Vendor

Microsoft

As of , 389 Microsoft vulnerabilities are on CISA's list of exploited vulnerabilities, 117 of them used in ransomware campaigns; 40 were added in 2026. Patch first: CVE-2019-1068.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2019-1068Remote Code ExecutionMicrosoft SQL ServerPatch nowForensic triage required by CISA0.57
2CVE-2026-55040Weak AuthenticationMicrosoft SharePointPatch nowForensic triage required by CISA0.70
3CVE-2023-21529Deserialization of Untrusted DataMicrosoft Exchange ServerPatch nowRansomware use, listed within a year0.59
4CVE-2026-58644Deserialization of Untrusted DataMicrosoft SharePointPatch nowForensic triage required by CISA0.16
5CVE-2025-60710Link FollowingMicrosoft WindowsPatch nowRansomware use, listed within a year0.05
6CVE-2026-50522Deserialization of Untrusted DataMicrosoft SharePointPatch nowForensic triage required by CISA0.03
7CVE-2026-45659Deserialization of Untrusted DataMicrosoft SharePoint ServerPatch nowForensic triage required by CISA; ransomware use, listed within a year0.03
8CVE-2026-65660Code InjectionMicrosoft SharePointPatch nowForensic triage required by CISA; listed in the last 14 days0.02
9CVE-2026-56164Missing Authentication for Critical FunctionMicrosoft SharePoint ServerPatch nowForensic triage required by CISA0.01
10CVE-2026-33825Insufficient Granularity of Access ControlMicrosoft DefenderPatch nowRansomware use, listed within a year0.00
11CVE-2008-4250Buffer OverflowMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
12CVE-2010-0249Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry0.92
13CVE-2010-0806Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry0.82
14CVE-2008-0015Video ActiveX Control Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry0.77
15CVE-2010-3962Uninitialized Memory CorruptionMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
16CVE-2013-3918Out-of-Bounds WriteMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry0.74
17CVE-2013-3893Resource Management ErrorsMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.88; verified Exploit-DB entry0.88
18CVE-2012-4792Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry0.79
19CVE-2013-3163Memory CorruptionMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.71; verified Exploit-DB entry0.71
20CVE-2010-2568Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry0.91
21CVE-2012-1889Memory CorruptionMicrosoft XML Core ServicesPatch this weekMetasploit module; EPSS 0.84; verified Exploit-DB entry0.84
22CVE-2012-4969Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.80; verified Exploit-DB entry0.80
23CVE-2013-0074Double DereferenceMicrosoft SilverlightPatch this weekRansomware use; Metasploit module; EPSS 0.79; verified Exploit-DB entry0.79
24CVE-2013-3896Information DisclosureMicrosoft SilverlightPatch this weekMetasploit module; EPSS 0.68; verified Exploit-DB entry0.68
25CVE-2015-0016TS WebProxy Directory TraversalMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry0.76

The next 100, from number 26

Products

  • Windows174 entries
  • Internet Explorer36 entries
  • Office29 entries
  • Win32k25 entries
  • Exchange Server17 entries
  • SharePoint10 entries
  • Defender5 entries
  • SharePoint Server5 entries
  • Open Management Infrastructure (OMI)4 entries
  • Word4 entries
  • .NET Framework3 entries
  • Active Directory3 entries
  • Excel3 entries
  • Silverlight3 entries
  • DirectX Graphics Kernel (DXGKRNL)2 entries
  • Edge2 entries
  • Edge and Internet Explorer2 entries
  • Enhanced Cryptographic Provider2 entries
  • Graphics Device Interface (GDI)2 entries
  • MSHTML2 entries
  • PowerPoint2 entries
  • SMBv12 entries
  • SMBv1 server2 entries
  • SQL Server2 entries
  • XML Core Services2 entries
  • .NET Core and Visual Studio1 entry
  • .NET Framework, SharePoint, Visual Studio1 entry
  • Active Directory Federation Services1 entry
  • Ancillary Function Driver (afd.sys)1 entry
  • ATM Font Driver1 entry
  • Client-Server Run-time Subsystem (CSRSS)1 entry
  • Configuration Manager1 entry
  • DirectX1 entry
  • DWM Core Library1 entry
  • Entra ID1 entry
  • Exchange1 entry
  • Forefront Threat Management Gateway (TMG)1 entry
  • Graphics Component1 entry
  • HTTP Protocol Stack1 entry
  • HTTP.sys1 entry
  • Hyper-V RemoteFX1 entry
  • Input Method Editor (IME) Japanese1 entry
  • Internet Explorer and Edge1 entry
  • Internet Explorer Scripting Engine1 entry
  • Internet Information Services (IIS)1 entry
  • Internet Key Exchange (IKE) Service Extensions1 entry
  • Kerberos Key Distribution Center (KDC)1 entry
  • Malware Protection Engine1 entry
  • Microsoft1 entry
  • MSCOMCTL.OCX1 entry
  • Netlogon1 entry
  • Office and WordPad1 entry
  • Office Outlook1 entry
  • Outlook1 entry
  • Partner Center1 entry
  • Power Pages1 entry
  • Project1 entry
  • Publisher1 entry
  • Remote Desktop Services1 entry
  • Skype for Business1 entry
  • SmartScreen Prompt1 entry
  • SMBv31 entry
  • Streaming Service1 entry
  • Streaming Service Proxy1 entry
  • Task Scheduler1 entry
  • Update Notification Manager1 entry
  • Visual Basic for Applications (VBA)1 entry
  • Windows Ancillary Function Driver for WinSock1 entry
  • Windows CNG Key Isolation Service1 entry
  • Windows COM+ Event System Service1 entry
  • WinVerifyTrust function1 entry
  • WordPad1 entry

Added each year

501001502002021: 838320212022: 16516520222023: 272720232024: 363620242025: 393920252026: 40402026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
202183
2022165
202327
202436
202539
202640

Used in ransomware

Changes CISA made to these entries

  1. CVE-2019-0859 Microsoft Win32kRansomware use: Unknown to Known.
  2. CVE-2016-7255 Microsoft Win32kRansomware use: Unknown to Known.
  3. CVE-2022-37969 Microsoft WindowsRansomware use: Unknown to Known.
  4. CVE-2026-69836 Microsoft Entra IDRemoved from CISA's list.
  5. CVE-2021-43226 Microsoft WindowsRansomware use: Unknown to Known.
  6. CVE-2012-0158 Microsoft MSCOMCTL.OCXRansomware use: Unknown to Known.
  7. CVE-2025-60710 Microsoft WindowsRansomware use: Unknown to Known.
  8. CVE-2022-21882 Microsoft Win32kRansomware use: Unknown to Known.
  9. CVE-2020-0968 Microsoft Internet ExplorerRansomware use: Unknown to Known.
  10. CVE-2020-0618 Microsoft SQL ServerRansomware use: Unknown to Known.

Every change we recorded

Removed from CISA's list

Removed from CISA's list
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-69836Deserialization of Untrusted DataMicrosoft Entra IDRemoved from CISA's list0.02