Product of Microsoft

Windows

As of , 174 Microsoft Windows vulnerabilities are on CISA's list of exploited vulnerabilities, 49 of them used in ransomware campaigns; 13 were added in 2026. Patch first: CVE-2025-60710.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-60710Link FollowingMicrosoft WindowsPatch nowRansomware use, listed within a year0.05
2CVE-2008-4250Buffer OverflowMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry0.99
3CVE-2008-0015Video ActiveX Control Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry0.77
4CVE-2013-3918Out-of-Bounds WriteMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry0.74
5CVE-2010-2568Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry0.91
6CVE-2015-0016TS WebProxy Directory TraversalMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry0.76
7CVE-2015-2426Adobe Type Manager Library Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry0.87
8CVE-2014-6332Object Linking & Embedding (OLE) Automation Array Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry0.95
9CVE-2017-0146SMB Remote Code ExecutionMicrosoft WindowsPatch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry0.90
10CVE-2014-4114Object Linking & Embedding (OLE) Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry0.82
11CVE-2014-6352Code InjectionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry0.77
12CVE-2017-0143Server Message Block (SMBv1) Remote Code ExecutionMicrosoft WindowsPatch this weekRansomware use; Metasploit module; EPSS 0.93; verified Exploit-DB entry0.93
13CVE-2019-0841AppX Deployment Service (AppXSVC) Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; Metasploit module; verified Exploit-DB entry0.41
14CVE-2019-1405Universal Plug and Play (UPnP) Service Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; Metasploit module; verified Exploit-DB entry0.30
15CVE-2010-0232Kernel Exception HandlerMicrosoft WindowsPatch this weekMetasploit module; verified Exploit-DB entry0.29
16CVE-2013-5065Kernel Privilege EscalationMicrosoft WindowsPatch this weekMetasploit module; verified Exploit-DB entry0.35
17CVE-2016-0099Secondary Logon Service Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; Metasploit module; verified Exploit-DB entry0.37
18CVE-2016-0040Kernel Privilege EscalationMicrosoft WindowsPatch this weekMetasploit module; verified Exploit-DB entry0.24
19CVE-2019-1322Privilege EscalationMicrosoft WindowsPatch this weekRansomware use; Metasploit module; verified Exploit-DB entry0.19
20CVE-2025-59287Server Update Service (WSUS) Deserialization of Untrusted DataMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.990.99
21CVE-2011-3402Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.780.78
22CVE-2025-33053External Control of File Name or PathMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.870.87
23CVE-2018-0824COM for Windows Deserialization of Untrusted DataMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.730.73
24CVE-2022-30190Support Diagnostic Tool (MSDT) Remote Code ExecutionMicrosoft WindowsPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
25CVE-2017-8464Shell (.lnk) Remote Code ExecutionMicrosoft WindowsPatch this weekMetasploit module; EPSS 0.900.90

The next 100, from number 26

Added each year

204060802021: 282820212022: 666620222023: 141420232024: 242420242025: 292920252026: 13132026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
202128
202266
202314
202424
202529
202613

Used in ransomware

Changes CISA made to these entries

  1. CVE-2022-37969 Microsoft WindowsRansomware use: Unknown to Known.
  2. CVE-2021-43226 Microsoft WindowsRansomware use: Unknown to Known.
  3. CVE-2025-60710 Microsoft WindowsRansomware use: Unknown to Known.
  4. CVE-2026-21513 Microsoft WindowsEdited: notes.
  5. CVE-2026-21513 Microsoft WindowsEdited: description and name.
  6. CVE-2024-49039 Microsoft WindowsRansomware use: Unknown to Known.
  7. CVE-2024-30088 Microsoft WindowsRansomware use: Unknown to Known.
  8. CVE-2026-20805 Microsoft WindowsEdited: description.
  9. CVE-2021-34527 Microsoft WindowsDeadline moved from 20 July 2021 to 3 May 2022.
  10. CVE-2020-1350 Microsoft WindowsDeadline moved from 24 July 2020 to 3 May 2022.

Every change we recorded