Threat Brief — 2026-08-20 — Zero-Click Windows Exploit Goes Wild
A zero-click vulnerability affecting Windows 10, 11, and Server is now under mass exploitation after sitting unpatched for four months — patch immediately. CISA published a new ICS advisory for Johnson Controls Simplex Incident Manager allowing low-privilege local attackers to extract credentials from system memory. Microsoft also updated CVSS vectors for two SQL Server RCE flaws to reflect that no privileges are required for exploitation.
Top items
- Zero-click Windows vuln now mass-exploited (new): A vulnerability affecting Windows 10, 11, and Server editions that went unpatched for four months is now being actively exploited en masse. Described as "zero click," it requires immediate patching across all affected endpoints. (src: SecurityLab)
- Johnson Controls Simplex Incident Manager credential extraction (new): CISA issued an ICS advisory (ICSA-26-232-01) for a vulnerability in Johnson Controls Simplex Incident Manager. A local attacker with low privileges can extract passwords and authentication tokens from system memory, potentially leading to unauthorized access. Assess OT/physical-security systems for exposure. (src: CISA ICS Advisory)
- Microsoft SQL Server RCE — CVSS updated to no-privilege-required (new, informational): Microsoft revised the CVSS vectors for CVE-2026-54117 and CVE-2026-54118 to reflect that exploitation requires no privileges (PR:N). Both are Remote Code Execution vulnerabilities in SQL Server — the lowered privilege bar increases practical exploitability. (src: MSRC CVE-2026-54117, MSRC CVE-2026-54118)
- Windows Device Health Attestation RCE — scope clarified (new, informational): Microsoft corrected CVE-2026-71331 and CVE-2026-66802 to clarify they affect Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. No change to severity or exploitability, but defenders should verify DHA components are patched. (src: MSRC CVE-2026-71331, MSRC CVE-2026-66802)
Themes
AI as both sword and shield: Microsoft delayed Exchange SE updates because AI found too many vulnerabilities to triage in time (first reported 2026-08-19), while adversaries continue leveraging AI for exploit generation against Siemens S7 PLCs and malware development (BusySnake). The dual trend of AI-accelerated vuln discovery and AI-assisted offensive tooling is compressing the window between disclosure and exploitation.
