Microsoft Corporation
Self-Reporting Analysis
Of all the CVEs published by Microsoft Corporation as a CNA, 99.6% affect products that Microsoft Corporation develops as a vendor.
Of all the CVEs published that affect products developed by Microsoft Corporation, 50.6% are self-published by Microsoft Corporation as a CNA.
Trends Over Time
The number and severity of CVEs published by Microsoft Corporation over time
Top CVEs
All CVEs published by Microsoft Corporation as a CNA, regardless of affected vendor or product.
12,990 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59287CRITICAL Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | Oct 14, 2025 | 9.8 | 99 | YES | YES |
CVE-2025-53770CRITICAL Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for | Jul 20, 2025 | 9.8 | 99 | YES | YES |
CVE-2021-26855CRITICAL Microsoft Exchange Server Remote Code Execution Vulnerability | Mar 3, 2021 | 9.8 | 99 | YES | YES |
CVE-2020-1472CRITICAL An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protoc | Aug 17, 2020 | 10.0 | 99 | YES | YES |
CVE-2020-0796CRITICAL A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Re | Mar 12, 2020 | 10.0 | 99 | YES | YES |
CVE-2020-0618HIGH A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remo | Feb 11, 2020 | 8.8 | 99 | YES | YES |
CVE-2020-0646CRITICAL A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. | Jan 14, 2020 | 9.8 | 99 | YES | YES |
CVE-2019-0708CRITICAL A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP | May 16, 2019 | 9.8 | 99 | YES | YES |
CVE-2015-1635CRITICAL HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via c | Apr 14, 2015 | 9.8 | 99 | YES | YES |
CVE-2025-49706MEDIUM Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Jul 8, 2025 | 6.5 | 98 | YES | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (12990 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Microsoft Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Microsoft Corporation as a CNA — matched by CVE ID, not by organization name.