Eleven Microsoft vulnerabilities entered CISA's Known Exploited Vulnerabilities catalogue over the past year with original disclosure dates stretching back to 2008 — a Windows buffer overflow from that year scoring CVSS 9.8, an Internet Explorer memory corruption bug from 2009, two separate IE use-after-free flaws from 2010, and more, continuing through 2013.
| CVE | Product | Disclosed | CVSS |
|---|---|---|---|
| CVE-2008-4250 | Windows | 2008 | 9.8 |
| CVE-2008-0015 | Windows (Video ActiveX) | 2008 | 8.8 |
| CVE-2009-1537 | DirectX | 2009 | 8.8 |
| CVE-2009-0556 | Office PowerPoint | 2009 | 8.8 |
| CVE-2009-0238 | Office | 2009 | 8.8 |
| CVE-2010-0249 | Internet Explorer | 2010 | 8.8 |
| CVE-2010-0806 | Internet Explorer | 2010 | 8.8 |
| CVE-2010-3962 | Internet Explorer | 2010 | 8.1 |
| CVE-2011-3402 | Windows | 2011 | 8.8 |
| CVE-2012-1854 | Visual Basic for Applications | 2012 | 7.8 |
| CVE-2013-3918 | Windows | 2013 | 8.8 |
Why this specific cluster is worth pausing on
This is not a slow trickle of one old CVE surfacing every so often — CISA added several of these on the exact same day. CVE-2008-4250, CVE-2009-1537, CVE-2010-0249, and CVE-2010-0806 were all confirmed exploited within the same short window in 2026. Four vulnerabilities spanning a range from 2008 to 2010, none touched for over a decade, all suddenly active at once.
The most plausible explanation isn't that four independent attacker groups happened to rediscover four unrelated ancient bugs simultaneously. It's that a single body of exploitation activity — quite possibly a malware framework, exploit kit, or threat-actor toolkit built to target legacy systems specifically — was identified and its full arsenal of old, reliable exploits became attributable at once. Old vulnerabilities like these remain valuable to attackers for exactly the reason they're dangerous to defenders: they're stable, well-documented, and reliably present on any system that has genuinely never been patched or replaced.
What kind of systems are actually still exposed to bugs this old
A system vulnerable to a 2008 Windows buffer overflow or 2010-era Internet Explorer use-after-free bugs is not running a currently supported, actively patched version of Windows. Realistic candidates include embedded and industrial systems built on old Windows Embedded builds that were never intended to be patched on a conventional cycle, air-gapped or isolated systems where "it can't reach the internet anyway" became the justification for skipping updates indefinitely, and legacy systems kept running specifically because replacing them threatens compatibility with equipment or software nobody wants to risk breaking.
What to check this week
Inventory for genuinely unsupported operating systems and legacy browser installations, treating any discovery as a priority finding regardless of how isolated the system is believed to be — "isolated" and "verified isolated" are different claims, and this cluster's confirmed exploitation means someone found a way to reach at least some of these systems.
Pay particular attention to embedded and OT-adjacent Windows deployments, which are the most likely home for genuinely unpatched systems this old, given the OT patching constraints discussed throughout this series.
Treat isolation as a hypothesis to verify, not a control to rely on. A system's supposed air-gap is only as good as its last network architecture review; connectivity requirements have a well-documented tendency to creep in over a system's operational life.
A closing note on decommissioning versus patching
For systems this old, patching may not even be an option — Microsoft's support lifecycle for software from this era ended long ago, meaning the realistic remediation for a genuinely still-running 2008-era Windows system is decommissioning or network isolation, not a security update that no longer exists to be applied.
A final consideration on merger and acquisition due diligence
Legacy systems this old are a well-documented discovery risk in merger and acquisition technical due diligence specifically, where an acquired company's undocumented, unsupported infrastructure can surface only after the deal has closed — a strong argument for including deep legacy-asset discovery, not just a surface-level inventory review, in any acquisition's security assessment.
How Safeguard helps
Safeguard's continuous inventory surfaces exactly this category of risk — genuinely ancient software still present somewhere in an environment, invisible to a vulnerability management process built around scanning for recently disclosed CVEs. Finding an operating system or application this old is itself the finding worth acting on, independent of any specific CVE attached to it.