Skip to content

CISA Confirms Ransomware Exploitation of Windows Task Host Vulnerability

Bottom line: CISA confirms that, in addition to the original attackers, ransomware groups are now also exploiting a Windows Task Host vulnerability that has been listed as actively exploited since April.

The US cybersecurity agency CISA has confirmed that, alongside other threat actors, ransomware groups are now also exploiting a vulnerability rated high-severity in the Windows Task Host. The flaw had already been flagged as actively exploited back in April.

CISA has updated its assessment of a Windows Task Host vulnerability classified as “high-severity.” The flaw was already added to the Known Exploited Vulnerabilities (KEV) catalog back in April of this year, after active exploitation had been observed. The agency now confirms that ransomware groups are additionally leveraging the vulnerability for their attacks.

For CISOs, the involvement of ransomware actors signals an escalation of the threat landscape: while initial exploitation is often carried out by specialized attackers with limited targets, the adoption by ransomware groups points to broader, more opportunistic exploitation of the flaw. Affected Windows systems that have not yet been patched are thus increasingly at risk from automated or widely distributed attack campaigns aimed at encryption and extortion.

Organizations with Windows infrastructure should verify whether the relevant security updates have been applied in accordance with vendor guidance. Inclusion in CISA’s KEV catalog also obligates US federal agencies to prioritize remediation within defined deadlines — a signal that can likewise serve organizations outside the US as an indicator of the urgency of patch prioritization.


Source: www.bleepingcomputer.com · Published August 18, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: