
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning for U.S. federal civilian agencies, urging them to address four significant Microsoft vulnerabilities by the end of the month. These flaws, recently publicised, are actively exploited by hackers and impact essential Microsoft products.
The vulnerabilities in question are CVE-2024-38226, CVE-2024-43491, CVE-2024-38014, and CVE-2024-38217, which are part of the 79 vulnerabilities included in Microsoft’s latest security release. Randy Watkins, CTO at Critical Start, emphasised the urgency of these updates, particularly for sectors like healthcare, finance, and government. "Failure to patch these vulnerabilities could result in severe data breaches and operational disruptions," Watkins warned.
CVE-2024-43491, given a severity score of 9.8 out of 10 by Microsoft, initially appeared to be the most severe. However, it only affects a specific version of Windows 10 released in July 2015, with later versions not impacted. Despite this, CVE-2024-38226, which affects Microsoft Publisher, and CVE-2024-38014, involving Windows Installer, are of significant concern. Both vulnerabilities can be exploited as part of a multi-stage attack chain, potentially allowing attackers to gain extensive control over systems.
The fourth vulnerability, CVE-2024-38217, impacts Windows Mark of the Web, a tool designed to flag potentially unsafe files downloaded from the internet. Hackers have targeted this feature, exploiting it to bypass security warnings—a tactic linked to previous ransomware attacks.
As security experts note the availability of exploit code on platforms like GitHub, organisations are advised to act swiftly to mitigate these risks. Alongside Microsoft’s updates, several other companies, including Ivanti, Cisco, and Adobe, have also addressed severe bugs in their latest security patches.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543