Vendor
Microsoft, page 5
As of , 389 Microsoft vulnerabilities are on CISA's list of exploited vulnerabilities, 117 of them used in ransomware campaigns; 40 were added in 2026. Patch first: CVE-2019-1068.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 326 | CVE-2024-38106Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.06 | ||
| 327 | CVE-2021-27059Remote Code Execution | Microsoft Office | Patch soon | 0.06 | ||
| 328 | CVE-2021-33739Desktop Window Manager (DWM) Core Library Privilege Escalation | Microsoft Windows | Patch soon | 0.07 | ||
| 329 | CVE-2023-21823Graphic Component Privilege Escalation | Microsoft Windows | Patch soon | 0.06 | ||
| 330 | CVE-2015-6175Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 331 | CVE-2019-0863Error Reporting (WER) Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 332 | CVE-2020-17087Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 333 | CVE-2021-27085Remote Code Execution | Microsoft Internet Explorer | Patch soon | 0.05 | ||
| 334 | CVE-2026-32202Protection Mechanism Failure | Microsoft Windows | Patch soon | 0.05 | ||
| 335 | CVE-2026-21525NULL Pointer Dereference | Microsoft Windows | Patch soon | 0.05 | ||
| 336 | CVE-2020-1027Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 337 | CVE-2009-1123Improper Input Validation | Microsoft Windows | Patch soon | 0.05 | ||
| 338 | CVE-2021-31979Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.05 | ||
| 339 | CVE-2026-21533Improper Privilege Management | Microsoft Windows | Patch soon | 0.04 | ||
| 340 | CVE-2025-24985Fast FAT File System Driver Integer Overflow | Microsoft Windows | Patch soon | 0.04 | ||
| 341 | CVE-2024-30040MSHTML Platform Security Feature Bypass | Microsoft Windows | Patch soon | 0.04 | ||
| 342 | CVE-2023-32049Defender SmartScreen Security Feature Bypass | Microsoft Windows | Patch soon | 0.04 | ||
| 343 | CVE-2015-1769Mount Manager Privilege Escalation | Microsoft Windows | Patch soon | 0.04 | ||
| 344 | CVE-2018-8611Kernel Privilege Escalation | Microsoft Windows | Patch soon | 0.04 | ||
| 345 | CVE-2026-85880Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.04 | ||
| 346 | CVE-2023-36584Mark of the Web (MOTW) Security Feature Bypass | Microsoft Windows | Patch soon | 0.03 | ||
| 347 | CVE-2022-41125CNG Key Isolation Service Privilege Escalation | Microsoft Windows | Patch soon | 0.03 | ||
| 348 | CVE-2018-8589Privilege Escalation | Microsoft Win32k | Patch soon | 0.03 | ||
| 349 | CVE-2017-0001Privilege Escalation | Microsoft Graphics Device Interface (GDI) | Patch soon | 0.03 | ||
| 350 | CVE-2021-31199Privilege Escalation | Microsoft Enhanced Cryptographic Provider | Patch soon | 0.03 | ||
| 351 | CVE-2021-38649Privilege Escalation | Microsoft Open Management Infrastructure (OMI) | Patch soon | 0.03 | ||
| 352 | CVE-2025-59230Improper Access Control | Microsoft Windows | Patch soon | 0.03 | ||
| 353 | CVE-2024-38226Protection Mechanism Failure | Microsoft Publisher | Patch soon | 0.03 | ||
| 354 | CVE-2021-38645Privilege Escalation | Microsoft Open Management Infrastructure (OMI) | Patch soon | 0.03 | ||
| 355 | CVE-2025-62221Use After Free | Microsoft Windows | Patch soon | 0.03 | ||
| 356 | CVE-2022-41049Mark of the Web (MOTW) Security Feature Bypass | Microsoft Windows | Patch soon | 0.02 | ||
