← Back to BrewedIntel
vulnerabilitycriticalPrivilege EscalationZero-day Exploit

Apr 17, 2026 • Sergiu Gatlan

Recently leaked Windows zero-days now exploited in attacks

Multiple Windows zero-day vulnerabilities have been disclosed and are now being actively exploited by threat actors in the wild. These security flaws are...

Source
Bleeping Computer
Category
vulnerability
Severity
critical

Executive Summary

Multiple Windows zero-day vulnerabilities have been disclosed and are now being actively exploited by threat actors in the wild. These security flaws are being leveraged to gain SYSTEM or elevated administrator permissions on targeted systems. The vulnerabilities represent a significant risk as they allow attackers to bypass existing security controls and achieve high-privilege access without initial footholds. Organizations should apply emergency patches immediately, restrict administrative privileges where possible, and implement robust monitoring for suspicious privilege escalation activity. The active exploitation indicates these zero-days are being rapidly weaponized in both targeted and opportunistic attack campaigns.

Summary

Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. [...]

Published Analysis

Multiple Windows zero-day vulnerabilities have been disclosed and are now being actively exploited by threat actors in the wild. These security flaws are being leveraged to gain SYSTEM or elevated administrator permissions on targeted systems. The vulnerabilities represent a significant risk as they allow attackers to bypass existing security controls and achieve high-privilege access without initial footholds. Organizations should apply emergency patches immediately, restrict administrative privileges where possible, and implement robust monitoring for suspicious privilege escalation activity. The active exploitation indicates these zero-days are being rapidly weaponized in both targeted and opportunistic attack campaigns. Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. [...] Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. [...]