# Microsoft vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 224 Microsoft CVEs, 72 in the CISA Known Exploited Vulnerabilities catalog, 36 used in ransomware campaigns, linked to 926 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 224 Microsoft CVEs published between 2008-10-15 and 2026-09-15. The busiest month was 2026-07 (28 new CVEs). 72 of them (32%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 60 of 224 tracked Microsoft CVEs.

- [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708) — CRITICAL 9.8 · KEV · Ransomware · EPSS 100% · 2019-05-16
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144) — HIGH 8.8 · KEV · Ransomware · EPSS 99.2% · 2017-03-17
- [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706) — MEDIUM 6.5 · KEV · Ransomware · EPSS 99.1% · 2025-07-08
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688) — HIGH 8.8 · KEV · Ransomware · EPSS 94.4% · 2020-02-11
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882) — HIGH 7.8 · KEV · Ransomware · EPSS 94.4% · 2017-11-15
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472) — MEDIUM 5.5 · KEV · Ransomware · EPSS 94.4% · 2020-08-17
- [CVE-2021-40444](https://intel.threadlinqs.com/cve/CVE-2021-40444) — HIGH 8.8 · KEV · Ransomware · EPSS 94.3% · 2021-09-15
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199) — HIGH 7.8 · KEV · Ransomware · EPSS 94.3% · 2017-04-12
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065) — HIGH 7.8 · KEV · Ransomware · EPSS 94.3% · 2021-03-03
- [CVE-2021-34527](https://intel.threadlinqs.com/cve/CVE-2021-34527) — HIGH 8.8 · KEV · Ransomware · EPSS 94.2% · 2021-07-02
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473) — CRITICAL 9.1 · KEV · Ransomware · EPSS 94.2% · 2021-07-14
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040) — HIGH 8.8 · KEV · Ransomware · EPSS 94.1% · 2022-10-03
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278) — HIGH 7.5 · KEV · Ransomware · EPSS 94.1% · 2021-11-10
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287) — HIGH 7.5 · KEV · Ransomware · EPSS 94% · 2021-11-10
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523) — CRITICAL 9 · KEV · Ransomware · EPSS 94% · 2021-07-14
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855) — CRITICAL 9.1 · KEV · Ransomware · EPSS 94% · 2021-03-03
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802) — HIGH 7.8 · KEV · Ransomware · EPSS 93.9% · 2018-01-10
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207) — MEDIUM 6.6 · KEV · Ransomware · EPSS 93.8% · 2021-05-11
- [CVE-2021-36942](https://intel.threadlinqs.com/cve/CVE-2021-36942) — HIGH 7.5 · KEV · Ransomware · EPSS 93.7% · 2021-08-12
- [CVE-2022-30190](https://intel.threadlinqs.com/cve/CVE-2022-30190) — HIGH 7.8 · KEV · Ransomware · EPSS 93.6% · 2022-06-01
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397) — CRITICAL 9.8 · KEV · EPSS 93.4% · 2023-03-14
- [CVE-2023-36884](https://intel.threadlinqs.com/cve/CVE-2023-36884) — HIGH 7.5 · KEV · Ransomware · EPSS 93.2% · 2023-07-11
- [CVE-2024-21413](https://intel.threadlinqs.com/cve/CVE-2024-21413) — CRITICAL 9.8 · KEV · EPSS 93% · 2024-02-13
- [CVE-2008-4250](https://intel.threadlinqs.com/cve/CVE-2008-4250) — CRITICAL 9.8 · KEV · Ransomware · EPSS 92.1% · 2008-10-23
- [CVE-2022-26923](https://intel.threadlinqs.com/cve/CVE-2022-26923) — HIGH 8.8 · KEV · Ransomware · EPSS 91.6% · 2022-05-10
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082) — HIGH 8 · KEV · Ransomware · EPSS 90.7% · 2022-10-03
- [CVE-2025-53770](https://intel.threadlinqs.com/cve/CVE-2025-53770) — CRITICAL 9.8 · KEV · Ransomware · EPSS 90% · 2025-07-20
