LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-60710: Microsoft Windows Link Following Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 13, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-60710 to its Known Exploited Vulnerabilities catalog on Apr 13, 2026, with a federal patch deadline of Apr 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

This vulnerability is a link following issue in Microsoft Windows that can result in privilege escalation. It matters because an attacker who can trigger the flaw may obtain elevated access on systems where the affected component runs.

How it works

The weakness is classified under CWE-59. It stems from improper resolution of links before file access. An attacker can supply or manipulate a link so that an operation intended for one resource is redirected to another, potentially allowing actions that require higher privileges.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Inventory Windows endpoints and servers through standard asset management tools or configuration management databases. Check installed operating system versions and any related components against the details listed in the vendor advisory. Review system and application logs for anomalous file or link operations that could indicate attempted exploitation.

How to remediate

Apply the update provided by the vendor as specified in the advisory. After patching, review Windows configurations that control link resolution and file access to reduce the attack surface for this class of weakness.

If you can't patch immediately

Apply mitigations according to the vendor instructions. For any cloud services involved, follow applicable BOD 22-01 guidance. If suitable mitigations are unavailable, discontinue use of the affected product or component.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-59
Added to CISA KEVApr 13, 2026
Federal patch deadlineApr 27, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities