Historical snapshot · Cybersecurity

CISA Exploited Vulnerabilities

Vulnerabilities with evidence of exploitation, including affected products and required actions.

This page is an archived snapshot of the CISA Exploited Vulnerabilities feed collected on Oct 2, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
1731 recordsOfficial source · JSON
CVE-2021-31956 · CISA Known Exploited Vulnerabilities

Microsoft Windows NTFS Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-31201 · CISA Known Exploited Vulnerabilities

Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Enhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-31979 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-0938 · CISA Known Exploited Vulnerabilities

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-17144 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0986 · CISA Known Exploited Vulnerabilities

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in kernel mode. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-1020 · CISA Known Exploited Vulnerabilities

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-38645 · CISA Known Exploited Vulnerabilities

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-34523 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2017-7269 · CISA Known Exploited Vulnerabilities

Microsoft Windows Server Buffer Overflow Vulnerability

Vendor: Microsoft | Product: Internet Information Services (IIS) | Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If:
CVE-2021-36948 · CISA Known Exploited Vulnerabilities

Microsoft Windows Update Medic Service Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-38649 · CISA Known Exploited Vulnerabilities

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Open Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-0688 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2016-7255 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-0708 · CISA Known Exploited Vulnerabilities

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Remote Desktop Services | Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. | Required…
Read full source summary
Vendor: Microsoft | Product: Remote Desktop Services | Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-34473 · CISA Known Exploited Vulnerabilities

Microsoft Exchange Server Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-1464 · CISA Known Exploited Vulnerabilities

Microsoft Windows Spoofing Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-1732 · CISA Known Exploited Vulnerabilities

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-34527 · CISA Known Exploited Vulnerabilities

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. | Required action: Apply updates per vendor…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
Browse saved snapshots

Sources & context

About these feeds

About BioThreat Corporation

BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.

01 / SOURCE

Read the source

Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.

Browse public feeds
02 / HISTORY

Compare over time

Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.

Browse saved snapshots
03 / RECORDS

Use the records

JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.

Archive sitemap

The BioThreat Corporation Library brings together research, analysis, and reference material across our areas of focus.

Live feed index