Skip to main content
Griffin Technology PartnersGTP

Public security advisories

GTP Security Intelligence

Current vulnerabilities, known exploitation, Microsoft security updates, and practical guidance from Griffin Technology Partners.

Primary sources

Microsoft Security Response Center
CISA Known Exploited Vulnerabilities

Subscribe via RSS

Vulnerability intelligence

Security bulletins

Last collection: October 9, 2026
Six-hour refresh · Public-source information only

494 bulletins · Page 19 of 21

JSON feed
Severity not suppliedKnown exploited
CVE-2019-0604Microsoft

Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: SharePoint

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2019-0708Microsoft

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Remote Desktop Services

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2019-0797Microsoft

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Win32k

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2019-0803Microsoft

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Win32k

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2019-0808Microsoft

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Win32k

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2019-1215Microsoft

Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2019-1367Microsoft

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Internet Explorer

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-0601Microsoft

Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-0674Microsoft

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Internet Explorer

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-0938Microsoft

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-1020Microsoft

Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-1040Microsoft

Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Hyper-V RemoteFX

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-1054Microsoft

Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Win32k

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-1147Microsoft

Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: .NET Framework, SharePoint, Visual Studio

Added to CISA KEV

Sources & coverage

The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.

Microsoft Security Response Center (opens in a new tab)

Last successful check: October 9, 2026

CISA Known Exploited Vulnerabilities (opens in a new tab)

Last successful check: October 9, 2026

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.