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570) — HIGH 7.8 · KEV · EPSS 89.9% · 2017-07-11
- [CVE-2010-0249](https://intel.threadlinqs.com/cve/CVE-2010-0249) — HIGH 8.8 · KEV · Ransomware · EPSS 88.8% · 2010-01-15
- [CVE-2010-0806](https://intel.threadlinqs.com/cve/CVE-2010-0806) — HIGH 8.8 · KEV · Ransomware · EPSS 87.3% · 2010-03-10
- [CVE-2025-33053](https://intel.threadlinqs.com/cve/CVE-2025-33053) — HIGH 8.8 · KEV · EPSS 82.1% · 2025-06-10
- [CVE-2024-43451](https://intel.threadlinqs.com/cve/CVE-2024-43451) — MEDIUM 6.5 · KEV · EPSS 81.8% · 2024-11-12
- [CVE-2014-4114](https://intel.threadlinqs.com/cve/CVE-2014-4114) — HIGH 7.8 · KEV · EPSS 81.6% · 2014-10-15
- [CVE-2024-21338](https://intel.threadlinqs.com/cve/CVE-2024-21338) — HIGH 7.8 · KEV · Ransomware · EPSS 79.1% · 2024-02-13
- [CVE-2025-49704](https://intel.threadlinqs.com/cve/CVE-2025-49704) — HIGH 8.8 · KEV · Ransomware · EPSS 59.6% · 2025-07-08
- [CVE-2025-24054](https://intel.threadlinqs.com/cve/CVE-2025-24054) — MEDIUM 6.5 · KEV · EPSS 59% · 2025-03-11
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858) — HIGH 7.8 · KEV · Ransomware · EPSS 53% · 2021-03-03
- [CVE-2009-1537](https://intel.threadlinqs.com/cve/CVE-2009-1537) — HIGH 8.8 · KEV · Ransomware · EPSS 53% · 2009-05-29
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857) — HIGH 7.8 · KEV · Ransomware · EPSS 44.8% · 2021-03-03
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073) — HIGH 8.8 · KEV · Ransomware · EPSS 37.2% · 2025-06-10
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513) — HIGH 8.8 · KEV · EPSS 28% · 2026-02-10
- [CVE-2026-21533](https://intel.threadlinqs.com/cve/CVE-2026-21533) — HIGH 7.8 · KEV · EPSS 22.7% · 2026-02-10
- [CVE-2025-60710](https://intel.threadlinqs.com/cve/CVE-2025-60710) — HIGH 7.5 · KEV · EPSS 20.8% · 2025-11-11
- [CVE-2026-21525](https://intel.threadlinqs.com/cve/CVE-2026-21525) — MEDIUM 6.2 · KEV · EPSS 11.8% · 2026-02-10
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201) — HIGH 8.8 · KEV · EPSS 8.9% · 2026-04-14
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509) — HIGH 7.8 · KEV · EPSS 7.5% · 2026-01-26
- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202) — MEDIUM 4.3 · KEV · EPSS 7.2% · 2026-04-14
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825) — HIGH 7.8 · KEV · EPSS 7.1% · 2026-04-14
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088) — HIGH 8.8 · KEV · EPSS 7% · 2025-08-08
- [CVE-2026-41091](https://intel.threadlinqs.com/cve/CVE-2026-41091) — HIGH 7.8 · KEV · Ransomware · EPSS 7% · 2026-05-20
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897) — HIGH 8.1 · KEV · EPSS 5.6% · 2026-05-14
- [CVE-2022-38028](https://intel.threadlinqs.com/cve/CVE-2022-38028) — HIGH 7.8 · KEV · EPSS 5% · 2022-10-11
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291) — HIGH 7.8 · KEV · Ransomware · EPSS 4.9% · 2017-08-09
- [CVE-2025-6218](https://intel.threadlinqs.com/cve/CVE-2025-6218) — HIGH 7.8 · KEV · EPSS 4.8% · 2025-06-21
- [CVE-2026-21519](https://intel.threadlinqs.com/cve/CVE-2026-21519) — HIGH 7.8 · KEV · EPSS 4.5% · 2026-02-10
- [CVE-2026-21514](https://intel.threadlinqs.com/cve/CVE-2026-21514) — HIGH 7.8 · KEV · EPSS 4.2% · 2026-02-10
- [CVE-2026-45498](https://intel.threadlinqs.com/cve/CVE-2026-45498) — MEDIUM 4 · KEV · Ransomware · EPSS 4.1% · 2026-05-20
- [CVE-2026-21510](https://intel.threadlinqs.com/cve/CVE-2026-21510) — HIGH 8.8 · KEV · EPSS 3.5% · 2026-02-10
- [CVE-2026-5281](https://intel.threadlinqs.com/cve/CVE-2026-5281) — HIGH 8.8 · KEV · EPSS 3.3% · 2026-04-01
- [CVE-2023-3079](https://intel.threadlinqs.com/cve/CVE-2023-3079) — HIGH 8.8 · KEV · EPSS 2.1% · 2023-06-05

