Exploited CVEs / By vendor / Microsoft

Microsoft vulnerabilities actively exploited

382 Microsoft CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-50522 (SharePoint, added 2026-07-22). 104 of the 382 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

382 exploited CVEs104 ransomware-linked

Senserva AI Opinion and rich prompt for Microsoft exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Windows: 172 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2008-4250Windows2026-05-20-
CVE-2026-32202Windows2026-04-28-
CVE-2023-36424Windows2026-04-13-
CVE-2025-60710Windows2026-04-13-
CVE-2008-0015Windows2026-02-17-
CVE-2026-21510Windows2026-02-10-
CVE-2026-21513Windows2026-02-10-
CVE-2026-21519Windows2026-02-10-
CVE-2026-21525Windows2026-02-10-
CVE-2026-21533Windows2026-02-10-
CVE-2026-20805Windows2026-01-13-
CVE-2025-62221Windows2025-12-09-
CVE-2025-62215Windows2025-11-12-
CVE-2025-59287Windows2025-10-24-
CVE-2025-33073Windows2025-10-20-
CVE-2025-24990Windows2025-10-14-
CVE-2025-59230Windows2025-10-14-
CVE-2011-3402Windows2025-10-06-
CVE-2013-3918Windows2025-10-06-
CVE-2021-43226Windows2025-10-06-
CVE-2025-33053Windows2025-06-10-
CVE-2025-30397Windows2025-05-13-
CVE-2025-30400Windows2025-05-13-
CVE-2025-32701Windows2025-05-13-
CVE-2025-32706Windows2025-05-13-
CVE-2025-32709Windows2025-05-13-
CVE-2025-24054Windows2025-04-17-
CVE-2025-29824Windows2025-04-08ransomware
CVE-2025-24983Windows2025-03-11-
CVE-2025-24984Windows2025-03-11-
CVE-2025-24985Windows2025-03-11-
CVE-2025-24991Windows2025-03-11-
CVE-2025-24993Windows2025-03-11-
CVE-2025-26633Windows2025-03-11ransomware
CVE-2018-8639Windows2025-03-03ransomware
CVE-2025-21391Windows2025-02-11-
CVE-2025-21418Windows2025-02-11-
CVE-2025-21333Windows2025-01-14-
CVE-2025-21334Windows2025-01-14-
CVE-2025-21335Windows2025-01-14-
CVE-2024-35250Windows2024-12-16-
CVE-2024-49138Windows2024-12-10-
CVE-2024-43451Windows2024-11-12-
CVE-2024-49039Windows2024-11-12ransomware
CVE-2024-30088Windows2024-10-15ransomware
CVE-2024-43572Windows2024-10-08-
CVE-2024-43573Windows2024-10-08-
CVE-2024-43461Windows2024-09-16-
CVE-2024-38014Windows2024-09-10-
CVE-2024-38217Windows2024-09-10-
CVE-2024-38106Windows2024-08-13-
CVE-2024-38107Windows2024-08-13-
CVE-2024-38178Windows2024-08-13-
CVE-2024-38193Windows2024-08-13-
CVE-2024-38213Windows2024-08-13-
CVE-2018-0824Windows2024-08-05-
CVE-2024-38080Windows2024-07-09-
CVE-2024-38112Windows2024-07-09-
CVE-2024-26169Windows2024-06-13ransomware
CVE-2024-30040Windows2024-05-14-
CVE-2022-38028Windows2024-04-23-
CVE-2024-21338Windows2024-03-04ransomware
CVE-2024-21351Windows2024-02-13-
CVE-2024-21412Windows2024-02-13ransomware
CVE-2023-36584Windows2023-11-16-
CVE-2023-36025Windows2023-11-14-
CVE-2023-36033Windows2023-11-14-
CVE-2023-36036Windows2023-11-14-
CVE-2023-36884Windows2023-07-17ransomware
CVE-2023-32046Windows2023-07-11-
CVE-2023-32049Windows2023-07-11-
CVE-2023-36874Windows2023-07-11-
CVE-2023-28252Windows2023-04-11ransomware
CVE-2019-1388Windows2023-04-07ransomware
CVE-2023-24880Windows2023-03-14ransomware
CVE-2023-21823Windows2023-02-14-
CVE-2023-23376Windows2023-02-14ransomware
CVE-2023-21674Windows2023-01-10-
CVE-2022-41049Windows2022-11-14-
CVE-2022-41073Windows2022-11-08ransomware
CVE-2022-41091Windows2022-11-08ransomware
CVE-2022-41125Windows2022-11-08-
CVE-2022-41128Windows2022-11-08-
CVE-2010-2568Windows2022-09-15-
CVE-2022-37969Windows2022-09-14-
CVE-2022-21971Windows2022-08-18-
CVE-2022-34713Windows2022-08-09-
CVE-2022-22047Windows2022-07-12-
CVE-2022-26925Windows2022-07-01-
CVE-2022-30190Windows2022-06-14ransomware
CVE-2012-0151Windows2022-06-08-
CVE-2014-4148Windows2022-05-25-
CVE-2015-0016Windows2022-05-25-
CVE-2015-1671Windows2022-05-25-
CVE-2015-1769Windows2022-05-25-
CVE-2015-6175Windows2022-05-25-
CVE-2016-3393Windows2022-05-25-
CVE-2016-7256Windows2022-05-25-
CVE-2017-0005Windows2022-05-24-
CVE-2017-8543Windows2022-05-24-
CVE-2018-8611Windows2022-05-24-
CVE-2019-0703Windows2022-05-23-
CVE-2019-0880Windows2022-05-23-
CVE-2019-1130Windows2022-05-23ransomware
CVE-2019-1385Windows2022-05-23ransomware
CVE-2020-1027Windows2022-05-23-
CVE-2022-21919Windows2022-04-25-
CVE-2022-26904Windows2022-04-25-
CVE-2022-22718Windows2022-04-19-
CVE-2022-24521Windows2022-04-13ransomware
CVE-2021-34484Windows2022-03-31-
CVE-2010-4398Windows2022-03-28-
CVE-2015-2426Windows2022-03-28-
CVE-2016-0040Windows2022-03-28-
CVE-2017-0213Windows2022-03-28ransomware
CVE-2018-8440Windows2022-03-28ransomware
CVE-2021-34486Windows2022-03-28-
CVE-2014-6332Windows2022-03-25-
CVE-2017-0146Windows2022-03-25ransomware
CVE-2018-8414Windows2022-03-25-
CVE-2022-21999Windows2022-03-25ransomware
CVE-2016-3309Windows2022-03-15ransomware
CVE-2017-0101Windows2022-03-15ransomware
CVE-2019-0543Windows2022-03-15ransomware
CVE-2019-0841Windows2022-03-15ransomware
CVE-2019-1064Windows2022-03-15ransomware
CVE-2019-1129Windows2022-03-15ransomware
CVE-2019-1253Windows2022-03-15ransomware
CVE-2019-1315Windows2022-03-15ransomware
CVE-2019-1322Windows2022-03-15ransomware
CVE-2019-1405Windows2022-03-15ransomware
CVE-2002-0367Windows2022-03-03-
CVE-2004-0210Windows2022-03-03-
CVE-2009-1123Windows2022-03-03-
CVE-2010-0232Windows2022-03-03-
CVE-2013-5065Windows2022-03-03-
CVE-2014-4114Windows2022-03-03-
CVE-2016-0099Windows2022-03-03ransomware
CVE-2021-41379Windows2022-03-03ransomware
CVE-2014-6352Windows2022-02-25-
CVE-2018-8174Windows2022-02-15ransomware
CVE-2017-8464Windows2022-02-10-
CVE-2021-36934Windows2022-02-10-
CVE-2020-0787Windows2022-01-28ransomware
CVE-2021-43890Windows2021-12-15ransomware
CVE-2021-40449Windows2021-11-17ransomware
CVE-2014-1812Windows2021-11-03ransomware
CVE-2016-0185Windows2021-11-03-
CVE-2017-0143Windows2021-11-03ransomware
CVE-2019-0863Windows2021-11-03-
CVE-2019-1214Windows2021-11-03-
CVE-2019-1215Windows2021-11-03ransomware
CVE-2020-0601Windows2021-11-03-
CVE-2020-0683Windows2021-11-03-
CVE-2020-0938Windows2021-11-03-
CVE-2020-0986Windows2021-11-03-
CVE-2020-1020Windows2021-11-03-
CVE-2020-1350Windows2021-11-03-
CVE-2020-1464Windows2021-11-03-
CVE-2020-17087Windows2021-11-03-
CVE-2021-1675Windows2021-11-03ransomware
CVE-2021-31955Windows2021-11-03-
CVE-2021-31956Windows2021-11-03-
CVE-2021-31979Windows2021-11-03-
CVE-2021-33739Windows2021-11-03-
CVE-2021-33742Windows2021-11-03-
CVE-2021-33771Windows2021-11-03-
CVE-2021-34448Windows2021-11-03-
CVE-2021-34527Windows2021-11-03ransomware
CVE-2021-36942Windows2021-11-03ransomware
CVE-2021-36948Windows2021-11-03-
CVE-2021-36955Windows2021-11-03ransomware

