Microsoft disclosed CVE-2026-42902 on June 9, 2026, as an elevation-of-privilege vulnerability in Microsoft PowerToys, placing a beloved Windows power-user utility into the same risk-management queue as drivers, services, shells, and enterprise agents. The important part is not that PowerToys...