The Windows Task Host flaw CVE-2025-60710 becomes a ransomware weapon in CISA’s KEV catalog
CISA updated its KEV catalog to flag the Windows Task Host privilege-escalation flaw CVE-2025-60710, patched in November 2025, as now being exploited by ransomware gangs. Organizations must treat privilege-escalation patches with the same urgency as RCEs: this is the link that turns limited access into full control.