CISA's list that day

20 May 2026

On CISA added 7 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows, Microsoft DirectX, Adobe Acrobat and Reader and 2 other products. US federal agencies must fix them by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2008-4250Buffer OverflowMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
CVE-2009-3459Heap-Based Buffer OverflowAdobe Acrobat and ReaderPatch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
CVE-2010-0249Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry0.92
CVE-2010-0806Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry0.82
CVE-2009-1537NULL Byte OverwriteMicrosoft DirectXPatch this weekEPSS 0.510.51
CVE-2026-45498Denial of ServiceMicrosoft DefenderPatch soon0.01
CVE-2026-41091Link FollowingMicrosoft DefenderPatch soon0.00