Internet Explorer: 36 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2010-0249Internet Explorer2026-05-20-
CVE-2010-0806Internet Explorer2026-05-20-
CVE-2010-3962Internet Explorer2025-10-06-
CVE-2013-3893Internet Explorer2025-08-12-
CVE-2012-4792Internet Explorer2024-07-23-
CVE-2013-3163Internet Explorer2023-03-30-
CVE-2012-4969Internet Explorer2022-06-08-
CVE-2013-7331Internet Explorer2022-05-25-
CVE-2014-2817Internet Explorer2022-05-25-
CVE-2014-4123Internet Explorer2022-05-25-
CVE-2015-0071Internet Explorer2022-05-25-
CVE-2015-2425Internet Explorer2022-05-25-
CVE-2016-0162Internet Explorer2022-05-24-
CVE-2016-3298Internet Explorer2022-05-24-
CVE-2017-0149Internet Explorer2022-05-24-
CVE-2017-0210Internet Explorer2022-05-24-
CVE-2019-0676Internet Explorer2022-05-23-
CVE-2014-0322Internet Explorer2022-05-04-
CVE-2015-2502Internet Explorer2022-04-13-
CVE-2013-2551Internet Explorer2022-03-28ransomware
CVE-2015-2419Internet Explorer2022-03-28-
CVE-2016-0189Internet Explorer2022-03-28-
CVE-2017-0059Internet Explorer2022-03-28-
CVE-2013-1347Internet Explorer2022-03-03-
CVE-2013-3897Internet Explorer2022-03-03-
CVE-2017-0222Internet Explorer2022-02-25-
CVE-2019-0752Internet Explorer2022-02-15ransomware
CVE-2014-1776Internet Explorer2022-01-28-
CVE-2018-8653Internet Explorer2021-11-03-
CVE-2019-1367Internet Explorer2021-11-03ransomware
CVE-2019-1429Internet Explorer2021-11-03-
CVE-2020-0674Internet Explorer2021-11-03-
CVE-2020-0968Internet Explorer2021-11-03-
CVE-2020-1380Internet Explorer2021-11-03-
CVE-2021-26411Internet Explorer2021-11-03ransomware
CVE-2021-27085Internet Explorer2021-11-03-

Office: 29 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2009-0238Office2026-04-14-
CVE-2026-21514Office2026-02-10-
CVE-2026-21509Office2026-01-26-
CVE-2009-0556Office2026-01-07-
CVE-2007-0671Office2025-08-12-
CVE-2023-23397Office2023-03-14-
CVE-2023-21715Office2023-02-14-
CVE-2009-0557Office2022-06-08-
CVE-2009-0563Office2022-06-08-
CVE-2013-1331Office2022-06-08-
CVE-2015-1770Office2022-03-28-
CVE-2021-38646Office2022-03-28ransomware
CVE-2010-3333Office2022-03-03-
CVE-2012-1856Office2022-03-03-
CVE-2015-1642Office2022-03-03-
CVE-2015-2545Office2022-03-03-
CVE-2016-7193Office2022-03-03-
CVE-2017-0261Office2022-03-03-
CVE-2017-11826Office2022-03-03-
CVE-2017-8570Office2022-02-25-
CVE-2017-0262Office2022-02-10-
CVE-2021-42292Office2021-11-17-
CVE-2015-1641Office2021-11-03-
CVE-2016-3235Office2021-11-03-
CVE-2017-11774Office2021-11-03-
CVE-2017-11882Office2021-11-03ransomware
CVE-2018-0798Office2021-11-03-
CVE-2018-0802Office2021-11-03-
CVE-2021-27059Office2021-11-03-

