Exploitation timeline
Threadlinqs has recorded 224 Microsoft CVEs published between and . The busiest month was 2026-07 (28 new CVEs). 72 of them (32%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 224 tracked Microsoft CVEs.
- CVE-2019-0708critical 9.8KEVRansomwareEPSS 100%
- CVE-2017-0144high 8.8KEVRansomwareEPSS 99.2%
- CVE-2025-49706medium 6.5KEVRansomwareEPSS 99.1%
- CVE-2020-0688high 8.8KEVRansomwareEPSS 94.4%
- CVE-2017-11882high 7.8KEVRansomwareEPSS 94.4%
- CVE-2020-1472medium 5.5KEVRansomwareEPSS 94.4%
- CVE-2021-40444high 8.8KEVRansomwareEPSS 94.3%
- CVE-2017-0199high 7.8KEVRansomwareEPSS 94.3%
- CVE-2021-27065high 7.8KEVRansomwareEPSS 94.3%
- CVE-2021-34527high 8.8KEVRansomwareEPSS 94.2%
- CVE-2021-34473critical 9.1KEVRansomwareEPSS 94.2%
- CVE-2022-41040high 8.8KEVRansomwareEPSS 94.1%
- CVE-2021-42278high 7.5KEVRansomwareEPSS 94.1%
- CVE-2021-42287high 7.5KEVRansomwareEPSS 94%
- CVE-2021-34523critical 9KEVRansomwareEPSS 94%
- CVE-2021-26855critical 9.1KEVRansomwareEPSS 94%
- CVE-2018-0802high 7.8KEVRansomwareEPSS 93.9%
- CVE-2021-31207medium 6.6KEVRansomwareEPSS 93.8%
- CVE-2021-36942high 7.5KEVRansomwareEPSS 93.7%
- CVE-2022-30190high 7.8KEVRansomwareEPSS 93.6%
- CVE-2023-23397critical 9.8KEVEPSS 93.4%
- CVE-2023-36884high 7.5KEVRansomwareEPSS 93.2%
- CVE-2024-21413critical 9.8KEVEPSS 93%
- CVE-2008-4250critical 9.8KEVRansomwareEPSS 92.1%
- CVE-2022-26923high 8.8KEVRansomwareEPSS 91.6%
- CVE-2022-41082high 8KEVRansomwareEPSS 90.7%
- CVE-2025-53770critical 9.8KEVRansomwareEPSS 90%
- CVE-2017-8570high 7.8KEVEPSS 89.9%
- CVE-2010-0249high 8.8KEVRansomwareEPSS 88.8%
- CVE-2010-0806high 8.8KEVRansomwareEPSS 87.3%
- CVE-2025-33053high 8.8KEVEPSS 82.1%
- CVE-2024-43451medium 6.5KEVEPSS 81.8%
- CVE-2014-4114high 7.8KEVEPSS 81.6%
- CVE-2024-21338high 7.8KEVRansomwareEPSS 79.1%
- CVE-2025-49704high 8.8KEVRansomwareEPSS 59.6%
- CVE-2025-24054medium 6.5KEVEPSS 59%
- CVE-2021-26858high 7.8KEVRansomwareEPSS 53%
- CVE-2009-1537high 8.8KEVRansomwareEPSS 53%
- CVE-2021-26857high 7.8KEVRansomwareEPSS 44.8%
- CVE-2025-33073high 8.8KEVRansomwareEPSS 37.2%
- CVE-2026-21513high 8.8KEVEPSS 28%
- CVE-2026-21533high 7.8KEVEPSS 22.7%
- CVE-2025-60710high 7.5KEVEPSS 20.8%
- CVE-2026-21525medium 6.2KEVEPSS 11.8%
- CVE-2026-32201high 8.8KEVEPSS 8.9%
- CVE-2026-21509high 7.8KEVEPSS 7.5%
- CVE-2026-32202medium 4.3KEVEPSS 7.2%
- CVE-2026-33825high 7.8KEVEPSS 7.1%
- CVE-2025-8088high 8.8KEVEPSS 7%
- CVE-2026-41091high 7.8KEVRansomwareEPSS 7%
- CVE-2026-42897high 8.1KEVEPSS 5.6%
- CVE-2022-38028high 7.8KEVEPSS 5%
- CVE-2015-2291high 7.8KEVRansomwareEPSS 4.9%
- CVE-2025-6218high 7.8KEVEPSS 4.8%
- CVE-2026-21519high 7.8KEVEPSS 4.5%
- CVE-2026-21514high 7.8KEVEPSS 4.2%
- CVE-2026-45498medium 4KEVRansomwareEPSS 4.1%
- CVE-2026-21510high 8.8KEVEPSS 3.5%
- CVE-2026-5281high 8.8KEVEPSS 3.3%
- CVE-2023-3079high 8.8KEVEPSS 2.1%
Products affected
Threadlinqs normalises CPE and CNA product records across all 224 CVEs; 149 distinct Microsoft products are affected. The most frequently affected (top 20):
- Windows Server 2012 52 CVEs
- Windows Server 2016 43 CVEs
- Windows Server 2019 39 CVEs
- Windows Server 2022 37 CVEs
- Windows 11 Version 24H2 35 CVEs
- Windows 10 Version 1809 33 CVEs
- Windows 10 Version 21H2 32 CVEs
- Windows 10 Version 22H2 32 CVEs
- Windows 11 Version 25H2 32 CVEs
- Windows 11 version 26H1 32 CVEs
- Windows 10 Version 1607 31 CVEs
- Windows 11 Version 23H2 28 CVEs
- Windows Server 2025 25 CVEs
- Windows 10 1809 24 CVEs
- Windows 10 21h2 24 CVEs
- Windows 10 1607 21 CVEs
- Windows 10 22h2 21 CVEs
- Windows 20 CVEs
- Windows 11 23h2 18 CVEs
- Windows Server 2012 R2 18 CVEs
Threat activity
926 tracked threat campaigns reference Microsoft products or exploit Microsoft CVEs; the 25 most recent are listed.
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)HIGH
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)HIGH
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)HIGH
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization FlawHIGH
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked IntrusionHIGH
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)HIGH
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)CRITICAL
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)HIGH
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic RedirectionMEDIUM
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus ScansHIGH
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAVMEDIUM
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)CRITICAL
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2HIGH
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based BackdoorsHIGH
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU OrganizationsHIGH
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormHIGH
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock BinariesHIGH
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX InstallersHIGH
- Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)CRITICAL
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows DefensesHIGH
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity VerificationHIGH
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)HIGH
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent AccessHIGH
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond UkraineHIGH
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companiesHIGH
Threat actors targeting Microsoft
Named threat actors attributed to campaigns that involve Microsoft products or CVEs, with the number of linked campaigns:
How to prioritise Microsoft patching
This order follows the data Threadlinqs holds for Microsoft, not a generic severity checklist:
- 72 of 224 Microsoft CVEs (32%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2019-0708, CVE-2017-0144, CVE-2025-49706.
- 36 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- 52 CVEs score Critical and 139 High on CVSS v3 (maximum 10, average 8.2); sequence these after KEV and high-EPSS items.
- 22 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.