Microsoft published security updates for a broad set of information disclosure vulnerabilities affecting Windows components including the Windows Kernel, Secure Kernel Mode, Storage Port Driver, Kerberos, File Explorer, Push Notification, and Storage Spaces features. The referenced advisories identify numerous CVEs, including CVE-2025-21319, CVE-2025-21323, CVE-2025-21242, CVE-2025-32722, CVE-2025-49684, CVE-2025-48808, CVE-2025-48809, CVE-2025-48810, CVE-2025-26636, CVE-2025-55683, CVE-2025-59184, CVE-2025-59209, CVE-2026-32217, and CVE-2026-32218, along with earlier related issues such as CVE-2024-49082 and CVE-2022-21877.
The disclosures show a recurring pattern of sensitive data exposure risks in core Windows subsystems, with repeated findings in kernel and storage-related code paths. While the individual entries provide limited public detail, the breadth of affected components indicates that enterprises should prioritize Microsoft security updates for systems running Windows workloads that rely on low-level kernel, storage, authentication, and user-interface services, as these flaws could allow attackers to obtain information that may aid further compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-32215, a Windows Kernel information disclosure vulnerability caused by insertion of sensitive information into a log file. The advisory said a low-privileged local attacker could disclose kernel memory contents, and Microsoft stated a fix was available with no evidence of public disclosure or in-the-wild exploitation.
Microsoft published Security Update Guide entries for CVE-2026-32217 and CVE-2026-32218, both described as Windows Kernel information disclosure vulnerabilities.
Microsoft published a Security Update Guide entry for CVE-2025-59186, a Windows Kernel information disclosure vulnerability. The advisory was released as part of Microsoft's October 2025 security updates.
Microsoft released Security Update Guide entries for CVE-2025-55683, CVE-2025-59184, and CVE-2025-59209, affecting the Windows Kernel, Storage Spaces Direct, and Windows Push Notification components.
Microsoft released Security Update Guide entries for CVE-2025-49684, CVE-2025-48809, CVE-2025-26636, CVE-2025-48810, and CVE-2025-48808, covering Windows Storage Port Driver, Secure Kernel Mode, and Windows Kernel information disclosure flaws.
Microsoft published Security Update Guide entry CVE-2025-32722 for a Windows Storage Port Driver information disclosure vulnerability.
Microsoft published a Security Update Guide entry for CVE-2025-21321, a Windows Kernel Memory information disclosure vulnerability. The advisory was released as part of Microsoft's January 2025 security updates.
Microsoft published a Security Update Guide entry for CVE-2025-21316, a Windows Kernel Memory information disclosure vulnerability. The advisory was released as part of Microsoft's January 2025 security updates.
Microsoft released Security Update Guide entries for CVE-2025-21319, CVE-2025-21323, and CVE-2025-21242, affecting Windows Kernel Memory and Windows Kerberos.
Microsoft published Security Update Guide entry CVE-2024-49082 covering a Windows File Explorer information disclosure vulnerability.
Microsoft released Security Update Guide entry CVE-2022-21877 for a Storage Spaces Controller information disclosure vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
21 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.