Microsoft known exploited vulnerabilities
CISA lists 389 Microsoft CVEs as exploited in the wild. 49 were added in the last 12 months (latest 2026-09-25), and 117 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2015-1635 (HTTP.sys): EPSS 100.0%, added 2022-02-10
- CVE-2021-34473 (Exchange Server): EPSS 100.0%, added 2021-11-03
- CVE-2019-0708 (Remote Desktop Services): EPSS 100.0%, added 2021-11-03
- CVE-2025-53770 (SharePoint): EPSS 100.0%, added 2025-07-20
- CVE-2021-26855 (Exchange Server): EPSS 100.0%, added 2021-11-03
Most affected Microsoft products
Windows (172), Internet Explorer (36), Office (29), Win32k (25), Exchange Server (17), SharePoint (10), SharePoint Server (5), Defender (5), Word (4), Open Management Infrastructure (OMI) (4), .NET Framework (3), Active Directory (3).
All Microsoft CVEs in KEV (latest 60)
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-65660 | SharePoint | SharePoint Code Injection | 2026-09-25 | 2026-09-28 | 2.1% | – |
| CVE-2026-85880 | Windows | Windows Heap-Based Buffer Overflow | 2026-09-08 | 2026-09-22 | 3.6% | – |
| CVE-2026-81963 | Windows | Windows Link Following | 2026-09-08 | 2026-09-22 | 0.4% | – |
| CVE-2019-1068 | SQL Server | SQL Server Remote Code Execution | 2026-08-26 | 2026-08-29 | 57.9% | – |
| CVE-2026-55040 | SharePoint | SharePoint Weak Authentication | 2026-08-18 | 2026-08-21 | 17.5% | – |
| CVE-2026-33824 | Internet Key Exchange (IKE) Service Extensions | Internet Key Exchange (IKE) Service Extensions Double Free | 2026-08-18 | 2026-08-21 | 1.6% | – |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Use-After-Free | 2026-08-11 | 2026-08-25 | 0.3% | – |
| CVE-2026-50522 | SharePoint | SharePoint Deserialization of Untrusted Data | 2026-07-22 | 2026-07-25 | 3.0% | – |
| CVE-2026-58644 | SharePoint | SharePoint Deserialization of Untrusted Data | 2026-07-16 | 2026-07-19 | 15.9% | – |
| CVE-2026-56164 | SharePoint Server | SharePoint Server Missing Authentication for Critical Function | 2026-07-14 | 2026-07-17 | 1.0% | – |
| CVE-2026-56155 | Active Directory Federation Services | Active Directory Federation Services Insufficient Granularity of Access Control | 2026-07-14 | 2026-07-28 | 0.3% | – |
| CVE-2026-45659 | SharePoint Server | SharePoint Server Deserialization of Untrusted Data | 2026-07-01 | 2026-07-04 | 2.7% | Yes |
| CVE-2026-45498 | Defender | Defender Denial of Service | 2026-05-20 | 2026-06-03 | 1.3% | – |
| CVE-2026-41091 | Defender | Defender Link Following | 2026-05-20 | 2026-06-03 | 0.4% | – |
| CVE-2010-0806 | Internet Explorer | Internet Explorer Use-After-Free | 2026-05-20 | 2026-06-03 | 82.2% | – |
| CVE-2010-0249 | Internet Explorer | Internet Explorer Use-After-Free | 2026-05-20 | 2026-06-03 | 91.9% | – |
| CVE-2009-1537 | DirectX | DirectX NULL Byte Overwrite | 2026-05-20 | 2026-06-03 | 51.2% | – |
| CVE-2008-4250 | Windows | Windows Buffer Overflow | 2026-05-20 | 2026-06-03 | 98.8% | – |
| CVE-2026-42897 | Microsoft | Exchange Server Cross-Site Scripting | 2026-05-15 | 2026-05-29 | 0.5% | – |
| CVE-2026-32202 | Windows | Windows Protection Mechanism Failure | 2026-04-28 | 2026-05-12 | 4.9% | – |
| CVE-2026-33825 | Defender | Defender Insufficient Granularity of Access Control | 2026-04-22 | 2026-05-06 | 0.4% | Yes |
| CVE-2026-32201 | SharePoint Server | SharePoint Server Improper Input Validation | 2026-04-14 | 2026-04-28 | 1.0% | – |
| CVE-2009-0238 | Office | Office Remote Code Execution | 2026-04-14 | 2026-04-28 | 43.2% | – |
| CVE-2025-60710 | Windows | Windows Link Following | 2026-04-13 | 2026-04-27 | 4.6% | Yes |
| CVE-2023-36424 | Windows | Windows Out-of-Bounds Read | 2026-04-13 | 2026-04-27 | 12.2% | – |
| CVE-2023-21529 | Exchange Server | Exchange Server Deserialization of Untrusted Data | 2026-04-13 | 2026-04-27 | 59.3% | Yes |
