Microsoft has 2,953 CVEs on record between 2013 and 2026. Disclosure cadence is accelerating: 2136 in the last 90 days against 414 in the 90 before. The busiest recent month was September 2026 with 1005. The median CVSS is 7.8 (high), with 178 rated critical. 3% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 113 days (91 cases). The dominant weakness classes are CWE-122 (585) and CWE-416 (512). Most affected products: windows_10_1607 (644), Windows 10 Version 1607 (481), Microsoft 365 Apps for Enterprise (209).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 3% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- 113 d median(91)
- Last 90 days
- 2136 prev 414
Weakness classes
Products
- windows_10_1607 644
- Windows 10 Version 1607 481
- Microsoft 365 Apps for Enterprise 209
- windows_10 122
- 365_apps 115
- windows_10_1809 106
Worst active — by depth score
CVE-2025-53770Critical· 9.8Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…100CVE-2021-38647Critical· 9.8Open Management Infrastructure (OMI) Remote Code Execution Vulnerability100CVE-2021-34473Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability100CVE-2021-26855Critical· 9.1Microsoft Exchange Server Remote Code Execution Vulnerability100CVE-2020-0796Critical· 10.0A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.100
microsoft vulnerabilities
CVEs affecting microsoft, newest first. Open any entry for full detail, references, and exploit status.
2953 CVEsRSS
CVE-2023-36566Medium· 6.5Microsoft Common Data Model SDK Denial of Service Vulnerability
Microsoft Common Data Model SDK Denial of Service Vulnerability
CVE-2023-23376High· 7.8CISA KEV0dayWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-37969High· 7.8CISA KEV0dayPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-30190High· 7.8CISA KEV0dayPoCA remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the c…
CVE-2022-21882High· 7.0CISA KEV0dayPoCWin32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
CVE-2021-43226High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-43890High· 7.1CISA KEV0dayWe have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malw…
CVE-2021-42321High· 8.8CISA KEVPoCMicrosoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-42292High· 7.8CISA KEVPoCMicrosoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2021-41379Medium· 5.5CISA KEV0dayWindows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
CVE-2021-42287High· 7.5CISA KEVPoCActive Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278High· 7.5CISA KEVPoCActive Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-40444High· 8.8CISA KEV0dayPoCMicrosoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …
CVE-2021-38649High· 7.0CISA KEVOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38648High· 7.8CISA KEVPoCOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38647Critical· 9.8CISA KEVPoCOpen Management Infrastructure (OMI) Remote Code Execution Vulnerability
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2021-38646High· 7.8CISA KEVMicrosoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2021-38645High· 7.8CISA KEVOpen Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-36955High· 7.8CISA KEVPoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36948High· 7.8CISA KEV0dayWindows Update Medic Service Elevation of Privilege Vulnerability
Windows Update Medic Service Elevation of Privilege Vulnerability
CVE-2021-36942High· 7.5CISA KEVPoCWindows LSA Spoofing Vulnerability
Windows LSA Spoofing Vulnerability
CVE-2021-34486High· 7.8CISA KEVPoCWindows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-34484High· 7.8CISA KEVWindows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2021-36934High· 7.8CISA KEVPoCAn elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…
CVE-2021-34448Medium· 6.8CISA KEV0dayScripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
CVE-2021-34447Medium· 6.8Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
CVE-2021-34446High· 8.0Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
CVE-2021-34445High· 7.8Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2021-34444Medium· 6.5Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability
CVE-2021-34442High· 8.8Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability