Skip to content

Data collected

CVEs Live

Microsoft vulnerabilities exploited in the wild

The Microsoft CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

389
flaws with confirmed attacks
117
used by ransomware
22.4%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2026-65660Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SharePoint

    Microsoft SharePoint Code Injection Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    2.10%81th pct

    KEV dates

    added due
  2. CVE-2026-85880Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Windows

    Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    3.62%89th pct

    KEV dates

    added due
  3. CVE-2026-81963Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Windows

    Microsoft Windows Link Following Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    0.39%31th pct

    KEV dates

    added due
  4. CVE-2019-1068Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SQL Server

    Microsoft SQL Server Remote Code Execution Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    57.0%99.0th pct

    KEV dates

    added due
  5. CVE-2026-55040Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SharePoint

    Microsoft SharePoint Weak Authentication Vulnerability

    Severity

    9.1CRITICALCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    17.5%97th pct

    KEV dates

    added due
  6. CVE-2026-33824Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Internet Key Exchange (IKE) Service Extensions

    Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    1.62%75th pct

    KEV dates

    added due
  7. CVE-2026-68820Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Windows Ancillary Function Driver for WinSock

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Severity

    7.0HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    0.33%24th pct

    KEV dates

    added due
  8. CVE-2026-50522Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SharePoint

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    3.04%87th pct

    KEV dates

    added due
  9. CVE-2026-58644Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SharePoint

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    15.9%97th pct

    KEV dates

    added due
  10. CVE-2026-56164Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · SharePoint Server

    Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    1.01%62th pct

    KEV dates

    added due
  11. CVE-2026-56155Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Microsoft · Active Directory Federation Services

    Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    0.35%26th pct

    KEV dates

    added due
  12. CVE-2026-45659Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalogransomware use: known

    Microsoft · SharePoint Server

    Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · microsoft.com

    Attack probability (EPSS)

    2.70%85th pct

    KEV dates

    added due

Microsoft products in the catalog

Among the most recent entries, the products that appear most often are:

  • SharePoint4 entries
  • Windows2 entries
  • SharePoint Server2 entries
  • SQL Server1 entry
  • Internet Key Exchange (IKE) Service Extensions1 entry
  • Windows Ancillary Function Driver for WinSock1 entry
  • Active Directory Federation Services1 entry

Product names are the ones CISA uses in the catalog. To check a specific Microsoft CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Fixed versions and workarounds are published by the vendor: Microsoft Security Update Guide.

Other vendors

Questions

How many Microsoft vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 389 Microsoft vulnerabilities as of 3 Oct 2026. CISA marks 117 of them as known to be used in ransomware campaigns.

What is the most recent Microsoft entry in KEV?

CVE-2026-65660 (Microsoft SharePoint Code Injection Vulnerability), added on 25 Sep 2026 with a due date of 28 Sep 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every Microsoft CVE?

No. It lists only the Microsoft CVEs that CISA has confirmed as exploited. Microsoft publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should Microsoft vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections