1 CVE-2019-1068 Remote Code Execution Microsoft SQL ServerPatch now Forensic triage required by CISA 2026-08-26 2026-08-29 0.57 2026-08-26 · due 2026-08-29 2 CVE-2026-55040 Weak Authentication Microsoft SharePointPatch now Forensic triage required by CISA 2026-08-18 2026-08-21 0.70 2026-08-18 · due 2026-08-21 3 CVE-2023-21529 Deserialization of Untrusted Data Microsoft Exchange ServerPatch now Ransomware use, listed within a year 2026-04-13 2026-04-27 0.59 2026-04-13 · due 2026-04-27 4 CVE-2026-58644 Deserialization of Untrusted Data Microsoft SharePointPatch now Forensic triage required by CISA 2026-07-16 2026-07-19 0.16 2026-07-16 · due 2026-07-19 5 CVE-2025-60710 Link Following Microsoft WindowsPatch now Ransomware use, listed within a year 2026-04-13 2026-04-27 0.05 2026-04-13 · due 2026-04-27 6 CVE-2026-50522 Deserialization of Untrusted Data Microsoft SharePointPatch now Forensic triage required by CISA 2026-07-22 2026-07-25 0.03 2026-07-22 · due 2026-07-25 7 CVE-2026-45659 Deserialization of Untrusted Data Microsoft SharePoint ServerPatch now Forensic triage required by CISA; ransomware use, listed within a year 2026-07-01 2026-07-04 0.03 2026-07-01 · due 2026-07-04 8 CVE-2026-65660 Code Injection Microsoft SharePointPatch now Forensic triage required by CISA; listed in the last 14 days 2026-09-25 2026-09-28 0.02 2026-09-25 · due 2026-09-28 9 CVE-2026-56164 Missing Authentication for Critical Function Microsoft SharePoint ServerPatch now Forensic triage required by CISA 2026-07-14 2026-07-17 0.01 2026-07-14 · due 2026-07-17 10 CVE-2026-33825 Insufficient Granularity of Access Control Microsoft DefenderPatch now Ransomware use, listed within a year 2026-04-22 2026-05-06 0.00 2026-04-22 · due 2026-05-06 11 CVE-2008-4250 Buffer Overflow Microsoft WindowsPatch this week Metasploit module; EPSS 0.99; verified Exploit-DB entry 2026-05-20 2026-06-03 0.99 2026-05-20 · due 2026-06-03 12 CVE-2010-0249 Use-After-Free Microsoft Internet ExplorerPatch this week Metasploit module; EPSS 0.92; verified Exploit-DB entry 2026-05-20 2026-06-03 0.92 2026-05-20 · due 2026-06-03 13 CVE-2010-0806 Use-After-Free Microsoft Internet ExplorerPatch this week Metasploit module; EPSS 0.82; verified Exploit-DB entry 2026-05-20 2026-06-03 0.82 2026-05-20 · due 2026-06-03 14 CVE-2008-0015 Video ActiveX Control Remote Code Execution Microsoft WindowsPatch this week Metasploit module; EPSS 0.77; verified Exploit-DB entry 2026-02-17 2026-03-10 0.77 2026-02-17 · due 2026-03-10 15 CVE-2010-3962 Uninitialized Memory Corruption Microsoft Internet ExplorerPatch this week Metasploit module; EPSS 0.97; verified Exploit-DB entry 2025-10-06 2025-10-27 0.97 2025-10-06 · due 2025-10-27 16 CVE-2013-3918 Out-of-Bounds Write Microsoft WindowsPatch this week Metasploit module; EPSS 0.74; verified Exploit-DB entry 2025-10-06 2025-10-27 0.74 2025-10-06 · due 2025-10-27 17 CVE-2013-3893 Resource Management Errors Microsoft Internet ExplorerPatch this week Metasploit module; EPSS 0.88; verified Exploit-DB entry 2025-08-12 2025-09-02 0.88 2025-08-12 · due 2025-09-02 18 CVE-2012-4792 Use-After-Free Microsoft Internet ExplorerPatch this week Metasploit module; EPSS 0.79; verified Exploit-DB entry 2024-07-23 2024-08-13 0.79 2024-07-23 · due 2024-08-13 19 CVE-2013-3163 Memory Corruption Microsoft Internet ExplorerPatch this week Metasploit module; EPSS 0.71; verified Exploit-DB entry 2023-03-30 2023-04-20 0.71 2023-03-30 · due 2023-04-20 20 CVE-2010-2568 Remote Code Execution Microsoft WindowsPatch this week Metasploit module; EPSS 0.91; verified Exploit-DB entry 2022-09-15 2022-10-06 0.91 2022-09-15 · due 2022-10-06 21 CVE-2012-1889 Memory Corruption Microsoft XML Core ServicesPatch this week Metasploit module; EPSS 0.84; verified Exploit-DB entry 2022-06-08 2022-06-22 0.84 2022-06-08 · due 2022-06-22 22 CVE-2012-4969 Use-After-Free Microsoft Internet ExplorerPatch this week Metasploit module; EPSS 0.80; verified Exploit-DB entry 2022-06-08 2022-06-22 0.80 2022-06-08 · due 2022-06-22 23 CVE-2013-0074 Double Dereference Microsoft SilverlightPatch this week Ransomware use; Metasploit module; EPSS 0.79; verified Exploit-DB entry 2022-05-25 2022-06-15 0.79 2022-05-25 · due 2022-06-15 24 CVE-2013-3896 Information Disclosure Microsoft SilverlightPatch this week Metasploit module; EPSS 0.68; verified Exploit-DB entry 2022-05-25 2022-06-15 0.68 2022-05-25 · due 2022-06-15 25 CVE-2015-0016 TS WebProxy Directory Traversal Microsoft WindowsPatch this week Metasploit module; EPSS 0.76; verified Exploit-DB entry 2022-05-25 2022-06-15 0.76 2022-05-25 · due 2022-06-15