Microsoft
Microsoft IIS: vulnerabilities and CVEs
Microsoft IIS has 4 published vulnerabilities, 2 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months2
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0611 | Critical (9.2) | 0.66% | — | Jun 2, 2026 | Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that… |
| CVE-2026-5426 | Critical (9.1) | 0.81% | — | Apr 16, 2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via… |
| CVE-2010-20112 | Critical (9.3) | 1.1% | — | Aug 21, 2025 | Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the… |
| CVE-2003-1102 | Medium (5) | 1.8% | — | Dec 31, 2003 | Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.