Microsoft
CVE-2024-43468: Configuration Manager unauthenticated SQL injectionNew!!
CISA lists CVE-2024-43468 as exploited. TechGeeks action notice for Configuration Manager unauthenticated SQL injection, with scope, remediation, investigation guidance, and official sources.
CVE-2026-20963: SharePoint unauthenticated deserialization RCENew!!
CISA lists CVE-2026-20963 as exploited. TechGeeks action notice for SharePoint unauthenticated deserialization RCE, with scope, remediation, investigation guidance, and official sources.
CVE-2026-32201: SharePoint unauthenticated spoofing vulnerabilityNew!!
CISA lists CVE-2026-32201 as exploited. TechGeeks action notice for SharePoint unauthenticated spoofing vulnerability, with scope, remediation, investigation guidance, and official sources.
CVE-2009-0238: Legacy Microsoft Excel file remote code executionNew!!
CISA lists CVE-2009-0238 as exploited. TechGeeks action notice for Legacy Microsoft Excel file remote code execution, with scope, remediation, investigation guidance, and official sources.
CVE-2025-60710: Windows link-following privilege escalationNew!!
CISA lists CVE-2025-60710 as exploited. TechGeeks action notice for Windows link-following privilege escalation, with scope, remediation, investigation guidance, and official sources.
CVE-2023-36424: Windows Common Log File System privilege escalationNew!!
CISA lists CVE-2023-36424 as exploited. TechGeeks action notice for Windows Common Log File System privilege escalation, with scope, remediation, investigation guidance, and official sources.
CVE-2023-21529: Exchange Server authenticated deserialization RCENew!!
CISA lists CVE-2023-21529 as exploited. TechGeeks action notice for Exchange Server authenticated deserialization RCE, with scope, remediation, investigation guidance, and official sources.
CVE-2012-1854: Legacy VBA insecure library loading RCENew!!
CISA lists CVE-2012-1854 as exploited. TechGeeks action notice for Legacy VBA insecure library loading RCE, with scope, remediation, investigation guidance, and official sources.
CVE-2026-33825: Microsoft Defender local privilege escalationNew!!
CISA lists CVE-2026-33825 as exploited. TechGeeks action notice for Microsoft Defender local privilege escalation, with scope, remediation, investigation guidance, and official sources.
CVE-2026-42897: Exchange Outlook Web Access cross-site scriptingNew!!
CISA lists CVE-2026-42897 as exploited. TechGeeks action notice for Exchange Outlook Web Access cross-site scripting, with scope, remediation, investigation guidance, and official sources.
