Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-1220Definition on MITRE ↗Clear

3 results

CVE-2026-56155
2026-07-14
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Microsoft

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CWE-1220
Refsmsrc.microsoft.comBOD 26-04Forensics Triage Requirementsnvd.nist.govlearn.microsoft.com
Federal remediation due 2026-07-28
CVE-2026-33825
2026-04-22
Microsoft Defender Insufficient Granularity of Access Control VulnerabilityRansomware
Microsoft

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

CWE-1220
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-05-06
CVE-2021-36934
2022-02-10
Microsoft Windows SAM Local Privilege Escalation Vulnerability
Microsoft

If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.

CWE-1220
Refsnvd.nist.gov
Federal remediation due 2022-02-24