KEV 2016
59 CISA Known Exploited Vulnerabilities from 2016
Critical 13
October 2025
July 2025
January 2024
May 2023
Oracle Java SE and JRockit — Unauthenticated Remote Code Execution via Java Management Extensions (JMX); CVSS 9.8; Patched Oracle CPU April 2016
CVSS 9.8Apache Tomcat — JmxRemoteLifecycleListener Inherits Oracle JMX Deserialization Flaw (CVE-2016-3427); Unauthenticated RCE via Exposed JMX Ports; Patched Tomcat 7.0.73 / 8.0.38 / 8.5.6
CVSS 9.8June 2022
March 2022
NETGEAR WNR2000v5 — Unauthenticated Buffer Overflow in Web Management Timestamp Parameter Enables Remote Code Execution; Botnet Recruitment Target
CVSS 9.8NETGEAR Wireless Access Points — Unauthenticated Form Input Passed Directly to CLI Enables Remote OS Command Injection on Multiple WAP Models
CVSS 9.8Adobe Flash Player — Unspecified Type Confusion Zero-Day Exploited In-the-Wild Before Patch; Emergency APSB16-18 (June 2016)
CVSS 9.8Adobe Flash Player — Zero-Day Heap Overflow Exploited by Magnitude/Nuclear Kits for Cerber Ransomware; Emergency APSB16-10 (April 2016); Ransomware Use Confirmed
CVSS 9.8Adobe Flash Player — Type Confusion Zero-Day Exploited In-the-Wild Before Patch; CVSS 9.8 / UI:N; Emergency APSB16-15 (May 2016)
CVSS 9.8February 2022
November 2021
High 38
September 2024
June 2023
Microsoft Win32k.sys — Kernel-Mode Driver LPE Enables SYSTEM Access via Crafted Application; Patched MS16-039 (April 2016)
CVSS 7.8Firefox / Tor Browser — SVG Animation Use-After-Free Exploited to De-Anonymize Tor Users on Windows; MFSA2016-92 (November 2016)
CVSS 7.5May 2023
June 2022
Chromium V8 Engine — Out-of-Bounds Array Read in JavaScript Enables RCE in Chrome Renderer; Fixed Chrome 49.0.2623.108 (March 2016)
CVSS 8.8Google Chromium V8 — Out-of-Bounds Read/Write via Crafted HTML Page Enables Remote Code Execution in Chrome Renderer; Patched Chrome 54.0.2840.100 (November 2016)
CVSS 8.8May 2022
Microsoft Silverlight — Negative Offset Decoding Error Enables RCE via Crafted Media; Angler Exploit Kit Delivery; Ransomware Use Confirmed; Patched MS16-006 (January 2016)
CVSS 8.8Adobe Flash Player and AIR — Use-After-Free Enables Heap-Based RCE via Crafted SWF; Exploit Kit Target in Early 2016; Patched APSB16-04 (February 2016)
CVSS 8.8Adobe Flash Player and AIR — Integer Overflow Leads to Heap Corruption and RCE via Crafted SWF; Exploit Kit Vector in 2016; Patched APSB16-08 (March 2016)
CVSS 8.8Windows Font Library — Malformed OpenType Font in Web Page or Document Triggers Memory Corruption Enabling RCE; Patched MS16-132 (November 2016)
CVSS 8.8Apple iOS WebKit — Memory Corruption via Crafted Web Page Enables Remote Code Execution; Stage 1 Entry Point of 'Trident' Pegasus Chain; Patched iOS 9.3.5 (August 2016)
CVSS 8.8Cisco ASA — SNMP Packet Processing Buffer Overflow Enables RCE or DoS; 'ExtraBacon' Shadow Brokers Leak; Patched cisco-sa-20160817-asa-snmp (August 2016)
CVSS 8.8Microsoft Windows GDI — Memory Object Handling Flaw Enables Code Execution via Crafted Document or Malicious Web Page; Patched MS16-120 (October 2016)
CVSS 7.8Apple iOS Kernel — Memory Corruption Enables Full Kernel Control / Jailbreak; Stage 3 of 'Trident' Pegasus Chain; Patched iOS 9.3.5 (August 2016)
CVSS 7.8Cisco ASA — Authenticated CLI Parser Buffer Overflow Enables Local Privilege Escalation or Code Execution; Companion to ExtraBacon (CVE-2016-6366); Patched August 2016
CVSS 7.8April 2022
March 2022
Microsoft Edge Chakra — Out-of-Bounds Write in JavaScript Engine Enables Remote Code Execution via Malicious Web Page; Patched MS16-145 (November 2016)
CVSS 8.8Microsoft Edge Chakra — Type Confusion in JavaScript Engine Enables Remote Code Execution via Malicious Web Page; Patched MS16-145 (November 2016)
CVSS 8.8Adobe Flash Player — TextField Class Use-After-Free Enables Remote Code Execution via Malicious Web Content; Patched APSB16-39 (December 2016)
CVSS 8.8NETGEAR R7000/R6400 and Others — Web Interface Command Injection via CSRF Enables Unauthenticated RCE on Home/SMB Routers; Widely Exploited by Botnets
CVSS 8.8Adobe Flash Player — Use-After-Free Zero-Day Exploited in Targeted Attacks Before Patch; Emergency APSB16-37 (October 2016)
CVSS 8.8Microsoft Windows Kernel — Local Privilege Escalation to SYSTEM via Crafted Application; Patched MS16-014 (February 2016)
CVSS 7.8Windows CSRSS — Process Token Mismanagement Enables Privilege Escalation; Ransomware Use Confirmed; Patched MS16-048 (April 2016)
CVSS 7.8Microsoft Windows — Kernel Object Handling Flaw Enables Local Privilege Escalation to SYSTEM; Exploited in Ransomware Chains; Patched MS16-098 (August 2016)
CVSS 7.8Windows Secondary Logon Service — Handle Management Flaw Enables LPE to SYSTEM; Widely Used by Ransomware Operators; Patched MS16-032 (March 2016)
CVSS 7.8Microsoft Word — RTF File Format Memory Corruption Enables Remote Code Execution via Malicious Document; Patched MS16-121 (October 2016)
CVSS 7.8Microsoft Excel — Security Feature Bypass via Malformed File Enables Arbitrary Command Execution Without Macro Prompts; Patched MS16-148 (December 2016)
CVSS 7.8Internet Explorer JScript/VBScript — Scripting Engine Memory Corruption Enables RCE via Crafted Web Page; Targeted APT Exploitation; Patched MS16-051 (May 2016)
CVSS 7.5Ruby on Rails Action View — render :file Path Traversal Allows Unauthenticated Arbitrary File Read; Fixed Rails 3.2.22.2 / 4.x / 5.0 (January 2016)
CVSS 7.5Siemens SIMATIC CP 1543-1 — Industrial Ethernet Communications Processor Allows Authenticated Low-Privilege Remote Denial of Service; Patched via Firmware Update
CVSS 7.5D-Link DCS-930L Network Camera — setSystemCommand Function Allows Authenticated Admin OS Command Injection; End-of-Life Device with No Patch Available
CVSS 7.2Linux Kernel 'Dirty COW' — Copy-on-Write Race Condition Permits Unprivileged Write to Read-Only Memory-Mapped Files
CVSS 7November 2021
Microsoft Win32k.sys — Zero-Day LPE Used in Dridex Campaigns; Ransomware Use Confirmed; Inaugural CISA KEV; Patched MS16-039 (April 2016)
CVSS 7.8Windows Media Center — Crafted .MCL File References Malicious Code Enabling RCE; Inaugural CISA KEV; Patched MS16-059 (May 2016)
CVSS 7.8Microsoft Office — OLE Component Loads Attacker-Controlled DLL from Current Working Directory; Enables Code Execution via Malicious Document on Network Share or Removable Media
CVSS 7.8SolarWinds Virtualization Manager — Misconfigured sudo Permissions Allow Low-Privilege User to Execute Arbitrary Commands as Root; Patched 2016
CVSS 7.8Microsoft Win32k — Kernel UAF in Win32k.sys Enables Local Privilege Escalation; APT28 Zero-Day in Active Exploitation Before Patch; Patched MS16-135 (November 2016)
CVSS 7.8SAP NetWeaver AS JAVA — Unauthenticated Path Traversal in CrashFileDownloadServlet via fileName Parameter Enables Arbitrary File Read Including SAP Configuration and Credentials
CVSS 7.5Medium 8
June 2022
May 2022
Microsoft Internet Explorer — Internet Messaging API Memory Handling Flaw Enables Remote File Presence Detection; ASLR Bypass Enabler; Patched MS16-126 (October 2016)
CVSS 6.5Microsoft Internet Explorer and Edge — Memory Object Handling Flaw Enables Remote Detection of Local Files; Used in Ransomware Exploit Chains as ASLR Bypass; Patched MS16-104/MS16-105 (September 2016)
CVSS 6.5Apple iOS Kernel — Memory Information Disclosure Enabling KASLR Bypass; Part of 'Trident' Three-Zero-Day Pegasus Spyware Chain; Patched iOS 9.3.5 (August 2016)
CVSS 5.5Microsoft Internet Explorer — JavaScript Handling Flaw Allows Remote Detection of Local Files; ASLR Bypass Enabler in Exploit Chains; Patched MS16-037 (April 2016)
CVSS 4.3November 2021
SAP NetWeaver AS Java — Authenticated XXE in BC-BMT-BPM-DSK Component Enables Server-Side File Disclosure and SSRF; SAP Security Note 2380729
CVSS 6.5ImageMagick — EPHEMERAL Pseudo-Protocol Deletes Arbitrary Files After Reading; Part of ImageTragick CVE Cluster; Patched ImageMagick 6.9.3-10 (May 2016)
CVSS 5.5ImageMagick — HTTP/FTP Coder Fetches Attacker-Controlled URLs Without Restriction; Part of ImageTragick CVE Cluster; Enables Internal Network Scanning via Image Processing
CVSS 5.5