TODAY'S critical alert highlights four active exploits detected, including two high-severity vulnerabilities in BeyondTrust’s Endpoint Privilege Management for Windows. These are identified as CVE-2026-40144 and CVE-2026-40145, both allowing for local privilege escalation. The highest severity score is 7.3, and although there is currently no confirmed exploitation, patches for both vulnerabilities are available in version 26.1.2.
The CVE details include: CVE-2026-40144 with a focus on memory corruption, and CVE-2026-40145 involving a control protections bypass. Users are urged to update their systems to mitigate risks.