Summary
March 2026 brought no confirmed active exploitations, but Ryan Braunstein and Henry Smith point to the medium-severity bugs as the real danger. Ryan covers a Push Message Routing Service memory leak (CVE-2026-24282) that scrapes session tokens from heap memory, and a GDI+ pair that chains to defeat ASLR and land remote code execution. Henry covers an accessibility infrastructure flaw in ATBroker.exe that jumps an attacker straight to SYSTEM, plus an SMB authentication bypass (CVE-2026-24294) that Microsoft flagged as exploitation more likely. The hosts agree on the advice: patch the mediums, and audit the trusted services nobody puts on a hardening checklist.
)
)
)
)
)
)
)