Win32k: 25 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2016-0165Win32k2023-06-22-
CVE-2023-29336Win32k2023-05-09-
CVE-2015-2360Win32k2022-05-25-
CVE-2018-8589Win32k2022-05-23-
CVE-2014-4113Win32k2022-05-04-
CVE-2021-40450Win32k2022-04-25-
CVE-2021-41357Win32k2022-04-25-
CVE-2013-3660Win32k2022-03-28-
CVE-2015-2546Win32k2022-03-15ransomware
CVE-2018-8120Win32k2022-03-15ransomware
CVE-2019-1132Win32k2022-03-15-
CVE-2015-1701Win32k2022-03-03ransomware
CVE-2017-0263Win32k2022-02-10-
CVE-2022-21882Win32k2022-02-04-
CVE-2018-8453Win32k2022-01-21ransomware
CVE-2019-1458Win32k2022-01-10ransomware
CVE-2016-0167Win32k2021-11-03ransomware
CVE-2016-7255Win32k2021-11-03-
CVE-2019-0797Win32k2021-11-03-
CVE-2019-0803Win32k2021-11-03-
CVE-2019-0808Win32k2021-11-03-
CVE-2019-0859Win32k2021-11-03-
CVE-2020-1054Win32k2021-11-03-
CVE-2021-1732Win32k2021-11-03ransomware
CVE-2021-28310Win32k2021-11-03-

Exchange Server: 17 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2023-21529Exchange Server2026-04-13ransomware
CVE-2021-31196Exchange Server2024-08-21-
CVE-2024-21410Exchange Server2024-02-15-
CVE-2022-41080Exchange Server2023-01-10ransomware
CVE-2022-41040Exchange Server2022-09-30ransomware
CVE-2022-41082Exchange Server2022-09-30ransomware
CVE-2018-8581Exchange Server2022-03-03ransomware
CVE-2021-33766Exchange Server2022-01-18-
CVE-2020-0688Exchange Server2021-11-03ransomware
CVE-2020-17144Exchange Server2021-11-03-
CVE-2021-26855Exchange Server2021-11-03ransomware
CVE-2021-26857Exchange Server2021-11-03ransomware
CVE-2021-26858Exchange Server2021-11-03ransomware
CVE-2021-27065Exchange Server2021-11-03ransomware
CVE-2021-31207Exchange Server2021-11-03ransomware
CVE-2021-34473Exchange Server2021-11-03ransomware
CVE-2021-34523Exchange Server2021-11-03ransomware

SharePoint: 8 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-50522SharePoint2026-07-22-
CVE-2026-58644SharePoint2026-07-16-
CVE-2026-20963SharePoint2026-03-18-
CVE-2025-49704SharePoint2025-07-22ransomware
CVE-2025-49706SharePoint2025-07-22ransomware
CVE-2025-53770SharePoint2025-07-20ransomware
CVE-2024-38094SharePoint2024-10-22ransomware
CVE-2019-0604SharePoint2021-11-03ransomware

SharePoint Server: 5 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-56164SharePoint Server2026-07-14-
CVE-2026-45659SharePoint Server2026-07-01-
CVE-2026-32201SharePoint Server2026-04-14-
CVE-2023-24955SharePoint Server2024-03-26ransomware
CVE-2023-29357SharePoint Server2024-01-10ransomware

Defender: 5 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-41091Defender2026-05-20-
CVE-2026-45498Defender2026-05-20-
CVE-2026-33825Defender2026-04-22ransomware
CVE-2022-44698Defender2022-12-13ransomware
CVE-2021-1647Defender2021-11-03-

Word: 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2023-36761Word2023-09-12-
CVE-2006-2492Word2022-06-08-
CVE-2012-2539Word2022-03-28-
CVE-2014-1761Word2022-02-15-

Open Management Infrastructure (OMI): 4 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2021-38645Open Management Infrastructure (OMI)2021-11-03-
CVE-2021-38647Open Management Infrastructure (OMI)2021-11-03ransomware
CVE-2021-38648Open Management Infrastructure (OMI)2021-11-03-
CVE-2021-38649Open Management Infrastructure (OMI)2021-11-03-

.NET Framework: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2024-29059.NET Framework2025-02-04-
CVE-2017-8759.NET Framework2021-11-03-
CVE-2020-0646.NET Framework2021-11-03-

Active Directory: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2022-26923Active Directory2022-08-18-
CVE-2021-42278Active Directory2022-04-11ransomware
CVE-2021-42287Active Directory2022-04-11ransomware

Silverlight: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2013-0074Silverlight2022-05-25ransomware
CVE-2013-3896Silverlight2022-05-25-
CVE-2016-0034Silverlight2022-05-25ransomware

Excel: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2009-3129Excel2022-03-03-
CVE-2016-7262Excel2022-03-03-
CVE-2019-1297Excel2022-03-03-

