828 vulnerabilities exploited at AI companies since 2021: Microsoft takes the lead
16 AI companies have been affected

- Since 2021, CISA has recorded 828 CVEs across 16 AI companies.
- Out of all AI companies in the dataset, Microsoft is by far the leader in the number of CVEs, with 377 vulnerabilities found.
- A closer look at Microsoft revealed that 27% of vulnerabilities were ransomware-related.
- Microsoft Windows is the most-exploited product, with 170 known vulnerabilities.
The companies behind today's leading AI products have accumulated hundreds of vulnerabilities that attackers have already exploited in the wild. To examine how widespread the issue is, Cybernews researchers have analyzed the KEV (Known Exploited Vulnerabilities) Catalog – a list of already-exploited weaknesses in software (or hardware), compiled by CISA (the U.S. Cybersecurity and Infrastructure Security Agency). Cybernews found 828 common vulnerabilities and exposures (CVEs) at AI companies since 2021, with Microsoft accounting for 377 of them.
This analysis focuses on known exploited vulnerabilities affecting companies that develop AI products and services. While some of these vulnerabilities may impact AI-related products, the dataset also includes vulnerabilities in other software and hardware produced by these companies.
16 AI companies affected
A CVE (Common Vulnerabilities and Exposures) is an identifier assigned to a publicly disclosed and documented security flaw, while a KEV (Known Exploited Vulnerability) is a CVE that has been confirmed by CISA as already actively exploited in real-world attacks.
Since 2021, CISA has recorded 828 known exploited vulnerabilities affecting 16 AI companies. These are not theoretical risks but vulnerabilities that attackers, including ransomware groups, have already used to compromise systems.
While several major technology companies appear in the analyzed dataset, including Apple, Adobe, Google, and Samsung, Microsoft is a clear outlier, accounting for nearly half of all exploited CVEs (377).
However, this doesn’t necessarily mean Microsoft is less secure. According to Voldemaras Kadys, Head of Security and Platform Engineering at Mediatech, the digital publishing house behind Cybernews, it may just mean that Microsoft is a more attractive target: “The number of exploited vulnerabilities correlates strongly with a technology company's market share. This isn't surprising: the biggest products draw the most attacker attention, since a single vulnerability can be leveraged against a far larger user base.”
No other single company in the dataset records more than 100 exploited CVEs: Apple has 93, Cisco has 92, Adobe has 79, and Google has 72, with the remaining AI companies each having fewer than 50. This shows that while all of these companies are vulnerable to attacks, none approaches the volume of flaws seen in Microsoft.
A known exploited vulnerability is not just a minor technical issue, but a potential entry point into sensitive and valuable technology. The most common weakness types found were OS Command Injection, a flaw that allows attackers to execute malicious operating system commands directly on a server, Improper Input Validation, a flaw in which an application accepts data from an external source but fails to sufficiently verify it before processing, and Out-of-bounds Write, a fundamental memory safety flaw.
Microsoft accounts for 46% of vulnerabilities at AI companies
103 CVEs found in Microsoft were used in ransomware campaigns. This means that threat actors not only discovered and exploited the vulnerability but also leveraged it as part of a ransomware campaign – a cyberattack in which malicious software locks or encrypts victims' data, with attackers demanding payment in exchange for the decryption key.
This shows that Microsoft has been a frequent target for ransomware operators, with exploited vulnerabilities in its products repeatedly serving as entry points for ransomware attacks.
At the product level, 170 CVEs were found in Microsoft Windows alone, making it the most exploited product in the dataset.
For comparison, Apple (multiple products) had 53 exploited CVEs and Google Chromium V8 had 39.
What do the findings mean for companies choosing AI vendors?
The findings raise questions about how organizations should evaluate AI vendors as AI systems gain access to increasingly sensitive business data:
“The shift toward SaaS, the growing amount of business-critical data living online, and the rapid adoption of AI are all raising the stakes around trust and vendor reputation. AI agents now have access to more sensitive information than ever before – some of it confidential – and supply chain attacks are becoming more frequent and more damaging. Vendor risk assessment isn't new, but compliance requirements and regulatory expectations are tightening every year, and the bar for what counts as "due diligence" keeps rising with them.
The open question for security leaders is whether this changes the calculus between staying on the cutting edge of technology adoption and prioritizing vendors with a proven track record of reliability and trust. As AI becomes more deeply embedded in business workflows, that tradeoff may need to be made more deliberately than it has been in the past,” concludes Voldemaras Kadys, Head of Security and Platform Engineering at Mediatech, the digital publishing house behind Cybernews.
Methodology:
Cybernews researchers analyzed the Known Exploited Vulnerabilities (KEV) Catalog maintained by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The analysis examined all Common Vulnerabilities and Exposures (CVEs) listed in the catalog since 2021 for 16 companies that develop leading AI products and services. Rather than focusing only on vulnerabilities affecting AI products, the research included all known exploited vulnerabilities across each company's software and hardware portfolio to assess the overall security track record of the organizations behind today's leading AI technologies.
For the full dataset, click here.