| 357 | CVE-2021-31201Privilege Escalation | Microsoft Enhanced Cryptographic Provider | Patch soon | 0.03 | ||
| 358 | CVE-2026-21519Type Confusion | Microsoft Windows | Patch soon | 0.02 | ||
| 359 | CVE-2022-21919User Profile Service Privilege Escalation | Microsoft Windows | Patch soon | 0.02 | ||
| 360 | CVE-2025-32706Common Log File System (CLFS) Driver Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| 361 | CVE-2025-24993NTFS Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| 362 | CVE-2025-21391Storage Link Following | Microsoft Windows | Patch soon | 0.02 | ||
| 363 | CVE-2019-0880Privilege Escalation | Microsoft Windows | Patch soon | 0.02 | ||
| 364 | CVE-2025-32709Ancillary Function Driver for WinSock Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| 365 | CVE-2025-24984NTFS Information Disclosure | Microsoft Windows | Patch soon | 0.02 | ||
| 366 | CVE-2025-24991NTFS Out-Of-Bounds Read | Microsoft Windows | Patch soon | 0.02 | ||
| 367 | CVE-2025-30400DWM Core Library Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| 368 | CVE-2019-0797Privilege Escalation | Microsoft Win32k | Patch soon | 0.02 | ||
| 369 | CVE-2023-28229Privilege Escalation | Microsoft Windows CNG Key Isolation Service | Patch soon | 0.02 | ||
| 370 | CVE-2022-41033Privilege Escalation | Microsoft Windows COM+ Event System Service | Patch soon | 0.02 | ||
| 371 | CVE-2026-33824Double Free | Microsoft Internet Key Exchange (IKE) Service Extensions | Patch soon | 0.02 | ||
| 372 | CVE-2025-24989Improper Access Control | Microsoft Power Pages | Patch soon | 0.02 | ||
| 373 | CVE-2024-38107Power Dependency Coordinator Privilege Escalation | Microsoft Windows | Patch soon | 0.02 | ||
| 374 | CVE-2026-21514Word Reliance on Untrusted Inputs in a Security Decision | Microsoft Office | Patch soon | 0.02 | ||
| 375 | CVE-2025-21418Ancillary Function Driver for WinSock Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| 376 | CVE-2025-21334Hyper-V NT Kernel Integration VSP Use-After-Free | Microsoft Windows | Patch soon | 0.02 | ||
| 377 | CVE-2021-40450Privilege Escalation | Microsoft Win32k | Patch soon | 0.02 | ||
| 378 | CVE-2021-41357Privilege Escalation | Microsoft Win32k | Patch soon | 0.02 | ||
| 379 | CVE-2025-32701Common Log File System (CLFS) Driver Use-After-Free | Microsoft Windows | Patch soon | 0.01 | ||
| 380 | CVE-2025-24983Win32k Use-After-Free | Microsoft Windows | Patch soon | 0.01 | ||
| 381 | CVE-2025-21335Hyper-V NT Kernel Integration VSP Use-After-Free | Microsoft Windows | Patch soon | 0.01 | ||
| 382 | CVE-2019-1214Privilege Common Log File System (CLFS) Escalation | Microsoft Windows | Patch soon | 0.01 | ||
| 383 | CVE-2024-49035Improper Access Control | Microsoft Partner Center | Patch soon | 0.01 | ||
| 384 | CVE-2026-45498Denial of Service | Microsoft Defender | Patch soon | 0.01 | ||
| 385 | CVE-2026-42897Exchange Server Cross-Site Scripting | Microsoft Microsoft | Patch soon | 0.01 | ||
| 386 | CVE-2026-41091Link Following | Microsoft Defender | Patch soon | 0.00 | ||
| 387 | CVE-2026-81963Link Following | Microsoft Windows | Patch soon | 0.00 | ||
| 388 | CVE-2026-56155Insufficient Granularity of Access Control | Microsoft Active Directory Federation Services | Patch soon | 0.00 | ||
| 389 | CVE-2026-68820Use-After-Free | Microsoft Windows Ancillary Function Driver for WinSock | Patch soon | 0.00 |