Skip to main content
Griffin Technology PartnersGTP

Public security advisories

GTP Security Intelligence

Current vulnerabilities, known exploitation, Microsoft security updates, and practical guidance from Griffin Technology Partners.

Primary sources

Microsoft Security Response Center
CISA Known Exploited Vulnerabilities

Subscribe via RSS

Vulnerability intelligence

Security bulletins

Last collection: October 9, 2026
Six-hour refresh · Public-source information only

494 bulletins · Page 8 of 21

JSON feed
Severity not suppliedKnown exploited
CVE-2025-24984Microsoft

Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2018-8639Microsoft

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2025-21391Microsoft

Microsoft Windows Storage Link Following Vulnerability

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2025-21418Microsoft

Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2024-21413Microsoft

Microsoft Outlook Improper Input Validation Vulnerability

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Office Outlook

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2024-43451Microsoft

Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2024-49039Microsoft

Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Windows

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2020-0618Microsoft

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: SQL Server

Added to CISA KEV

Sources & coverage

The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.

Microsoft Security Response Center (opens in a new tab)

Last successful check: October 9, 2026

CISA Known Exploited Vulnerabilities (opens in a new tab)

Last successful check: October 9, 2026

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.