| CVE-2012-1854 | Visual Basic for Applications (VBA) | Visual Basic for Applications Insecure Library Loading | 2026-04-13 | 2026-04-27 | 21.0% | – |
| CVE-2026-20963 | SharePoint | SharePoint Deserialization of Untrusted Data | 2026-03-18 | 2026-03-21 | 29.6% | – |
| CVE-2008-0015 | Windows | Windows Video ActiveX Control Remote Code Execution | 2026-02-17 | 2026-03-10 | 76.7% | – |
| CVE-2024-43468 | Configuration Manager | Configuration Manager SQL Injection | 2026-02-12 | 2026-03-05 | 80.9% | – |
| CVE-2026-21533 | Windows | Windows Improper Privilege Management | 2026-02-10 | 2026-03-03 | 4.1% | – |
| CVE-2026-21525 | Windows | Windows NULL Pointer Dereference | 2026-02-10 | 2026-03-03 | 4.8% | – |
| CVE-2026-21519 | Windows | Windows Type Confusion | 2026-02-10 | 2026-03-03 | 2.5% | – |
| CVE-2026-21514 | Office | Office Word Reliance on Untrusted Inputs in a Security Decision | 2026-02-10 | 2026-03-03 | 1.5% | – |
| CVE-2026-21513 | Windows | MSHTML Framework Protection Mechanism Failure | 2026-02-10 | 2026-03-03 | 15.6% | – |
| CVE-2026-21510 | Windows | Windows Shell Protection Mechanism Failure | 2026-02-10 | 2026-03-03 | 24.2% | – |
| CVE-2026-21509 | Office | Office Security Feature Bypass | 2026-01-26 | 2026-02-16 | 70.8% | – |
| CVE-2026-20805 | Windows | Windows Information Disclosure | 2026-01-13 | 2026-02-03 | 7.2% | – |
| CVE-2009-0556 | Office | Office PowerPoint Code Injection | 2026-01-07 | 2026-01-28 | 67.3% | – |
| CVE-2025-62221 | Windows | Windows Use After Free | 2025-12-09 | 2025-12-30 | 2.5% | – |
| CVE-2025-62215 | Windows | Windows Race Condition | 2025-11-12 | 2025-12-03 | 6.0% | – |
| CVE-2025-59287 | Windows | Windows Server Update Service (WSUS) Deserialization of Untrusted Data | 2025-10-24 | 2025-11-14 | 100.0% | – |
| CVE-2025-33073 | Windows | Windows SMB Client Improper Access Control | 2025-10-20 | 2025-11-10 | 82.7% | – |
| CVE-2025-59230 | Windows | Windows Improper Access Control | 2025-10-14 | 2025-11-04 | 2.7% | – |
| CVE-2025-24990 | Windows | Windows Untrusted Pointer Dereference | 2025-10-14 | 2025-11-04 | 6.4% | – |
| CVE-2021-43226 | Windows | Windows Privilege Escalation | 2025-10-06 | 2025-10-27 | 3.1% | Yes |
| CVE-2013-3918 | Windows | Windows Out-of-Bounds Write | 2025-10-06 | 2025-10-27 | 73.7% | – |
| CVE-2011-3402 | Windows | Windows Remote Code Execution | 2025-10-06 | 2025-10-27 | 78.1% | – |
| CVE-2010-3962 | Internet Explorer | Internet Explorer Uninitialized Memory Corruption | 2025-10-06 | 2025-10-27 | 96.8% | – |
| CVE-2013-3893 | Internet Explorer | Internet Explorer Resource Management Errors | 2025-08-12 | 2025-09-02 | 87.5% | – |
| CVE-2007-0671 | Office | Office Excel Remote Code Execution | 2025-08-12 | 2025-09-02 | 43.2% | – |
| CVE-2025-49706 | SharePoint | SharePoint Improper Authentication | 2025-07-22 | 2025-07-23 | 99.1% | Yes |
| CVE-2025-49704 | SharePoint | SharePoint Code Injection | 2025-07-22 | 2025-07-23 | 100.0% | Yes |
| CVE-2025-53770 | SharePoint | SharePoint Deserialization of Untrusted Data | 2025-07-20 | 2025-07-21 | 100.0% | Yes |
| CVE-2025-33053 | Windows | Windows External Control of File Name or Path | 2025-06-10 | 2025-07-01 | 87.0% | – |
| CVE-2025-32709 | Windows | Windows Ancillary Function Driver for WinSock Use-After-Free | 2025-05-13 | 2025-06-03 | 2.1% | – |
| CVE-2025-32706 | Windows | Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow | 2025-05-13 | 2025-06-03 | 2.3% | – |
| CVE-2025-32701 | Windows | Windows Common Log File System (CLFS) Driver Use-After-Free | 2025-05-13 | 2025-06-03 | 1.4% | – |
| CVE-2025-30400 | Windows | Windows DWM Core Library Use-After-Free | 2025-05-13 | 2025-06-03 | 1.9% | – |
| CVE-2025-30397 | Windows | Windows Scripting Engine Type Confusion | 2025-05-13 | 2025-06-03 | 26.8% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors