Vendor

Microsoft, page 5

As of , 389 Microsoft vulnerabilities are on CISA's list of exploited vulnerabilities, 117 of them used in ransomware campaigns; 40 were added in 2026. Patch first: CVE-2019-1068.

#VulnerabilityProductOur groupListedDeadlineEPSS
326CVE-2024-38106Kernel Privilege EscalationMicrosoft WindowsPatch soon0.06
327CVE-2021-27059Remote Code ExecutionMicrosoft OfficePatch soon0.06
328CVE-2021-33739Desktop Window Manager (DWM) Core Library Privilege EscalationMicrosoft WindowsPatch soon0.07
329CVE-2023-21823Graphic Component Privilege EscalationMicrosoft WindowsPatch soon0.06
330CVE-2015-6175Kernel Privilege EscalationMicrosoft WindowsPatch soon0.05
331CVE-2019-0863Error Reporting (WER) Privilege EscalationMicrosoft WindowsPatch soon0.05
332CVE-2020-17087Kernel Privilege EscalationMicrosoft WindowsPatch soon0.05
333CVE-2021-27085Remote Code ExecutionMicrosoft Internet ExplorerPatch soon0.05
334CVE-2026-32202Protection Mechanism FailureMicrosoft WindowsPatch soon0.05
335CVE-2026-21525NULL Pointer DereferenceMicrosoft WindowsPatch soon0.05
336CVE-2020-1027Kernel Privilege EscalationMicrosoft WindowsPatch soon0.05
337CVE-2009-1123Improper Input ValidationMicrosoft WindowsPatch soon0.05
338CVE-2021-31979Kernel Privilege EscalationMicrosoft WindowsPatch soon0.05
339CVE-2026-21533Improper Privilege ManagementMicrosoft WindowsPatch soon0.04
340CVE-2025-24985Fast FAT File System Driver Integer OverflowMicrosoft WindowsPatch soon0.04
341CVE-2024-30040MSHTML Platform Security Feature BypassMicrosoft WindowsPatch soon0.04
342CVE-2023-32049Defender SmartScreen Security Feature BypassMicrosoft WindowsPatch soon0.04
343CVE-2015-1769Mount Manager Privilege EscalationMicrosoft WindowsPatch soon0.04
344CVE-2018-8611Kernel Privilege EscalationMicrosoft WindowsPatch soon0.04
345CVE-2026-85880Heap-Based Buffer OverflowMicrosoft WindowsPatch soon0.04
346CVE-2023-36584Mark of the Web (MOTW) Security Feature BypassMicrosoft WindowsPatch soon0.03
347CVE-2022-41125CNG Key Isolation Service Privilege EscalationMicrosoft WindowsPatch soon0.03
348CVE-2018-8589Privilege EscalationMicrosoft Win32kPatch soon0.03
349CVE-2017-0001Privilege EscalationMicrosoft Graphics Device Interface (GDI)Patch soon0.03
350CVE-2021-31199Privilege EscalationMicrosoft Enhanced Cryptographic ProviderPatch soon0.03
351CVE-2021-38649Privilege EscalationMicrosoft Open Management Infrastructure (OMI)Patch soon0.03
352CVE-2025-59230Improper Access ControlMicrosoft WindowsPatch soon0.03
353CVE-2024-38226Protection Mechanism FailureMicrosoft PublisherPatch soon0.03
354CVE-2021-38645Privilege EscalationMicrosoft Open Management Infrastructure (OMI)Patch soon0.03
355CVE-2025-62221Use After FreeMicrosoft WindowsPatch soon0.03
356CVE-2022-41049Mark of the Web (MOTW) Security Feature BypassMicrosoft WindowsPatch soon0.02
357CVE-2021-31201Privilege EscalationMicrosoft Enhanced Cryptographic ProviderPatch soon0.03
358CVE-2026-21519Type ConfusionMicrosoft WindowsPatch soon0.02
359CVE-2022-21919User Profile Service Privilege EscalationMicrosoft WindowsPatch soon0.02
360CVE-2025-32706Common Log File System (CLFS) Driver Heap-Based Buffer OverflowMicrosoft WindowsPatch soon0.02
361CVE-2025-24993NTFS Heap-Based Buffer OverflowMicrosoft WindowsPatch soon0.02
362CVE-2025-21391Storage Link FollowingMicrosoft WindowsPatch soon0.02
363CVE-2019-0880Privilege EscalationMicrosoft WindowsPatch soon0.02
364CVE-2025-32709Ancillary Function Driver for WinSock Use-After-FreeMicrosoft WindowsPatch soon0.02
365CVE-2025-24984NTFS Information DisclosureMicrosoft WindowsPatch soon0.02
366CVE-2025-24991NTFS Out-Of-Bounds ReadMicrosoft WindowsPatch soon0.02
367CVE-2025-30400DWM Core Library Use-After-FreeMicrosoft WindowsPatch soon0.02
368CVE-2019-0797Privilege EscalationMicrosoft Win32kPatch soon0.02
369CVE-2023-28229Privilege EscalationMicrosoft Windows CNG Key Isolation ServicePatch soon0.02
370CVE-2022-41033Privilege EscalationMicrosoft Windows COM+ Event System ServicePatch soon0.02
371CVE-2026-33824Double FreeMicrosoft Internet Key Exchange (IKE) Service ExtensionsPatch soon0.02
372CVE-2025-24989Improper Access ControlMicrosoft Power PagesPatch soon0.02
373CVE-2024-38107Power Dependency Coordinator Privilege EscalationMicrosoft WindowsPatch soon0.02
374CVE-2026-21514Word Reliance on Untrusted Inputs in a Security DecisionMicrosoft OfficePatch soon0.02
375CVE-2025-21418Ancillary Function Driver for WinSock Heap-Based Buffer OverflowMicrosoft WindowsPatch soon0.02
376CVE-2025-21334Hyper-V NT Kernel Integration VSP Use-After-FreeMicrosoft WindowsPatch soon0.02
377CVE-2021-40450Privilege EscalationMicrosoft Win32kPatch soon0.02
378CVE-2021-41357Privilege EscalationMicrosoft Win32kPatch soon0.02
379CVE-2025-32701Common Log File System (CLFS) Driver Use-After-FreeMicrosoft WindowsPatch soon0.01
380CVE-2025-24983Win32k Use-After-FreeMicrosoft WindowsPatch soon0.01
381CVE-2025-21335Hyper-V NT Kernel Integration VSP Use-After-FreeMicrosoft WindowsPatch soon0.01
382CVE-2019-1214Privilege Common Log File System (CLFS) EscalationMicrosoft WindowsPatch soon0.01
383CVE-2024-49035Improper Access ControlMicrosoft Partner CenterPatch soon0.01
384CVE-2026-45498Denial of ServiceMicrosoft DefenderPatch soon0.01
385CVE-2026-42897Exchange Server Cross-Site ScriptingMicrosoft MicrosoftPatch soon0.01
386CVE-2026-41091Link FollowingMicrosoft DefenderPatch soon0.00
387CVE-2026-81963Link FollowingMicrosoft WindowsPatch soon0.00
388CVE-2026-56155Insufficient Granularity of Access ControlMicrosoft Active Directory Federation ServicesPatch soon0.00
389CVE-2026-68820Use-After-FreeMicrosoft Windows Ancillary Function Driver for WinSockPatch soon0.00