## Products affected

Threadlinqs normalises CPE and CNA product records across all 224 CVEs; 149 distinct Microsoft products are affected. The most frequently affected (top 20):

- Windows Server 2012 — 52 CVEs
- Windows Server 2016 — 43 CVEs
- Windows Server 2019 — 39 CVEs
- Windows Server 2022 — 37 CVEs
- Windows 11 Version 24H2 — 35 CVEs
- Windows 10 Version 1809 — 33 CVEs
- Windows 10 Version 21H2 — 32 CVEs
- Windows 10 Version 22H2 — 32 CVEs
- Windows 11 Version 25H2 — 32 CVEs
- Windows 11 version 26H1 — 32 CVEs
- Windows 10 Version 1607 — 31 CVEs
- Windows 11 Version 23H2 — 28 CVEs
- Windows Server 2025 — 25 CVEs
- Windows 10 1809 — 24 CVEs
- Windows 10 21h2 — 24 CVEs
- Windows 10 1607 — 21 CVEs
- Windows 10 22h2 — 21 CVEs
- Windows — 20 CVEs
- Windows 11 23h2 — 18 CVEs
- Windows Server 2012 R2 — 18 CVEs

## Threat activity

926 tracked threat campaigns reference Microsoft products or exploit Microsoft CVEs; the 25 most recent are listed.

- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — HIGH — 2026-10-04
- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH — 2026-10-03
- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)](https://intel.threadlinqs.com/threat/TL-2026-2858) — HIGH — 2026-10-03
- [Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw](https://intel.threadlinqs.com/threat/TL-2026-2864) — HIGH — 2026-10-03
- [Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion](https://intel.threadlinqs.com/threat/TL-2026-2868) — HIGH — 2026-10-03
- [EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)](https://intel.threadlinqs.com/threat/TL-2026-2873) — HIGH — 2026-10-03
- [Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)](https://intel.threadlinqs.com/threat/TL-2026-2838) — CRITICAL — 2026-10-02
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — HIGH — 2026-10-02
- [Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection](https://intel.threadlinqs.com/threat/TL-2026-2821) — MEDIUM — 2026-10-01
- [Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans](https://intel.threadlinqs.com/threat/TL-2026-2824) — HIGH — 2026-10-01
- [Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV](https://intel.threadlinqs.com/threat/TL-2026-2828) — MEDIUM — 2026-10-01
- [Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)](https://intel.threadlinqs.com/threat/TL-2026-2833) — CRITICAL — 2026-10-01
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — HIGH — 2026-10-01
- [AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors](https://intel.threadlinqs.com/threat/TL-2026-2800) — HIGH — 2026-09-30
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations](https://intel.threadlinqs.com/threat/TL-2026-2802) — HIGH — 2026-09-30
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — HIGH — 2026-09-30
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries](https://intel.threadlinqs.com/threat/TL-2026-2766) — HIGH — 2026-09-29
- [OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers](https://intel.threadlinqs.com/threat/TL-2026-2767) — HIGH — 2026-09-29
- [Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)](https://intel.threadlinqs.com/threat/TL-2026-2772) — CRITICAL — 2026-09-29
- [SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses](https://intel.threadlinqs.com/threat/TL-2026-2773) — HIGH — 2026-09-29
- [AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification](https://intel.threadlinqs.com/threat/TL-2026-2774) — HIGH — 2026-09-29
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — HIGH — 2026-09-29
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — HIGH — 2026-09-29
- [Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine](https://intel.threadlinqs.com/threat/TL-2026-2795) — HIGH — 2026-09-29
- [Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies](https://intel.threadlinqs.com/threat/TL-2026-2764) — HIGH — 2026-09-28

## Threat actors targeting Microsoft

Named threat actors attributed to campaigns that involve Microsoft products or CVEs, with the number of linked campaigns:

- [APT28](https://intel.threadlinqs.com/actor/APT28) — 17 campaigns
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 16 campaigns
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 13 campaigns
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 12 campaigns
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 12 campaigns
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 11 campaigns
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 11 campaigns
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 11 campaigns
- [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda) — 10 campaigns
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 10 campaigns
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 9 campaigns
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 9 campaigns

## How to prioritise Microsoft patching

This order follows the data Threadlinqs holds for Microsoft, not a generic severity checklist:

- 72 of 224 Microsoft CVEs (32%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708), [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144), [CVE-2025-49706](https://intel.threadlinqs.com/cve/CVE-2025-49706).
- 36 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- 52 CVEs score Critical and 139 High on CVSS v3 (maximum 10, average 8.2); sequence these after KEV and high-EPSS items.
- 22 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/microsoft
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