Other Microsoft products

CVEProductAdded to KEVSignals
CVE-2026-56155Active Directory Federation Services2026-07-14-
CVE-2009-1537DirectX2026-05-20-
CVE-2026-42897Microsoft2026-05-15-
CVE-2012-1854Visual Basic for Applications (VBA)2026-04-13-
CVE-2024-43468Configuration Manager2026-02-12-
CVE-2024-49035Partner Center2025-02-25-
CVE-2025-24989Power Pages2025-02-21-
CVE-2024-21413Office Outlook2025-02-06-
CVE-2020-0618SQL Server2024-09-18-
CVE-2024-38226Publisher2024-09-10-
CVE-2024-38189Project2024-08-13-
CVE-2024-30051DWM Core Library2024-05-14ransomware
CVE-2024-29988SmartScreen Prompt2024-04-30-
CVE-2023-29360Streaming Service2024-02-29-
CVE-2023-36563WordPad2023-10-10-
CVE-2023-41763Skype for Business2023-10-10-
CVE-2023-28229Windows CNG Key Isolation Service2023-10-04-
CVE-2023-36802Streaming Service Proxy2023-09-12-
CVE-2023-38180.NET Core and Visual Studio2023-08-09-
CVE-2023-35311Outlook2023-07-11-
CVE-2022-41033Windows COM+ Event System Service2022-10-11-
CVE-2010-2572PowerPoint2022-06-08-
CVE-2012-1889XML Core Services2022-06-08-
CVE-2014-4077Input Method Editor (IME) Japanese2022-05-25-
CVE-2016-3351Internet Explorer and Edge2022-05-24ransomware
CVE-2017-0022XML Core Services2022-05-24-
CVE-2017-0147SMBv1 server2022-05-24ransomware
CVE-2020-0638Update Notification Manager2022-05-23ransomware
CVE-2017-0148SMBv1 server2022-04-06ransomware
CVE-2021-31166HTTP Protocol Stack2022-04-06-
CVE-2011-2005Ancillary Function Driver (afd.sys)2022-03-28-
CVE-2016-0151Client-Server Run-time Subsystem (CSRSS)2022-03-28ransomware
CVE-2016-7200Edge2022-03-28-
CVE-2016-7201Edge2022-03-28-
CVE-2017-0037Edge and Internet Explorer2022-03-28-
CVE-2018-8405DirectX Graphics Kernel (DXGKRNL)2022-03-28ransomware
CVE-2018-8406DirectX Graphics Kernel (DXGKRNL)2022-03-28ransomware
CVE-2014-6324Kerberos Key Distribution Center (KDC)2022-03-25-
CVE-2018-8373Internet Explorer Scripting Engine2022-03-25-
CVE-2019-0903Graphics Device Interface (GDI)2022-03-25-
CVE-2019-1069Task Scheduler2022-03-15ransomware
CVE-2011-1889Forefront Threat Management Gateway (TMG)2022-03-03-
CVE-2015-2387ATM Font Driver2022-03-03-
CVE-2015-2424PowerPoint2022-03-03-
CVE-2017-0001Graphics Device Interface (GDI)2022-03-03-
CVE-2017-8540Malware Protection Engine2022-03-03-
CVE-2013-3906Graphics Component2022-02-15-
CVE-2015-1635HTTP.sys2022-02-10-
CVE-2017-0144SMBv12022-02-10ransomware
CVE-2017-0145SMBv12022-02-10ransomware
CVE-2020-0796SMBv32022-02-10ransomware
CVE-2013-3900WinVerifyTrust function2022-01-10-
CVE-2021-42321Exchange2021-11-17ransomware
CVE-2012-0158MSCOMCTL.OCX2021-11-03-
CVE-2017-0199Office and WordPad2021-11-03ransomware
CVE-2017-7269Internet Information Services (IIS)2021-11-03-
CVE-2019-0541MSHTML2021-11-03-
CVE-2019-0708Remote Desktop Services2021-11-03ransomware
CVE-2020-0878Edge and Internet Explorer2021-11-03ransomware
CVE-2020-1040Hyper-V RemoteFX2021-11-03-
CVE-2020-1147.NET Framework, SharePoint, Visual Studio2021-11-03-
CVE-2020-1472Netlogon2021-11-03ransomware
CVE-2021-31199Enhanced Cryptographic Provider2021-11-03-
CVE-2021-31201Enhanced Cryptographic Provider2021-11-03-
CVE-2021-40444MSHTML2021-11-03ransomware

Common questions about exploited Microsoft CVEs

Which Microsoft vulnerabilities are actively exploited?

As of July 2026, 382 Microsoft CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Windows (172), Internet Explorer (36), Office (29), Win32k (25). 104 are linked to ransomware campaigns.

What is the newest exploited Microsoft CVE?

CVE-2026-50522, affecting SharePoint, added to the CISA KEV catalog on 2026-07-22. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Microsoft CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. For Microsoft entries, each CVE links to its page with the fixing KB, and Senserva can report which of them are actually missing on your own devices.

Can I ask my own AI about exploited Microsoft CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Microsoft KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

Check your own tenant free with Siemserva by Senserva

This page shows the fix. Siemserva by Senserva shows which of your devices are still missing it: which ones are exposed to CVE-2026-50522, for example, ranked by what attackers actually exploit.

  • Patch status in one scan: which devices are affected, which are not
  • Missing updates ranked by CISA KEV and EPSS, so you fix the right things first
  • Data from Intune, Microsoft Defender, Windows Autopatch, and Azure Update Manager, with more sources on the way
  • Third-party app patching too: updates published to Intune by PatchMyPC, Scappman, Robopack, or any vendor, read vendor-neutrally
  • Optional AI Enhanced Reporting: plain-language summaries and recommended next steps written into your reports
  • Then go further: 650+ security checks find the drift detection misses your last hardening pass left behind, with compliance evidence and Senserva Trustworthy AI remediation
Senserva patching for Microsoft 365
Two minutes, click to play

Patching in action in two minutes. Watch page · All videos.

3 actively exploited CVEs are unmitigated on devices in this tenant, per CISA KEV.View fix-first list ↓
312
Devices scanned
Intune + Autopatch + Defender
3
Exploited updates missing
CISA KEV, unmitigated
905
Microsoft updates tracked
Refreshed daily, MSRC + NVD
650+
Security checks in scan
Patch, config, identity, logs

Triage order for this list

Same order in the dashboard, the report, and every AI answer
1st · overrides everything
Actively exploited (KEV)
e.g. KB5040219, CVE-2026-31210
2nd · tiebreaker
Severity (Critical → Low)
MSRC + EPSS probability
3rd · tiebreaker
Days waiting
Oldest unresolved first

Ranked missing updates, fix-first order

27 findings · showing top 2
#UpdateCVESeveritySourceDevicesWaiting
1KB5040219
Windows 11 23H2 cumulative
CVE-2026-31210
KEV EPSS 0.94
CriticalDefender4119 daysAdd to fix-first
2KB5040088
.NET Framework security update
CVE-2026-29981
KEV
CriticalIntune1712 daysAdd to fix-first
Estimated dashboard, sample data for illustration

Ask Senserva

via Claude + MCP
Which devices are still missing the fix for CVE-2026-31210?
41 devices are missing KB5040219, which resolves CVE-2026-31210. This CVE is on CISA KEV, so CISA BOD 22-01 calls for remediation within 14 days. You are at 19 days and counting.
source: scan_db · defender_posture · kev_join, not model memory
Get Devices Found Get Devices Missing
Senserva is a Microsoft Intelligent Security Association member. Get Going with Senserva Senserva patching Built for IT admins and security teams, with audit-ready data for compliance.
Lexicon: the terms on this page
CVE
Common Vulnerabilities and Exposures. A unique ID for one publicly known vulnerability, such as CVE-2025-1234.
KB
Microsoft Knowledge Base article. The identifier for a specific Microsoft update.
KEV
CISA Known Exploited Vulnerabilities. CVEs confirmed exploited in the wild. Fix these first.
CVSS
Common Vulnerability Scoring System. A standardized Severity score from 0 to 10.
EPSS
Exploit Prediction Scoring System. The probability a CVE will be exploited in the next 30 days.
MSRC
Microsoft Security Response Center. Microsoft's Patch Tuesday advisories and KB-to-CVE mapping.
NVD
National Vulnerability Database (NIST). Authoritative CVE metadata and CVSS scores.
Ransomware
The vulnerability is linked to known ransomware activity.
Reference: Microsoft CVE and vulnerability management, the full CVE-to-patch lookup ranked by real-world risk, and the Microsoft patching guide, how Intune, Windows Autopatch, Defender, and Azure Update Manager fit together.
Data notice: this page, the feeds, and the API are provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative vendor advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.