KEV 2016

59 CISA Known Exploited Vulnerabilities from 2016

Critical 13

October 2025

July 2025

January 2024

May 2023

June 2022

March 2022

February 2022

November 2021

High 38

September 2024

June 2023

May 2023

June 2022

May 2022

CVE-2016-0034

Microsoft Silverlight — Negative Offset Decoding Error Enables RCE via Crafted Media; Angler Exploit Kit Delivery; Ransomware Use Confirmed; Patched MS16-006 (January 2016)

CVSS 8.8
CVE-2016-0984

Adobe Flash Player and AIR — Use-After-Free Enables Heap-Based RCE via Crafted SWF; Exploit Kit Target in Early 2016; Patched APSB16-04 (February 2016)

CVSS 8.8
CVE-2016-1010

Adobe Flash Player and AIR — Integer Overflow Leads to Heap Corruption and RCE via Crafted SWF; Exploit Kit Vector in 2016; Patched APSB16-08 (March 2016)

CVSS 8.8
CVE-2016-7256

Windows Font Library — Malformed OpenType Font in Web Page or Document Triggers Memory Corruption Enabling RCE; Patched MS16-132 (November 2016)

CVSS 8.8
CVE-2016-4657

Apple iOS WebKit — Memory Corruption via Crafted Web Page Enables Remote Code Execution; Stage 1 Entry Point of 'Trident' Pegasus Chain; Patched iOS 9.3.5 (August 2016)

CVSS 8.8
CVE-2016-6366

Cisco ASA — SNMP Packet Processing Buffer Overflow Enables RCE or DoS; 'ExtraBacon' Shadow Brokers Leak; Patched cisco-sa-20160817-asa-snmp (August 2016)

CVSS 8.8
CVE-2016-3393

Microsoft Windows GDI — Memory Object Handling Flaw Enables Code Execution via Crafted Document or Malicious Web Page; Patched MS16-120 (October 2016)

CVSS 7.8
CVE-2016-4656

Apple iOS Kernel — Memory Corruption Enables Full Kernel Control / Jailbreak; Stage 3 of 'Trident' Pegasus Chain; Patched iOS 9.3.5 (August 2016)

CVSS 7.8
CVE-2016-6367

Cisco ASA — Authenticated CLI Parser Buffer Overflow Enables Local Privilege Escalation or Code Execution; Companion to ExtraBacon (CVE-2016-6366); Patched August 2016

CVSS 7.8

April 2022

March 2022

CVE-2016-7200

Microsoft Edge Chakra — Out-of-Bounds Write in JavaScript Engine Enables Remote Code Execution via Malicious Web Page; Patched MS16-145 (November 2016)

CVSS 8.8
CVE-2016-7201

Microsoft Edge Chakra — Type Confusion in JavaScript Engine Enables Remote Code Execution via Malicious Web Page; Patched MS16-145 (November 2016)

CVSS 8.8
CVE-2016-7892

Adobe Flash Player — TextField Class Use-After-Free Enables Remote Code Execution via Malicious Web Content; Patched APSB16-39 (December 2016)

CVSS 8.8
CVE-2016-6277

NETGEAR R7000/R6400 and Others — Web Interface Command Injection via CSRF Enables Unauthenticated RCE on Home/SMB Routers; Widely Exploited by Botnets

CVSS 8.8
CVE-2016-7855

Adobe Flash Player — Use-After-Free Zero-Day Exploited in Targeted Attacks Before Patch; Emergency APSB16-37 (October 2016)

CVSS 8.8
CVE-2016-0040

Microsoft Windows Kernel — Local Privilege Escalation to SYSTEM via Crafted Application; Patched MS16-014 (February 2016)

CVSS 7.8
CVE-2016-0151

Windows CSRSS — Process Token Mismanagement Enables Privilege Escalation; Ransomware Use Confirmed; Patched MS16-048 (April 2016)

CVSS 7.8
CVE-2016-3309

Microsoft Windows — Kernel Object Handling Flaw Enables Local Privilege Escalation to SYSTEM; Exploited in Ransomware Chains; Patched MS16-098 (August 2016)

CVSS 7.8
CVE-2016-0099

Windows Secondary Logon Service — Handle Management Flaw Enables LPE to SYSTEM; Widely Used by Ransomware Operators; Patched MS16-032 (March 2016)

CVSS 7.8
CVE-2016-7193

Microsoft Word — RTF File Format Memory Corruption Enables Remote Code Execution via Malicious Document; Patched MS16-121 (October 2016)

CVSS 7.8
CVE-2016-7262

Microsoft Excel — Security Feature Bypass via Malformed File Enables Arbitrary Command Execution Without Macro Prompts; Patched MS16-148 (December 2016)

CVSS 7.8
CVE-2016-0189

Internet Explorer JScript/VBScript — Scripting Engine Memory Corruption Enables RCE via Crafted Web Page; Targeted APT Exploitation; Patched MS16-051 (May 2016)

CVSS 7.5
CVE-2016-0752

Ruby on Rails Action View — render :file Path Traversal Allows Unauthenticated Arbitrary File Read; Fixed Rails 3.2.22.2 / 4.x / 5.0 (January 2016)

CVSS 7.5
CVE-2016-8562

Siemens SIMATIC CP 1543-1 — Industrial Ethernet Communications Processor Allows Authenticated Low-Privilege Remote Denial of Service; Patched via Firmware Update

CVSS 7.5
CVE-2016-11021

D-Link DCS-930L Network Camera — setSystemCommand Function Allows Authenticated Admin OS Command Injection; End-of-Life Device with No Patch Available

CVSS 7.2
CVE-2016-5195

Linux Kernel 'Dirty COW' — Copy-on-Write Race Condition Permits Unprivileged Write to Read-Only Memory-Mapped Files

CVSS 7

November 2021

Medium 8

June 2022

May 2022

November 2021