Microsoft Patches Critical Windows Zero-Day Exploited in US Government Networks
• Microsoft issued Patch Tuesday on April 25, 2026, fixing CVE-2026-1234 zero-day in Windows Kernel exploited by Chinese state actors against 15 US agencies. • Vulnerability allowed remote code execution with 9.8 CVSS score, affecting Windows 11 and Server 2025 in 40% of federal endpoints. • CISA urges immediate patching, citing 'active exploitation' in ongoing incident response.
bleepingcomputer.com