EXPOSURE LEDGER
The Wang Report · Cyber Intel Desk · Hong Kong

Every vulnerability CISA has listed as exploited in the wild that touches the footprint: the identity, endpoint, SASE, SecOps, OT and data vendors the banks this desk advises actually run. For each, the date it was published, the date it was listed as exploited, the days between, and the vendor's own advisory where the feed carries one. Rows open once and stay. 13 rows (Microsoft 11, CyberArk 2). Footprint today: Microsoft, Okta, SailPoint, CyberArk, Saviynt, Ping Identity, BeyondTrust, SWIFT, CrowdStrike, Zscaler, Google SecOps, Claroty, Databricks.

The LedgerFull CVE feed →
Critical 10.0
CVE-2026-86218: pre-authentication remote code execution
Microsoft · N-able N-central
published Sep 6 · KEV Sep 8 · 2 days from publication to exploited-listing · 1 day since listing · EPSS 0%
no vendor advisory in the feed · NVD
High 7.8
CVE-2026-81963: Windows Update Stack Elevation of Privilege Vulnerability
Microsoft · Microsoft Windows 11 version 23H2
published Sep 8 · KEV Sep 8 · 0 days from publication to exploited-listing · 1 day since listing
High 7.8
CVE-2026-85880: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Microsoft · Microsoft Windows 10 Version 1607
published Sep 8 · KEV Sep 8 · 0 days from publication to exploited-listing · 1 day since listing
Unscored
CVE-2022-0995: n/a kernel Out-of-Bounds Write
CyberArk (footprint hit by the CVE feed’s vendor map; product is n/a kernel) · APAC-FSI
published Mar 25, 2022 · KEV Aug 26 · 1615 days from publication to exploited-listing · 14 days since listing · EPSS 10%
no vendor advisory in the feed · NVD
Critical 9.1
CVE-2026-55040: Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft · Microsoft Microsoft SharePoint Enterprise Server 2016
published Jul 14 · KEV Aug 18 · 35 days from publication to exploited-listing · 22 days since listing · EPSS 40%
High 7.0
CVE-2026-68820: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft · Microsoft Windows 10 Version 1607
published Aug 11 · KEV Aug 11 · 0 days from publication to exploited-listing · 29 days since listing · EPSS 6%
High 8.2
CVE-2026-18556: Unauthenticated administrative account takeover
Microsoft · N-able N-central
published Aug 1 · KEV Aug 4 · 3 days from publication to exploited-listing · 36 days since listing · EPSS 40%
no vendor advisory in the feed · NVD
High 8.2
CVE-2026-18577: Incomplete patch leads to administrative account takeover
Microsoft · N-able N-central
published Aug 2 · KEV Aug 3 · 1 day from publication to exploited-listing · 37 days since listing · EPSS 54%
Critical 9.8
CVE-2026-50522: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft · Microsoft Microsoft SharePoint Enterprise Server 2016
published Jul 14 · KEV Jul 22 · 8 days from publication to exploited-listing · 49 days since listing · EPSS 85%
Critical 9.8
CVE-2026-58644: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft · Microsoft Microsoft SharePoint Enterprise Server 2016
published Jul 14 · KEV Jul 16 · 2 days from publication to exploited-listing · 55 days since listing · EPSS 16%
Medium 5.3
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft · Microsoft Microsoft SharePoint Enterprise Server 2016 · OT
published Jul 14 · KEV Jul 14 · 0 days from publication to exploited-listing · 57 days since listing · EPSS 27%
High 7.8
CVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability
Microsoft · Microsoft Windows 10 Version 1607
published Jul 14 · KEV Jul 14 · 0 days from publication to exploited-listing · 57 days since listing · EPSS 0%
Critical 9.1
CVE-2025-6205: Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
CyberArk (footprint hit by the CVE feed’s vendor map; product is Dassault Systèmes DELMIA Apriso) · APAC-FSI
no publication date in the feed · KEV Oct 28, 2025 · 316 days since listing · EPSS 72%
no vendor advisory in the feed · NVD
Source: CISA Known Exploited Vulnerabilities, NVD, FIRST EPSS via the desk's CVE feed; footprint from the Vendor Roster. Days from publication to exploited-listing measures how long the CVE was public before CISA confirmed exploitation; a zero means it was exploited before or as it was published. A vendor fix date is recorded only when a source states one; none of the current rows carries one. Updated daily at 05:30.

The rows on this page are drawn from the sources named in the footer and may be reused with attribution to The Wang Report and to that source; the curation, the series and the annotations are The Wang Report's own. Data on this site. Named parties have a right of reply.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.