« Back to list

Microsoft

Microsoft IIS: vulnerabilities and CVEs

Microsoft IIS has 4 published vulnerabilities, 2 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months2
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-0611Critical (9.2)0.66%—Jun 2, 2026
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that…
CVE-2026-5426Critical (9.1)0.81%—Apr 16, 2026
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via…
CVE-2010-20112Critical (9.3)1.1%—Aug 21, 2025
Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the…
CVE-2003-1102Medium (5)1.8%—Dec 31, 2003
Hummingbird CyberDOCS 3.5, 3.9, and 4.0, when running on IIS, uses insecure permissions for script source code files, which allows remote attackers to read the source code.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter3
  2. T1190 Exploit Public-Facing Application3

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft