Microsoft vulnerabilities under active exploitation
38 CVEs on this page carry evidence of exploitation.
Which Microsoft vulnerabilities are being exploited?
35 of them are in the CISA KEV catalog.
4 were added to KEV in the last 90 days.
- CVE-2026-50522 In KEV since 2026-07-22 · Fix identified
- CVE-2026-56164 In KEV since 2026-07-14 · Fix identified
- CVE-2026-45498 In KEV since 2026-05-20 · EPSS 63% · Fix identified
- CVE-2026-41091 In KEV since 2026-05-20 · EPSS 10% · Fix identified
- CVE-2026-33825 In KEV since 2026-04-22 · Fix identified
- CVE-2026-34197 In KEV since 2026-04-16 · EPSS 97% · No fix identified here
- CVE-2009-0238 In KEV since 2026-04-14 · EPSS 43% · No fix identified here
- CVE-2026-32201 In KEV since 2026-04-14 · Fix identified
- CVE-2026-21643 In KEV since 2026-04-13 · EPSS 94% · No fix identified here
- CVE-2023-21529 In KEV since 2026-04-13 · EPSS 62% · No fix identified here
- CVE-2020-9715 In KEV since 2026-04-13 · EPSS 48% · No fix identified here
- CVE-2012-1854 In KEV since 2026-04-13 · EPSS 21% · No fix identified here
- CVE-2023-36424 In KEV since 2026-04-13 · EPSS 12% · No fix identified here
- CVE-2026-34621 In KEV since 2026-04-13 · EPSS 7% · No fix identified here
- CVE-2025-60710 In KEV since 2026-04-13 · EPSS 5% · No fix identified here
- CVE-2026-5281 In KEV since 2026-04-01 · EPSS 5% · Fix identified
- CVE-2026-20963 In KEV since 2026-03-18 · EPSS 32% · No fix identified here
- CVE-2026-20700 In KEV since 2026-02-12 · EPSS 1% · Fix identified
- CVE-2026-21510 In KEV since 2026-02-10 · EPSS 26% · Fix identified
- CVE-2026-21513 In KEV since 2026-02-10 · EPSS 15% · Fix identified
- CVE-2026-21525 In KEV since 2026-02-10 · EPSS 5% · Fix identified
- CVE-2026-21533 In KEV since 2026-02-10 · EPSS 4% · Fix identified
- CVE-2026-21519 In KEV since 2026-02-10 · EPSS 2% · Fix identified
- CVE-2026-21514 In KEV since 2026-02-10 · EPSS 2% · Fix identified
- CVE-2026-21509 In KEV since 2026-01-26 · EPSS 72% · No fix identified here
- CVE-2025-55182 In KEV since 2025-12-05 · EPSS 99.6% · Used in ransomware · Fix identified
- CVE-2025-61882 In KEV since 2025-10-06 · EPSS 99.7% · Used in ransomware · No fix identified here
- CVE-2025-53770 In KEV since 2025-07-20 · EPSS 100.0% · Used in ransomware · No fix identified here
- CVE-2025-31324 In KEV since 2025-04-29 · EPSS 99.5% · Used in ransomware · No fix identified here
- CVE-2025-24472 In KEV since 2025-03-18 · EPSS 4% · Used in ransomware · No fix identified here
- CVE-2024-55591 In KEV since 2025-01-14 · EPSS 98% · Used in ransomware · No fix identified here
- CVE-2021-26855 In KEV since 2021-11-03 · EPSS 100.0% · Used in ransomware · No fix identified here
- CVE-2021-27065 In KEV since 2021-11-03 · EPSS 99.9% · Used in ransomware · No fix identified here
- CVE-2021-26857 In KEV since 2021-11-03 · EPSS 94% · Used in ransomware · No fix identified here
- CVE-2021-26858 In KEV since 2021-11-03 · EPSS 90% · Used in ransomware · No fix identified here
- CVE-2026-41089 EPSS 80% · Fix identified
- CVE-2026-28289 EPSS 31% · No fix identified here
- CVE-2026-50656 EPSS 11% · Fix identified
Which of them have a fix?
We can name a fix for 17 of them.
For the rest we hold no patch identifier, which is not the same as no patch existing.
What PlainSec published about Microsoft
Which Microsoft products this page tracks
- Active Directory
- Azure
- Azure Sentinel
- Exchange Online
- Exchange Server
- Intune
- Microsoft
- Microsoft 365
- Microsoft Active Directory
- Microsoft Azure
- Microsoft Copilot
- Microsoft Defender
- Microsoft Edge
- Microsoft Entra ID
- Microsoft Excel
- Microsoft Exchange
- Microsoft Exchange Online
- Microsoft Intune
- Microsoft Office
- Microsoft Power Platform
- Microsoft Sentinel
- Microsoft SharePoint
- Microsoft Teams
- Microsoft Windows
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server
- Microsoft Word
- Office 365
- Power Automate
- SharePoint
- Teams
- Windows
- Windows Defender
- Windows Server
KEV and EPSS are re-checked daily. Page last updated 2026-08-16.