Skip to main content
Griffin Technology PartnersGTP

Public security advisories

GTP Security Intelligence

Current vulnerabilities, known exploitation, Microsoft security updates, and practical guidance from Griffin Technology Partners.

Primary sources

Microsoft Security Response Center
CISA Known Exploited Vulnerabilities

Subscribe via RSS

Vulnerability intelligence

Security bulletins

Last collection: October 9, 2026
Six-hour refresh · Public-source information only

494 bulletins · Page 6 of 21

JSON feed
Severity not suppliedKnown exploited
CVE-2010-0806Microsoft

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Internet Explorer

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2009-0238Microsoft

Microsoft Office Remote Code Execution

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Office

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2008-0015Microsoft

Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2024-43468Microsoft

Microsoft Configuration Manager SQL Injection Vulnerability

Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Configuration Manager

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2026-21509Microsoft

Microsoft Office Security Feature Bypass Vulnerability

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Office

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2009-0556Microsoft

Microsoft Office PowerPoint Code Injection Vulnerability

Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Office

Added to CISA KEV

Sources & coverage

The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.

Microsoft Security Response Center (opens in a new tab)

Last successful check: October 9, 2026

CISA Known Exploited Vulnerabilities (opens in a new tab)

Last successful check: October 9, 2026

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.