CyberMax
Home › Exploited CVEs › Microsoft

Microsoft Internet Explorer known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 36 Microsoft Internet Explorer CVEs as exploited in the wild. 3 were added in the last 12 months and 6 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 36 Microsoft Internet Explorer CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2010-3962Internet Explorer Uninitialized Memory Corruption96.8%–2025-10-062025-10-27
2CVE-2016-0189Internet Explorer Memory Corruption94.1%Yes2022-03-282022-04-18
3CVE-2010-0249Internet Explorer Use-After-Free91.9%–2026-05-202026-06-03
4CVE-2013-3893Internet Explorer Resource Management Errors87.5%–2025-08-122025-09-02
5CVE-2020-0674Internet Explorer Scripting Engine Memory Corruption86.9%–2021-11-032022-05-03
6CVE-2014-0322Internet Explorer Use-After-Free85.1%–2022-05-042022-05-25
7CVE-2014-1776Internet Explorer Memory Corruption82.7%–2022-01-282022-07-28
8CVE-2010-0806Internet Explorer Use-After-Free82.2%–2026-05-202026-06-03
9CVE-2019-0752Internet Explorer Type Confusion81.6%Yes2022-02-152022-08-15
10CVE-2021-26411Internet Explorer Memory Corruption80.8%Yes2021-11-032021-11-17
11CVE-2012-4969Internet Explorer Use-After-Free80.2%–2022-06-082022-06-22
12CVE-2012-4792Internet Explorer Use-After-Free78.8%–2024-07-232024-08-13
13CVE-2013-1347Internet Explorer Remote Code Execution77.7%–2022-03-032022-03-24
14CVE-2013-3897Internet Explorer Use-After-Free77.3%–2022-03-032022-03-24
15CVE-2019-1429Internet Explorer Scripting Engine Memory Corruption77.3%–2021-11-032022-05-03
16CVE-2013-2551Internet Explorer Use-After-Free73.9%Yes2022-03-282022-04-18
17CVE-2013-3163Internet Explorer Memory Corruption70.7%–2023-03-302023-04-20
18CVE-2017-0059Internet Explorer Information Disclosure62.0%–2022-03-282022-04-18
19CVE-2015-2419Internet Explorer Memory Corruption53.1%–2022-03-282022-04-18
20CVE-2019-1367Internet Explorer Scripting Engine Memory Corruption52.4%Yes2021-11-032022-05-03
21CVE-2015-2502Internet Explorer Memory Corruption51.0%–2022-04-132022-05-04
22CVE-2013-7331Internet Explorer Information Disclosure50.2%–2022-05-252022-06-15
23CVE-2014-4123Internet Explorer Privilege Escalation47.1%–2022-05-252022-06-15
24CVE-2015-2425Internet Explorer Memory Corruption44.7%–2022-05-252022-06-15
25CVE-2015-0071Internet Explorer ASLR Bypass33.6%–2022-05-252022-06-15
26CVE-2016-3298Internet Explorer Messaging API Information Disclosure33.3%–2022-05-242022-06-14
27CVE-2020-0968Internet Explorer Scripting Engine Memory Corruption30.7%Yes2021-11-032022-05-03
28CVE-2017-0222Internet Explorer Remote Code Execution29.6%–2022-02-252022-08-25
29CVE-2018-8653Internet Explorer Scripting Engine Memory Corruption29.6%–2021-11-032022-05-03
30CVE-2017-0149Internet Explorer Memory Corruption29.2%–2022-05-242022-06-14
31CVE-2014-2817Internet Explorer Privilege Escalation26.3%–2022-05-252022-06-15
32CVE-2020-1380Internet Explorer Scripting Engine Memory Corruption24.2%–2021-11-032022-05-03
33CVE-2017-0210Internet Explorer Privilege Escalation22.3%–2022-05-242022-06-14
34CVE-2016-0162Internet Explorer Information Disclosure22.0%–2022-05-242022-06-14
35CVE-2019-0676Internet Explorer Information Disclosure8.1%–2022-05-232022-06-13
36CVE-2021-27085Internet Explorer Remote Code Execution5.4%–2021-11-032021-11-17
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Microsoft KEV CVEs · other Microsoft products: SharePoint · Windows · SharePoint Server · Defender · Office · Exchange Server · Win32k · free KEV badge for Microsoft · all vendors