Windows Zero-Day Vulnerabilities YellowKey GreenPlasma MiniPlasma | MSSP Advisory

CriticalCredible Report
DateMay 19, 2026
📋Executive Summary
Security researcher Simone Margaritelli disclosed three new Windows zero-day vulnerabilities named YellowKey, GreenPlasma, and MiniPlasma following Microsoft's latest Patch Tuesday. These vulnerabilities add to six total zero-days released by the researcher over six weeks, targeting core Windows functionality that remains unpatched.
⚠️Why It Matters for MSSPs
Your RMM agents and remote access tools run on Windows endpoints that these zero-days can compromise, giving attackers direct access to your entire client base through your management infrastructure. Every client Windows environment you manage sits exposed while Microsoft works through their patch backlog, and your clients expect immediate guidance on protecting systems you have administrative access to.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.