[UPDATE] [critical] Microsoft Windows: Multiple Vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in Microsoft Windows products to elevate privileges, disclose information, bypass security measures, execute arbitrary code, present false information, perform a denial of service attack, and perform an unspecified attack.
CSIRTS triage
- What
- Multiple vulnerabilities in Windows permit remote code execution, privilege escalation, information disclosure, security bypass, denial of service, and other attacks.
- Who is affected
- Windows deployments across versions are affected; specific version ranges not detailed in advisory.
- Urgency
- Immediate patching required; vulnerabilities are actively exploited and rated critical.
- Action
- Apply the latest Microsoft Windows security updates addressing CVE-2026-32202, CVE-2026-27912, CVE-2023-20585, CVE-2025-6965, CVE-2026-0390, CVE-2026-20806, CVE-2026-20928, and CVE-2026-20930.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows
Get an email when a new Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1104
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-32202Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-279120.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-205850.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2025-6965EPSS puts this in the most-targeted tier (74.9% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-03900.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-208060.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-209280.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-209300.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-236700.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-251840.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [high] Dell PowerProtect Data Domain OS: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Red Hat Enterprise Linux (nodejs, perl): Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in SUSE Linux kernel (July 31, 2026)cert-fr-avis
- medium[UPDATE] [medium] AMD processors: Multiple vulnerabilitiescert-bund
- criticalexploitedCVE-2026-32202: Microsoft Windows Protection Mechanism Failure Vulnerabilitycisa-kev
Recent advisories for Microsoft Windows
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilitiescert-bund · 2026-08-14
- medium[NEW] [medium] Microsoft Windows Package Manager: Vulnerability enables Privilege Escalationcert-bund · 2026-08-12
- unknownexploitedMultiple vulnerabilities in Microsoft Windows (August 12, 2026)cert-fr-avis · 2026-08-12
- unknownexploitedNCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windowsncsc-nl · 2026-08-11
- mediumCVE-2026-59136: Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to di…nvd · 2026-08-11
- mediumCVE-2026-59135: Weak authentication in Microsoft Windows Search Component allows an authorized attacker to dis…nvd · 2026-08-11
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17