[UPDATE] [critical] Microsoft Windows products: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Windows products to execute arbitrary code, escalate privileges, conduct a Denial of Service attack, disclose information, and bypass security measures.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to execute arbitrary code, escalate privileges, conduct denial of service attacks, disclose information, and bypass security measures.
- Who is affected
- All deployments of Microsoft Windows products are affected.
- Urgency
- Remediation is urgent due to the critical severity and confirmed exploitation.
- Action
- Apply the latest security updates provided by Microsoft.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows
Get an email when a new Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1489
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-42897Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-545180.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-215300.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-321610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-321700.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-322090.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-338340.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-338352.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 80% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-338371.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-338380.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8668-1: Linux kernel (GCP) vulnerabilitiesubuntu
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 21, 2026)cert-fr-avis
- unknownUSN-8665-1: Linux kernel (Raspberry Pi) vulnerabilitiesubuntu
- unknownUSN-8664-1: Linux kernel (NVIDIA BaseOS) vulnerabilitiesubuntu
- unknownUSN-8663-1: Linux kernel (NVIDIA) vulnerabilitiesubuntu
- high[UPDATE] [high] AMD Processor: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 14, 2026)cert-fr-avis
- unknownDSA-6424-1 xen - security updatedebian
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 07, 2026)cert-fr-avis
- unknownUbuntu Linux Kernel Multiple Vulnerabilitieshkcert
- unknownUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilitiesubuntu
- unknownUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilitiesubuntu
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25