CISA's list that day
20 May 2026
On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Microsoft DirectX, Adobe Acrobat and Reader and 2 other products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2008-4250Buffer Overflow | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2009-3459Heap-Based Buffer Overflow | Adobe Acrobat and Reader | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| CVE-2010-0249Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| CVE-2010-0806Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| CVE-2009-1537NULL Byte Overwrite | Microsoft DirectX | Patch this weekEPSS 0.51 | 0.51 | ||
| CVE-2026-45498Denial of Service | Microsoft Defender | Patch soon | 0.01 | ||
| CVE-2026-41091Link Following | Microsoft Defender | Patch soon | 0.00 |