Microsoft Uses LLMs for vuln discovery
CPE vendor key: microsoft ·
6,034 CVEs published in the last 24 months.
CVEs (365 d)
4,117
▼ -320 vs prior 30d
Avg CVSS (365 d)
7.31
over 4,117 CVEs
Avg EPSS pct (365 d)
0.29
higher = more likely exploited
KEV hit rate (365 d)
0.9%
38 of 4,117 added to CISA KEV
LLM-credited CVEs
204
Openai 204
Monthly CVE volume — last 24 months
Each point is one calendar month. Bars in the
severity card to the right slice the same volume by CVSS band.
Severity mix
Stacked by CVSS band (Critical / High / Medium /
Low) using the best available metric per CVE.
Top affected products (24 mo)
2,468
1,922
1,900
1,853
1,772
1,674
1,663
1,626
1,497
1,448
Distinct CVEs that include each product in their
CPE configuration.
Top CWEs (24 mo)
1,110
668
531
324
292
272
207
153
142
137
Distinct CVEs assigned each weakness.
Recent CISA KEV adds (last 12 months)
| Added | CVE | Product | KEV name |
|---|---|---|---|
| 2026-08-18 | CVE-2026-55040 | SharePoint | Microsoft SharePoint Weak Authentication Vulnerability |
| 2026-08-18 | CVE-2026-33824 | Internet Key Exchange (IKE) Service Extensions | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability |
| 2026-08-11 | CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability |
| 2026-07-22 | CVE-2026-50522 | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
| 2026-07-16 | CVE-2026-58644 | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
| 2026-07-14 | CVE-2026-56164 | SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability |
| 2026-07-14 | CVE-2026-56155 | Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability |
| 2026-07-01 | CVE-2026-45659 | SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability |
| 2026-05-20 | CVE-2026-45498 | Defender | Microsoft Defender Denial of Service Vulnerability |
| 2026-05-20 | CVE-2026-41091 | Defender | Microsoft Defender Link Following Vulnerability |
| 2026-05-20 | CVE-2010-0806 | Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability |
| 2026-05-20 | CVE-2010-0249 | Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability |
| 2026-05-20 | CVE-2009-1537 | DirectX | Microsoft DirectX NULL Byte Overwrite Vulnerability |
| 2026-05-20 | CVE-2008-4250 | Windows | Microsoft Windows Buffer Overflow Vulnerability |
| 2026-05-15 | CVE-2026-42897 | Microsoft | Microsoft Exchange Server Cross-Site Scripting Vulnerability |
| 2026-04-28 | CVE-2026-32202 | Windows | Microsoft Windows Protection Mechanism Failure Vulnerability |
| 2026-04-22 | CVE-2026-33825 | Defender | Microsoft Defender Insufficient Granularity of Access Control Vulnerability |
| 2026-04-14 | CVE-2026-32201 | SharePoint Server | Microsoft SharePoint Server Improper Input Validation Vulnerability |
| 2026-04-14 | CVE-2009-0238 | Office | Microsoft Office Remote Code Execution |
| 2026-04-13 | CVE-2025-60710 | Windows | Microsoft Windows Link Following Vulnerability |
| 2026-04-13 | CVE-2023-36424 | Windows | Microsoft Windows Out-of-Bounds Read Vulnerability |
| 2026-04-13 | CVE-2023-21529 | Exchange Server | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability |
| 2026-04-13 | CVE-2012-1854 | Visual Basic for Applications (VBA) | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability |
| 2026-03-18 | CVE-2026-20963 | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
| 2026-02-17 | CVE-2008-0015 | Windows | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability |
| 2026-02-12 | CVE-2024-43468 | Configuration Manager | Microsoft Configuration Manager SQL Injection Vulnerability |
| 2026-02-10 | CVE-2026-21533 | Windows | Microsoft Windows Improper Privilege Management Vulnerability |
| 2026-02-10 | CVE-2026-21525 | Windows | Microsoft Windows NULL Pointer Dereference Vulnerability |
| 2026-02-10 | CVE-2026-21519 | Windows | Microsoft Windows Type Confusion Vulnerability |
| 2026-02-10 | CVE-2026-21514 | Office | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability |
| 2026-02-10 | CVE-2026-21513 | Windows | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability |
| 2026-02-10 | CVE-2026-21510 | Windows | Microsoft Windows Shell Protection Mechanism Failure Vulnerability |
| 2026-01-26 | CVE-2026-21509 | Office | Microsoft Office Security Feature Bypass Vulnerability |
| 2026-01-13 | CVE-2026-20805 | Windows | Microsoft Windows Information Disclosure Vulnerability |
| 2026-01-07 | CVE-2009-0556 | Office | Microsoft Office PowerPoint Code Injection Vulnerability |
| 2025-12-09 | CVE-2025-62221 | Windows | Microsoft Windows Use After Free Vulnerability |
| 2025-11-12 | CVE-2025-62215 | Windows | Microsoft Windows Race Condition Vulnerability |
| 2025-10-24 | CVE-2025-59287 | Windows | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability |
| 2025-10-20 | CVE-2025-33073 | Windows | Microsoft Windows SMB Client Improper Access Control Vulnerability |
| 2025-10-14 | CVE-2025-59230 | Windows | Microsoft Windows Improper Access Control Vulnerability |
| 2025-10-14 | CVE-2025-24990 | Windows | Microsoft Windows Untrusted Pointer Dereference Vulnerability |
| 2025-10-06 | CVE-2021-43226 | Windows | Microsoft Windows Privilege Escalation Vulnerability |
| 2025-10-06 | CVE-2013-3918 | Windows | Microsoft Windows Out-of-Bounds Write Vulnerability |
| 2025-10-06 | CVE-2011-3402 | Windows | Microsoft Windows Remote Code Execution Vulnerability |
| 2025-10-06 | CVE-2010-3962 | Internet Explorer | Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability |
Filtered to KEV entries whose CISA vendor or product name matches this
vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps
that CPE-map to Microsoft).
LLM-credited CVEs from this vendor
| Published | CVE | LLM family | Model(s) |
|---|---|---|---|
| 2026-08-18 | CVE-2026-76037 | openai | OpenAI |
| 2026-08-06 | CVE-2026-19171 | openai | OpenAI |
| 2026-08-06 | CVE-2026-19163 | openai | OpenAI |
| 2026-08-06 | CVE-2026-19158 | openai | OpenAI |
| 2026-08-06 | CVE-2026-19139 | openai | OpenAI |
| 2026-07-01 | CVE-2026-14402 | openai | OpenAI |
| 2026-07-01 | CVE-2026-14391 | openai | OpenAI |
| 2026-07-01 | CVE-2026-14384 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14154 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14153 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14148 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14144 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14139 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14138 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14125 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14124 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14122 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14119 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14117 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14115 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14113 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14112 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14111 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14108 | openai | OpenAI |
| 2026-06-30 | CVE-2026-14107 | openai | OpenAI |
From
mythos_attributed_cves: CVEs whose NVD description
or vendor advisory credits an LLM-assisted discovery. Confidence is
high for every row.
Generated 23 August 2026 00:24 UTC .