← Back to BrewedIntel
vulnerabilitycriticalPrivilege EscalationZero-day Exploit

Apr 17, 2026 • Sergiu Gatlan

Recently leaked Windows zero-days now exploited in attacks

Three recently disclosed Windows zero-day vulnerabilities are being actively exploited in the wild by threat actors. These vulnerabilities allow attackers to...

Source
Bleeping Computer
Category
vulnerability
Severity
critical

Executive Summary

Three recently disclosed Windows zero-day vulnerabilities are being actively exploited in the wild by threat actors. These vulnerabilities allow attackers to escalate privileges to SYSTEM or administrator-level access on compromised systems. The vulnerabilities affect core Windows components and pose a critical risk to enterprise environments. Microsoft has been notified and patches are expected. Organizations should prioritize applying emergency patches once available, monitor for indicators of privilege escalation, and restrict administrative access where possible. The active exploitation suggests these zero-days were discovered through leaked source code or independent vulnerability research.

Summary

Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. [...]

Published Analysis

Three recently disclosed Windows zero-day vulnerabilities are being actively exploited in the wild by threat actors. These vulnerabilities allow attackers to escalate privileges to SYSTEM or administrator-level access on compromised systems. The vulnerabilities affect core Windows components and pose a critical risk to enterprise environments. Microsoft has been notified and patches are expected. Organizations should prioritize applying emergency patches once available, monitor for indicators of privilege escalation, and restrict administrative access where possible. The active exploitation suggests these zero-days were discovered through leaked source code or independent vulnerability research. Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. [...] Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. [...]