Exploited Known exploited (KEV) Ransomware use CVE-2025-60710

One product listed 172 times: a Windows link following flaw and what repetition means

Microsoft Windows Added to KEV Apr 13, 2026 Federal remediation due 2026-04-27

A privilege escalation flaw added to the CISA exploited-vulnerabilities catalog on 13 April 2026. Windows appears in that catalog 172 times, more than any other product in these records.

Key facts

  • CVE IDCVE-2025-60710
  • Affected (vendor / product)Microsoft Windows
  • CWECWE-59
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-04-27 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A privilege escalation flaw in Windows from link following (CWE-59), added to the catalog on 13 April 2026.
  • The remediation date was 27 April 2026, a fourteen-day window, and ransomware use is confirmed.
  • Of the 1,695 KEV records this site holds as of 2026-09-06, across 711 products, Windows accounts for 172.
  • Those 172 span identifier years 2002 to 2026 and several weakness types: use after free, out-of-bounds write, link following.

1The catalog is unevenly distributed across products

A catalog of exploited vulnerabilities is a list built one flaw at a time. Counted by product, however, the distribution is heavily skewed. Of the 1,695 KEV records this site holds as of 2026-09-06, spread across 711 products, Windows alone accounts for 172.

KEV records this site holds as of 2026-09-061,695across 711 products
Times Windows appears172the most of any product
Window on this record14 daysadded 13 April 2026, due 27 April

2How those 172 spread across years

The 172 Windows entries do not cluster in one period. By the year in the CVE identifier they run from 2002 to 2026, with more entries in recent years.

Identifiers from 202526 / 172
Identifiers from 202422 / 172
Identifiers from 202119 / 172
Identifiers from 201916 / 172
Identifiers from 202314 / 172

The weakness types are scattered too. The leaders are use after free (CWE-416) with 13, out-of-bounds write (CWE-787) with 13, link following (CWE-59) with 11 and improper input validation (CWE-20) with 11. This is not one cause recurring; it is a broad product in which varied defects keep being found.

3What this record shows

The weakness here is link following (CWE-59), the same type as 11 of the 172 Windows entries. An attacker substitutes the target a program follows and so causes operations beyond the intended privilege. This is not a way in from outside but a way up from a foothold already inside.

The record is also among those where use in ransomware campaigns has been confirmed. Of the 172 Windows entries, 49 (28.5%) carry that confirmation.

The next article takes up a single record that spans six operating systems.

Why it matters

Alongside tracking individual vulnerabilities, it pays to review priorities by how often a product appears. For products that recur, assume the next entry is coming and have the update and monitoring path ready in advance.

FAQ

What is a link following vulnerability?
A defect in which an attacker substitutes the target of a link a program follows, causing it to act on something it should not reach.
Does 172 listings mean the product is dangerous?
Not directly. Widely used products attract more attack and more research, so they appear more often. The count reflects visibility as much as risk.
How should a fourteen-day window be used?
The catalog deadline is directed at federal agencies, but since exploitation is confirmed the date is a usable priority signal for anyone.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#Known exploited#Windows#Privilege escalation#Vulnerability management
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.