Cybernews researchers have analyzed the KEV (Known Exploited Vulnerabilities) Catalog – a list of already-exploited weaknesses in software (or hardware), compiled by CISA (the U.S. Cybersecurity and Infrastructure Security Agency). Cybernews found 828 common vulnerabilities and exposures (CVEs) at AI companies since 2021, with Microsoft accounting for 377 of them.
Key findings:
- Since 2021, CISA has recorded 828 CVEs across 16 AI companies.
- Out of all AI companies in the dataset, Microsoft is by far the leader in the number of CVEs, with 377 vulnerabilities found.
- A closer look at Microsoft revealed that 27% of vulnerabilities were ransomware-related.
- Microsoft Windows is the most-exploited product, with 170 known vulnerabilities.
“The number of exploited vulnerabilities correlates strongly with a technology company’s market share. This isn’t surprising: the biggest products draw the most attacker attention, since a single vulnerability can be leveraged against a far larger user base. That said, the shift toward SaaS, the growing amount of business-critical data living online, and the rapid adoption of AI are all raising the stakes around trust and vendor reputation,” says Voldemaras Kadys, Head of Security and Platform Engineering at Mediatech, the digital publishing house behind Cybernews.
For more information, here’s the full report:
https://cybernews.com/security/828-vulnerabilities-exploited-at-ai-companies-since-2021
Related
This entry was posted on July 28, 2026 at 9:53 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
377 vulnerabilities exploited at Microsoft since 2021, more than any other AI company
Cybernews researchers have analyzed the KEV (Known Exploited Vulnerabilities) Catalog – a list of already-exploited weaknesses in software (or hardware), compiled by CISA (the U.S. Cybersecurity and Infrastructure Security Agency). Cybernews found 828 common vulnerabilities and exposures (CVEs) at AI companies since 2021, with Microsoft accounting for 377 of them.
Key findings:
“The number of exploited vulnerabilities correlates strongly with a technology company’s market share. This isn’t surprising: the biggest products draw the most attacker attention, since a single vulnerability can be leveraged against a far larger user base. That said, the shift toward SaaS, the growing amount of business-critical data living online, and the rapid adoption of AI are all raising the stakes around trust and vendor reputation,” says Voldemaras Kadys, Head of Security and Platform Engineering at Mediatech, the digital publishing house behind Cybernews.
For more information, here’s the full report:
https://cybernews.com/security/828-vulnerabilities-exploited-at-ai-companies-since-2021
Share this:
Like this:
Related
This entry was posted on July 28, 2026 at 9:53 am and is filed under Commentary with tags Cybernews. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.