one week after CISA similarly flagged that ransomware gangs had begun exploiting a Microsoft SharePoint remote code execution vulnerability, tracked as CVE-2026-45659, following confirmation of active exploitation in early July. Since November 2021, CISA has identified 383 actively exploited vulnerabilities in Microsoft products, with 112 of those also abused in ransomware attacks.

The latest update highlights a broader trend in how defenses can appear strong on aggregate metrics while failing at critical stages. Once attackers gain valid credentials, the effectiveness of prevention measures drops significantly, according to the Blue Report 2026. That report measured defenses across 338 million simulations run in customer production environments, breaking down performance technique by technique. The new catalog entry underscores the continued pressure on federal agencies and enterprises to patch quickly against known exploited flaws.