How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Microsoft (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Microsoft vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2019-1068 | SQL Server | Microsoft SQL Server Remote Code Execution Vulnerability | 2026-08-26 | |
| CVE-2026-33824 | Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | 2026-08-18 | |
| CVE-2026-55040 | SharePoint | Microsoft SharePoint Weak Authentication Vulnerability | 2026-08-18 | |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 2026-08-11 | |
| CVE-2026-50522 | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-22 | |
| CVE-2026-58644 | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-07-16 | |
| CVE-2026-56155 | Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | 2026-07-14 | |
| CVE-2026-56164 | SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | 2026-07-14 | |
| CVE-2026-45659 | SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | 2026-07-01 | ransomware |
| CVE-2008-4250 | Windows | Microsoft Windows Buffer Overflow Vulnerability | 2026-05-20 | |
| CVE-2009-1537 | DirectX | Microsoft DirectX NULL Byte Overwrite Vulnerability | 2026-05-20 | |
| CVE-2010-0249 | Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability | 2026-05-20 | |
| CVE-2010-0806 | Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability | 2026-05-20 | |
| CVE-2026-41091 | Defender | Microsoft Defender Link Following Vulnerability | 2026-05-20 | |
| CVE-2026-45498 | Defender | Microsoft Defender Denial of Service Vulnerability | 2026-05-20 | |
| CVE-2026-42897 | Microsoft | Microsoft Exchange Server Cross-Site Scripting Vulnerability | 2026-05-15 | |
| CVE-2026-32202 | Windows | Microsoft Windows Protection Mechanism Failure Vulnerability | 2026-04-28 | |
| CVE-2026-33825 | Defender | Microsoft Defender Insufficient Granularity of Access Control Vulnerability | 2026-04-22 | ransomware |
| CVE-2009-0238 | Office | Microsoft Office Remote Code Execution | 2026-04-14 | |
| CVE-2026-32201 | SharePoint Server | Microsoft SharePoint Server Improper Input Validation Vulnerability | 2026-04-14 | |
| CVE-2012-1854 | Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | 2026-04-13 | |
| CVE-2025-60710 | Windows | Microsoft Windows Link Following Vulnerability | 2026-04-13 | ransomware |
| CVE-2023-21529 | Exchange Server | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | 2026-04-13 | ransomware |
| CVE-2023-36424 | Windows | Microsoft Windows Out-of-Bounds Read Vulnerability | 2026-04-13 | |
| CVE-2026-20963 | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2026-03-18 | |
| CVE-2008-0015 | Windows | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | 2026-02-17 | |
| CVE-2024-43468 | Configuration Manager | Microsoft Configuration Manager SQL Injection Vulnerability | 2026-02-12 | |
| CVE-2026-21513 | Windows | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | 2026-02-10 | |
| CVE-2026-21525 | Windows | Microsoft Windows NULL Pointer Dereference Vulnerability | 2026-02-10 | |
| CVE-2026-21510 | Windows | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | 2026-02-10 | |
| CVE-2026-21533 | Windows | Microsoft Windows Improper Privilege Management Vulnerability | 2026-02-10 | |
| CVE-2026-21519 | Windows | Microsoft Windows Type Confusion Vulnerability | 2026-02-10 | |
| CVE-2026-21514 | Office | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability | 2026-02-10 | |
| CVE-2026-21509 | Office | Microsoft Office Security Feature Bypass Vulnerability | 2026-01-26 | |
| CVE-2026-20805 | Windows | Microsoft Windows Information Disclosure Vulnerability | 2026-01-13 | |
| CVE-2009-0556 | Office | Microsoft Office PowerPoint Code Injection Vulnerability | 2026-01-07 | |
| CVE-2025-62221 | Windows | Microsoft Windows Use After Free Vulnerability | 2025-12-09 | |
| CVE-2025-62215 | Windows | Microsoft Windows Race Condition Vulnerability | 2025-11-12 | |
| CVE-2025-59287 | Windows | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability | 2025-10-24 | |
| CVE-2025-33073 | Windows | Microsoft Windows SMB Client Improper Access Control Vulnerability | 2025-10-20 | |
| CVE-2025-24990 | Windows | Microsoft Windows Untrusted Pointer Dereference Vulnerability | 2025-10-14 | |
| CVE-2025-59230 | Windows | Microsoft Windows Improper Access Control Vulnerability | 2025-10-14 | |
| CVE-2010-3962 | Internet Explorer | Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability | 2025-10-06 | |
| CVE-2021-43226 | Windows | Microsoft Windows Privilege Escalation Vulnerability | 2025-10-06 | ransomware |
| CVE-2013-3918 | Windows | Microsoft Windows Out-of-Bounds Write Vulnerability | 2025-10-06 | |
| CVE-2011-3402 | Windows | Microsoft Windows Remote Code Execution Vulnerability | 2025-10-06 | |
| CVE-2007-0671 | Office | Microsoft Office Excel Remote Code Execution Vulnerability | 2025-08-12 | |
| CVE-2013-3893 | Internet Explorer | Microsoft Internet Explorer Resource Management Errors Vulnerability | 2025-08-12 | |
| CVE-2025-49704 | SharePoint | Microsoft SharePoint Code Injection Vulnerability | 2025-07-22 | ransomware |
| CVE-2025-49706 | SharePoint | Microsoft SharePoint Improper Authentication Vulnerability | 2025-07-22 | ransomware |
| CVE-2025-53770 | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 2025-07-20 | ransomware |
| CVE-2025-33053 | Windows | Microsoft Windows External Control of File Name or Path Vulnerability | 2025-06-10 | |
| CVE-2025-32709 | Windows | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | 2025-05-13 | |
| CVE-2025-30397 | Windows | Microsoft Windows Scripting Engine Type Confusion Vulnerability | 2025-05-13 | |
| CVE-2025-32706 | Windows | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | 2025-05-13 | |
| CVE-2025-32701 | Windows | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | 2025-05-13 | |
| CVE-2025-30400 | Windows | Microsoft Windows DWM Core Library Use-After-Free Vulnerability | 2025-05-13 | |
| CVE-2025-24054 | Windows | Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability | 2025-04-17 | |
| CVE-2025-29824 | Windows | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | 2025-04-08 | ransomware |
| CVE-2025-24993 | Windows | Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability | 2025-03-11 |
Showing the 60 most recent of 386 Microsoft KEV entries. Full catalog at CISA.
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.