Find notable cyber news and cases, enriched with sources, timelines, and signals.

Windows Collaborative Translation Framework CTFMON improper link resolution EoP security flaw (CVE-2026-45586)

Vulnerability
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

Windows Collaborative Translation Framework (CTFMON) has a local privilege-escalation vulnerability, CVE-2026-45586, that Microsoft patched in June 2026. An authorized attacker can abuse improper link resolution to gain SYSTEM-level privileges on affected Windows systems. Microsoft says the flaw was publicly disclosed, but it is not known to have been exploited in attacks.

Related Happenings

Microsoft RDP file security guidance

Advisory/Mitigation
H score28 First: 14.07.2026 21:49 Last: 14.07.2026 21:49 Sources 1

About this happening: Microsoft issued RDP mitigation guidance that restricts which .rdp files users can open and recommends migrating trusted publishers to SHA-256 thumbprints, reducing ph...

Microsoft Defender RoguePlanet race-condition zero-day remote code execution flaw

Vulnerability
H score39 First: 10.06.2026 02:11 Last: 10.06.2026 02:11 Sources 1

About this happening: Microsoft Defender zero-day RoguePlanet is a race-condition flaw affecting fully patched Windows 10 and Windows 11 systems. A public proof-of-concept exploit was released shortly...

Latest development: 10.06.2026 08:22

The anonymous security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, released a proof-of-concept (PoC) exploit for the Microsoft Defender zero-day RoguePlanet under a new GitHub account named MSNightmare. The race-condition exploit can yield a SYSTEM-level shell and arbitrary code execution when it succeeds, has been tested on Windows 11 and Windows 10 with the June 2026 Patch Tuesday updates installed, and currently does not work on Windows Server without redesign because standard users cannot mount an ISO image.

CCB urgent patch warning for CVE-2026-41089 on Windows servers

Public Sector Action
H score48 First: 01.06.2026 15:30 Last: 01.06.2026 15:30 Sources 1

About this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...

CISA orders FCEB remediation for CVE-2025-60710

Public Sector Action
H score34 First: 15.04.2026 17:51 Last: 15.04.2026 17:51 Sources 1

About this happening: CISA added CVE-2025-60710 to its actively exploited catalog and gave FCEB agencies two weeks to secure systems under BOD 22-01. The move targets a Windows Ta...

Timeline

  1. 09.06.2026 20:57 2 articles · 1mo ago

    Microsoft patches CVE-2026-45586 in Windows Collaborative Translation Framework

    Mitigation Patch Update

    Microsoft's June 2026 Patch Tuesday includes a fix for CVE-2026-45586, a publicly disclosed elevation-of-privilege flaw in Windows Collaborative Translation Framework (CTFMON). Improper link resolution before file access ('link following') can let an authorized attacker elevate privileges locally to SYSTEM on affected Windows systems.

    Show sources