CyberMax
Home › Exploited CVEs

Microsoft known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 389 Microsoft CVEs as exploited in the wild. 49 were added in the last 12 months (latest 2026-09-25), and 117 are known to be used in ransomware campaigns.

Microsoft CVEs added to CISA KEV per year
2021: 832021832022: 16520221652023: 272023272024: 362024362025: 392025392026: 39202639

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Microsoft products

Windows (172), Internet Explorer (36), Office (29), Win32k (25), Exchange Server (17), SharePoint (10), SharePoint Server (5), Defender (5), Word (4), Open Management Infrastructure (OMI) (4), .NET Framework (3), Active Directory (3).

All Microsoft CVEs in KEV (latest 60)

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-65660SharePointSharePoint Code Injection2026-09-252026-09-282.1%–
CVE-2026-85880WindowsWindows Heap-Based Buffer Overflow2026-09-082026-09-223.6%–
CVE-2026-81963WindowsWindows Link Following2026-09-082026-09-220.4%–
CVE-2019-1068SQL ServerSQL Server Remote Code Execution2026-08-262026-08-2957.9%–
CVE-2026-55040SharePointSharePoint Weak Authentication2026-08-182026-08-2117.5%–
CVE-2026-33824Internet Key Exchange (IKE) Service ExtensionsInternet Key Exchange (IKE) Service Extensions Double Free2026-08-182026-08-211.6%–
CVE-2026-68820Windows Ancillary Function Driver for WinSock Windows Ancillary Function Driver for WinSock Use-After-Free2026-08-112026-08-250.3%–
CVE-2026-50522SharePointSharePoint Deserialization of Untrusted Data2026-07-222026-07-253.0%–
CVE-2026-58644SharePointSharePoint Deserialization of Untrusted Data2026-07-162026-07-1915.9%–
CVE-2026-56164SharePoint ServerSharePoint Server Missing Authentication for Critical Function2026-07-142026-07-171.0%–
CVE-2026-56155Active Directory Federation ServicesActive Directory Federation Services Insufficient Granularity of Access Control2026-07-142026-07-280.3%–
CVE-2026-45659SharePoint ServerSharePoint Server Deserialization of Untrusted Data2026-07-012026-07-042.7%Yes
CVE-2026-45498DefenderDefender Denial of Service2026-05-202026-06-031.3%–
CVE-2026-41091DefenderDefender Link Following2026-05-202026-06-030.4%–
CVE-2010-0806Internet ExplorerInternet Explorer Use-After-Free2026-05-202026-06-0382.2%–
CVE-2010-0249Internet ExplorerInternet Explorer Use-After-Free2026-05-202026-06-0391.9%–
CVE-2009-1537DirectXDirectX NULL Byte Overwrite2026-05-202026-06-0351.2%–
CVE-2008-4250WindowsWindows Buffer Overflow2026-05-202026-06-0398.8%–
CVE-2026-42897MicrosoftExchange Server Cross-Site Scripting2026-05-152026-05-290.5%–
CVE-2026-32202WindowsWindows Protection Mechanism Failure2026-04-282026-05-124.9%–
CVE-2026-33825DefenderDefender Insufficient Granularity of Access Control2026-04-222026-05-060.4%Yes
CVE-2026-32201SharePoint ServerSharePoint Server Improper Input Validation2026-04-142026-04-281.0%–
CVE-2009-0238OfficeOffice Remote Code Execution2026-04-142026-04-2843.2%–
CVE-2025-60710WindowsWindows Link Following2026-04-132026-04-274.6%Yes
CVE-2023-36424WindowsWindows Out-of-Bounds Read2026-04-132026-04-2712.2%–
CVE-2023-21529Exchange ServerExchange Server Deserialization of Untrusted Data2026-04-132026-04-2759.3%Yes
CVE-2012-1854Visual Basic for Applications (VBA)Visual Basic for Applications Insecure Library Loading2026-04-132026-04-2721.0%–
CVE-2026-20963SharePointSharePoint Deserialization of Untrusted Data2026-03-182026-03-2129.6%–
CVE-2008-0015WindowsWindows Video ActiveX Control Remote Code Execution2026-02-172026-03-1076.7%–
CVE-2024-43468Configuration ManagerConfiguration Manager SQL Injection2026-02-122026-03-0580.9%–
CVE-2026-21533WindowsWindows Improper Privilege Management2026-02-102026-03-034.1%–
CVE-2026-21525WindowsWindows NULL Pointer Dereference2026-02-102026-03-034.8%–
CVE-2026-21519WindowsWindows Type Confusion2026-02-102026-03-032.5%–
CVE-2026-21514OfficeOffice Word Reliance on Untrusted Inputs in a Security Decision2026-02-102026-03-031.5%–
CVE-2026-21513WindowsMSHTML Framework Protection Mechanism Failure2026-02-102026-03-0315.6%–
CVE-2026-21510WindowsWindows Shell Protection Mechanism Failure2026-02-102026-03-0324.2%–
CVE-2026-21509OfficeOffice Security Feature Bypass2026-01-262026-02-1670.8%–
CVE-2026-20805WindowsWindows Information Disclosure2026-01-132026-02-037.2%–
CVE-2009-0556OfficeOffice PowerPoint Code Injection2026-01-072026-01-2867.3%–
CVE-2025-62221WindowsWindows Use After Free2025-12-092025-12-302.5%–
CVE-2025-62215WindowsWindows Race Condition2025-11-122025-12-036.0%–
CVE-2025-59287WindowsWindows Server Update Service (WSUS) Deserialization of Untrusted Data2025-10-242025-11-14100.0%–
CVE-2025-33073WindowsWindows SMB Client Improper Access Control2025-10-202025-11-1082.7%–
CVE-2025-59230WindowsWindows Improper Access Control2025-10-142025-11-042.7%–
CVE-2025-24990WindowsWindows Untrusted Pointer Dereference2025-10-142025-11-046.4%–
CVE-2021-43226WindowsWindows Privilege Escalation2025-10-062025-10-273.1%Yes
CVE-2013-3918WindowsWindows Out-of-Bounds Write2025-10-062025-10-2773.7%–
CVE-2011-3402WindowsWindows Remote Code Execution2025-10-062025-10-2778.1%–
CVE-2010-3962Internet ExplorerInternet Explorer Uninitialized Memory Corruption2025-10-062025-10-2796.8%–
CVE-2013-3893Internet ExplorerInternet Explorer Resource Management Errors2025-08-122025-09-0287.5%–
CVE-2007-0671OfficeOffice Excel Remote Code Execution2025-08-122025-09-0243.2%–
CVE-2025-49706SharePointSharePoint Improper Authentication2025-07-222025-07-2399.1%Yes
CVE-2025-49704SharePointSharePoint Code Injection2025-07-222025-07-23100.0%Yes
CVE-2025-53770SharePointSharePoint Deserialization of Untrusted Data2025-07-202025-07-21100.0%Yes
CVE-2025-33053WindowsWindows External Control of File Name or Path2025-06-102025-07-0187.0%–
CVE-2025-32709WindowsWindows Ancillary Function Driver for WinSock Use-After-Free2025-05-132025-06-032.1%–
CVE-2025-32706WindowsWindows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow2025-05-132025-06-032.3%–
CVE-2025-32701WindowsWindows Common Log File System (CLFS) Driver Use-After-Free2025-05-132025-06-031.4%–
CVE-2025-30400WindowsWindows DWM Core Library Use-After-Free2025-05-132025-06-031.9%–
CVE-2025-30397WindowsWindows Scripting Engine Type Confusion2025-05-132025-06-0326.8%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors