The U.S. Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities Catalog to mark a Windows Task Host flaw as being used by ransomware gangs, BleepingComputer reports. The vulnerability is tracked as CVE-2025-60710. According to BleepingComputer, it is a high-severity Windows privilege-escalation flaw in Task Host, a core Windows component that helps run DLL-based background processes and close them properly during shutdown. Microsoft patched the issue in November 2025. BleepingComputer reports that the bug stems from a link-following weakness and affects Windows 11 and Windows Server 2025 devices. The risk is escalation after a foothold. BleepingComputer reports that local attackers with basic user permissions can exploit the flaw to gain SYSTEM privileges, giving them full control of unpatched devices. CISA had already treated CVE-2025-60710 as active exploitation. BleepingComputer says the agency added the vulnerability to the KEV catalog on April 13 and gave Federal Civilian Executive Branch agencies two weeks to secure affected systems. The new development is the ransomware designation. BleepingComputer reports that CISA updated the KEV entry again on Friday to flag the flaw as abused by ransomware gangs, but the agency has not published details on the attacks. The report also says Microsoft had not updated its security advisory to confirm in-the-wild exploitation, and that a Microsoft spokesperson was not immediately available for comment. CISA’s guidance, as summarized by BleepingComputer, is to apply vendor mitigations, follow applicable federal cloud-service guidance, or discontinue use if mitigations are unavailable. The report places the Windows Task Host bug in a broader Microsoft exposure pattern. BleepingComputer says CISA warned one week earlier that ransomware gangs had begun exploiting a Microsoft SharePoint remote-code-execution vulnerability, CVE-2026-45659, after confirming active exploitation in early July. Since November 2021, according to BleepingComputer, CISA has flagged 383 actively exploited vulnerabilities across Microsoft products, including 112 that were also exploited in ransomware attacks. Who benefits: Organizations that already applied Microsoft’s November 2025 fix or CISA-recommended mitigations are better positioned. Security teams also get a clearer remediation priority from the ransomware tag. Who's exposed: Unpatched Windows 11 and Windows Server 2025 devices are the named exposure. The supplied reporting does not identify specific victims, ransomware groups, or attack chains.