Vendor Exploitation Record

Microsoft — Known Exploited Vulnerabilities

386 in CISA KEV · 114 ransomware-linked · as of 2026-08-31
In CISA KEV386 confirmed exploited
Ransomware-linked114 (30% of KEV, per CISA)
First KEV addition2021-11-03
Most recent2026-08-26

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Microsoft (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited Microsoft vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2019-1068SQL ServerMicrosoft SQL Server Remote Code Execution Vulnerability2026-08-26
CVE-2026-33824Internet Key Exchange (IKE) Service ExtensionsMicrosoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability2026-08-18
CVE-2026-55040SharePointMicrosoft SharePoint Weak Authentication Vulnerability2026-08-18
CVE-2026-68820Windows Ancillary Function Driver for WinSock Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability2026-08-11
CVE-2026-50522SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability 2026-07-22
CVE-2026-58644SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability2026-07-16
CVE-2026-56155Active Directory Federation ServicesMicrosoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability 2026-07-14
CVE-2026-56164SharePoint ServerMicrosoft SharePoint Server Missing Authentication for Critical Function Vulnerability2026-07-14
CVE-2026-45659SharePoint ServerMicrosoft SharePoint Server Deserialization of Untrusted Data Vulnerability2026-07-01ransomware
CVE-2008-4250WindowsMicrosoft Windows Buffer Overflow Vulnerability2026-05-20
CVE-2009-1537DirectXMicrosoft DirectX NULL Byte Overwrite Vulnerability2026-05-20
CVE-2010-0249Internet ExplorerMicrosoft Internet Explorer Use-After-Free Vulnerability2026-05-20
CVE-2010-0806Internet ExplorerMicrosoft Internet Explorer Use-After-Free Vulnerability2026-05-20
CVE-2026-41091DefenderMicrosoft Defender Link Following Vulnerability2026-05-20
CVE-2026-45498DefenderMicrosoft Defender Denial of Service Vulnerability2026-05-20
CVE-2026-42897MicrosoftMicrosoft Exchange Server Cross-Site Scripting Vulnerability2026-05-15
CVE-2026-32202WindowsMicrosoft Windows Protection Mechanism Failure Vulnerability2026-04-28
CVE-2026-33825DefenderMicrosoft Defender Insufficient Granularity of Access Control Vulnerability2026-04-22ransomware
CVE-2009-0238OfficeMicrosoft Office Remote Code Execution2026-04-14
CVE-2026-32201SharePoint ServerMicrosoft SharePoint Server Improper Input Validation Vulnerability2026-04-14
CVE-2012-1854Visual Basic for Applications (VBA)Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability2026-04-13
CVE-2025-60710WindowsMicrosoft Windows Link Following Vulnerability2026-04-13ransomware
CVE-2023-21529Exchange ServerMicrosoft Exchange Server Deserialization of Untrusted Data Vulnerability2026-04-13ransomware
CVE-2023-36424WindowsMicrosoft Windows Out-of-Bounds Read Vulnerability2026-04-13
CVE-2026-20963SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability2026-03-18
CVE-2008-0015Windows Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability2026-02-17
CVE-2024-43468Configuration ManagerMicrosoft Configuration Manager SQL Injection Vulnerability2026-02-12
CVE-2026-21513WindowsMicrosoft MSHTML Framework Protection Mechanism Failure Vulnerability2026-02-10
CVE-2026-21525WindowsMicrosoft Windows NULL Pointer Dereference Vulnerability2026-02-10
CVE-2026-21510WindowsMicrosoft Windows Shell Protection Mechanism Failure Vulnerability2026-02-10
CVE-2026-21533WindowsMicrosoft Windows Improper Privilege Management Vulnerability2026-02-10
CVE-2026-21519WindowsMicrosoft Windows Type Confusion Vulnerability2026-02-10
CVE-2026-21514OfficeMicrosoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability2026-02-10
CVE-2026-21509OfficeMicrosoft Office Security Feature Bypass Vulnerability2026-01-26
CVE-2026-20805WindowsMicrosoft Windows Information Disclosure Vulnerability2026-01-13
CVE-2009-0556OfficeMicrosoft Office PowerPoint Code Injection Vulnerability2026-01-07
CVE-2025-62221WindowsMicrosoft Windows Use After Free Vulnerability2025-12-09
CVE-2025-62215WindowsMicrosoft Windows Race Condition Vulnerability2025-11-12
CVE-2025-59287WindowsMicrosoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability2025-10-24
CVE-2025-33073WindowsMicrosoft Windows SMB Client Improper Access Control Vulnerability2025-10-20
CVE-2025-24990WindowsMicrosoft Windows Untrusted Pointer Dereference Vulnerability2025-10-14
CVE-2025-59230WindowsMicrosoft Windows Improper Access Control Vulnerability2025-10-14
CVE-2010-3962Internet ExplorerMicrosoft Internet Explorer Uninitialized Memory Corruption Vulnerability2025-10-06
CVE-2021-43226WindowsMicrosoft Windows Privilege Escalation Vulnerability2025-10-06ransomware
CVE-2013-3918WindowsMicrosoft Windows Out-of-Bounds Write Vulnerability2025-10-06
CVE-2011-3402WindowsMicrosoft Windows Remote Code Execution Vulnerability2025-10-06
CVE-2007-0671OfficeMicrosoft Office Excel Remote Code Execution Vulnerability2025-08-12
CVE-2013-3893Internet ExplorerMicrosoft Internet Explorer Resource Management Errors Vulnerability2025-08-12
CVE-2025-49704SharePointMicrosoft SharePoint Code Injection Vulnerability2025-07-22ransomware
CVE-2025-49706SharePointMicrosoft SharePoint Improper Authentication Vulnerability2025-07-22ransomware
CVE-2025-53770SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability2025-07-20ransomware
CVE-2025-33053Windows Microsoft Windows External Control of File Name or Path Vulnerability2025-06-10
CVE-2025-32709WindowsMicrosoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability2025-05-13
CVE-2025-30397WindowsMicrosoft Windows Scripting Engine Type Confusion Vulnerability2025-05-13
CVE-2025-32706WindowsMicrosoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability2025-05-13
CVE-2025-32701WindowsMicrosoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability2025-05-13
CVE-2025-30400WindowsMicrosoft Windows DWM Core Library Use-After-Free Vulnerability2025-05-13
CVE-2025-24054WindowsMicrosoft Windows NTLM Hash Disclosure Spoofing Vulnerability2025-04-17
CVE-2025-29824WindowsMicrosoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability2025-04-08ransomware
CVE-2025-24993WindowsMicrosoft Windows NTFS Heap-Based Buffer Overflow Vulnerability2025-03-11

Showing the 60 most recent of 386 Microsoft KEV entries. Full catalog at CISA.

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.