[UPDATE] [critical] Microsoft Windows: Multiple Vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in Microsoft Windows products to elevate privileges, disclose information, bypass security measures, execute arbitrary code, present false information, perform a denial of service attack, and perform an unspecified attack.
CSIRTS triage
- What
- Multiple vulnerabilities in Windows permit remote code execution, privilege escalation, information disclosure, security bypass, denial of service, and other attacks.
- Who is affected
- Windows deployments across versions are affected; specific version ranges not detailed in advisory.
- Urgency
- Immediate patching required; vulnerabilities are actively exploited and rated critical.
- Action
- Apply the latest Microsoft Windows security updates addressing CVE-2026-32202, CVE-2026-27912, CVE-2023-20585, CVE-2025-6965, CVE-2026-0390, CVE-2026-20806, CVE-2026-20928, and CVE-2026-20930.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows
Get an email when a new Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1104
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-32202Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-279120.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-205850.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2025-6965EPSS puts this in the most-targeted tier (75.8% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-03900.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-208060.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-209280.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-209300.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-236700.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-251840.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] Red Hat Enterprise Linux (nodejs, perl): Mehrere Schwachstellencert-bund
- mediumCVE-2026-25250: EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" as…nvd
- high[UPDATE] [high] Dell PowerProtect Data Domain OS: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in SUSE Linux kernel (July 31, 2026)cert-fr-avis
- medium[UPDATE] [medium] AMD processors: Multiple vulnerabilitiescert-bund
- criticalexploitedCVE-2026-32202: Microsoft Windows Protection Mechanism Failure Vulnerabilitycisa-kev
Recent advisories for Microsoft Windows
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEU] [kritisch] Microsoft Windows: Mehrere Schwachstellencert-bund · 2026-09-09
- unknownexploitedNCSC-2026-0353 [1.01] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl · 2026-09-09
- unknownexploitedMultiples vulnérabilités dans Microsoft Windows (09 septembre 2026)cert-fr-avis · 2026-09-09
- unknownNCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl · 2026-09-08
- highCVE-2026-81353: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
- highCVE-2026-81352: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14