Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Top 20 Most Exploited Vulnerabilities: Microsoft Products Draw Hackers

In the current cybersecurity landscape, identifying and addressing open vulnerabilities is a critical task for security teams. Highlighting high-risk CVEs that are actively exploited by threat actors is essential for maintaining security.

In the current cybersecurity landscape, identifying and addressing open vulnerabilities is a critical task for security teams. Highlighting high-risk CVEs that are actively exploited by threat actors is essential for maintaining security.

Research from Qualys has identified the top 20 most exploited vulnerabilities, with a significant focus on Microsoft products. These findings are also reflected in the CISA Joint Cybersecurity Advisory (CSA) dated Thu, Aug 3, 2023.

CVE-2017-11882

Description: Microsoft Office Memory Corruption Vulnerability Trending: 2018, 2020, 2021, 2022, 2023 (79 times) Qualys ID: 110308

CVE-2017-0199

Description: Microsoft Wordpad Remote Code Execution Vulnerability Trending: 2017, 2020, 2021, 2023 (59 times) Qualys ID: 110297

CVE-2012-0158

Description: Vulnerability in Windows Common Controls Could Allow RCE Trending: 2013, 2020, 2021, 2023 (33 times) Qualys ID: 90793

CVE-2017-8570

Description: Microsoft Office Remote Code Execution Vulnerability Trending: 2018, 2020, 2023 (25 times) Qualys ID: 110300

CVE-2020-1472

Description: Zerologon – An Unauthenticated Privilege Escalation to Full Domain Privileges Trending: 2020, 2021, 2022, 2023 (56 times) Qualys ID: 91680

CVE-2017-0144 , CVE-2017-0145 , CVE-2017-0143

Description: Windows SMBv1 Remote Code Execution Vulnerability (WannaCry, Petya) Trending: 2017, 2020, 2021, 2023 (50 times) Qualys ID: 91361, 91360, 91359, 91345

CVE-2012-1723

Description: Java Applet Field Bytecode Verifier Cache Remote Code Execution Trending: 2023 (6 times) Qualys ID: 120274

In the current cybersecurity landscape, identifying and addressing open vulnerabilities is a critical task for security teams.
Noah Redmond · Thehackingpost

CVE-2021-34473 , CVE-2021-34523 , CVE-2021-31207

Description: Microsoft Exchange Server RCE (ProxyShell) Trending: 2021, 2022, 2023 (39 times) Qualys ID: 50114, 50111, 50112

CVE-2019-11510

Description: Pulse Secure Pulse Connect Secure SSL VPN Unauthenticated Path Trending: 2019, 2020, 2023 (53 times) Qualys ID: 38771

CVE-2021-44228

Description: Apache Log4j Remote Code Execution Vulnerability Trending: 2021, 2022, 2023 (77 times) Qualys ID: 376157, 730297

CVE-2014-6271

Description: Shellshock – Linux Bash Vulnerability Trending: 2014, 2016, 2017, 2020, 2021, 2022, 2023 (70 times) Qualys ID: 122693, 13038, 150134

CVE-2018-8174

Description: Windows VBScript Engine Remote Code Execution Vulnerability Trending: 2018, 2020, 2023 (30 times) Qualys ID: 91447

CVE-2013-0074

Description: Microsoft Silverlight Could Allow Remote Code Execution Trending: 2023 (8 times) Qualys ID: 90870

Advertisement

CVE-2012-0507

Description: Oracle Java SE Remote Java Runtime Environment Vulnerability Trending: 2023 (10 times) Qualys ID: 119956

CVE-2019-19781

Description: Citrix ADC and Citrix Gateway – Remote Code Execution (RCE) Vulnerability Trending: 2020, 2022, 2023 (60 times) Qualys ID: 372305, 150273

CVE-2018-0802

Description: Microsoft Office Memory Corruption Vulnerability Trending: 2021, 2022, 2023 (19 times) Qualys ID: 110310

CVE-2021-26855

Description: Microsoft Exchange Server Authentication Bypass (RCE) Trending: 2021, 2023 (46 times) Qualys ID: 50107, 50108

CVE-2019-2725

Description: Oracle WebLogic Affected by Unauthenticated RCE Vulnerability Trending: 2019, 2020, 2022, 2023 (53 times) Qualys ID: 150267, 87386

CVE-2018-13379

Description: Fortinet FortiGate (FortiOS) System File Leak through SSL Trending: 2020, 2021, 2023 (41 times) Qualys ID: 43702

CVE-2021-26084

Description: Atlassian Confluence Server Webwork OGNL Injection RCE Vulnerability Trending: 2021, 2022, 2023 (35 times) Qualys ID: 730172, 150368, 375839

Security analysts at Qualys recommend that users promptly identify assets vulnerable to these top CVEs and prioritize remediation. Utilizing Qualys Patch can effectively reduce risk. Additionally, leveraging Qualys VMDR's dynamic Threat Intelligence is advised to streamline the prioritization of high-risk vulnerabilities.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories