Threadlinqs IntelligenceStart free

Vendor149 products tracked

Microsoft vulnerabilities & exploitation

72 in CISA KEV36 ransomware-linked22 with public exploit

As of 2026-10-05, Threadlinqs tracks 224 Microsoft CVEs, 72 in the CISA Known Exploited Vulnerabilities catalog, 36 used in ransomware campaigns, linked to 926 tracked threat campaigns and 12 named threat actors.

CVEs
224Since 2008
CISA KEV
7232% of CVEs
Critical
52CVSS v3 9.0+
Avg CVSS
8.2/10Max 10
Threats
926Linked campaigns
Actors
12Named in campaigns

Data as of:

Exploitation timeline

Threadlinqs has recorded 224 Microsoft CVEs published between and . The busiest month was 2026-07 (28 new CVEs). 72 of them (32%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 224 tracked Microsoft CVEs.

Products affected

Threadlinqs normalises CPE and CNA product records across all 224 CVEs; 149 distinct Microsoft products are affected. The most frequently affected (top 20):

  • Windows Server 2012 52 CVEs
  • Windows Server 2016 43 CVEs
  • Windows Server 2019 39 CVEs
  • Windows Server 2022 37 CVEs
  • Windows 11 Version 24H2 35 CVEs
  • Windows 10 Version 1809 33 CVEs
  • Windows 10 Version 21H2 32 CVEs
  • Windows 10 Version 22H2 32 CVEs
  • Windows 11 Version 25H2 32 CVEs
  • Windows 11 version 26H1 32 CVEs
  • Windows 10 Version 1607 31 CVEs
  • Windows 11 Version 23H2 28 CVEs
  • Windows Server 2025 25 CVEs
  • Windows 10 1809 24 CVEs
  • Windows 10 21h2 24 CVEs
  • Windows 10 1607 21 CVEs
  • Windows 10 22h2 21 CVEs
  • Windows 20 CVEs
  • Windows 11 23h2 18 CVEs
  • Windows Server 2012 R2 18 CVEs

Threat activity

926 tracked threat campaigns reference Microsoft products or exploit Microsoft CVEs; the 25 most recent are listed.

Threat actors targeting Microsoft

Named threat actors attributed to campaigns that involve Microsoft products or CVEs, with the number of linked campaigns:

How to prioritise Microsoft patching

This order follows the data Threadlinqs holds for Microsoft, not a generic severity checklist:

  • 72 of 224 Microsoft CVEs (32%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2019-0708, CVE-2017-0144, CVE-2025-49706.
  • 36 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
  • 52 CVEs score Critical and 139 High on CVSS v3 (maximum 10, average 8.2); sequence these after KEV and high-EPSS items.
  • 22 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.