One product listed 172 times: a Windows link following flaw and what repetition means
A privilege escalation flaw added to the CISA exploited-vulnerabilities catalog on 13 April 2026. Windows appears in that catalog 172 times, more than any other product in these records.
Key facts
- CVE IDCVE-2025-60710
- Affected (vendor / product)Microsoft Windows
- CWECWE-59
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-04-27 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A privilege escalation flaw in Windows from link following (CWE-59), added to the catalog on 13 April 2026.
- The remediation date was 27 April 2026, a fourteen-day window, and ransomware use is confirmed.
- Of the 1,695 KEV records this site holds as of 2026-09-06, across 711 products, Windows accounts for 172.
- Those 172 span identifier years 2002 to 2026 and several weakness types: use after free, out-of-bounds write, link following.
1The catalog is unevenly distributed across products
A catalog of exploited vulnerabilities is a list built one flaw at a time. Counted by product, however, the distribution is heavily skewed. Of the 1,695 KEV records this site holds as of 2026-09-06, spread across 711 products, Windows alone accounts for 172.
2How those 172 spread across years
The 172 Windows entries do not cluster in one period. By the year in the CVE identifier they run from 2002 to 2026, with more entries in recent years.
The weakness types are scattered too. The leaders are use after free (CWE-416) with 13, out-of-bounds write (CWE-787) with 13, link following (CWE-59) with 11 and improper input validation (CWE-20) with 11. This is not one cause recurring; it is a broad product in which varied defects keep being found.
3What this record shows
The weakness here is link following (CWE-59), the same type as 11 of the 172 Windows entries. An attacker substitutes the target a program follows and so causes operations beyond the intended privilege. This is not a way in from outside but a way up from a foothold already inside.
The record is also among those where use in ransomware campaigns has been confirmed. Of the 172 Windows entries, 49 (28.5%) carry that confirmation.
The next article takes up a single record that spans six operating systems.
Why it matters
Alongside tracking individual vulnerabilities, it pays to review priorities by how often a product appears. For products that recur, assume the next entry is coming and have the update and monitoring path ready in advance.
FAQ
What is a link following vulnerability?
Does 172 listings mean the product is dangerous?
How should a fourteen-day window be used?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).