Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 16 SEP 2026

Microsoft · AUTOMATIC DISCOVERY

Access 2019

Access is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Access is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductAccess
Release2019
End of Fixed Lifecycle Policy14 October 2025
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 17 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2026-56155Added 14 Jul 2026

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Microsoft · Active Directory Federation ServicesRansomware use: Unknown

CISA entry
CVE-2010-0806Added 20 May 2026

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Microsoft · Internet ExplorerRansomware use: Unknown

CISA entry
CVE-2010-0249Added 20 May 2026

Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Microsoft · Internet ExplorerRansomware use: Unknown

CISA entry
CVE-2026-42897Added 15 May 2026

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

Microsoft · MicrosoftRansomware use: Unknown

CISA entry
CVE-2026-33825Added 22 Apr 2026

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

Microsoft · DefenderRansomware use: Known

CISA entry
CVE-2026-21525Added 10 Feb 2026

Microsoft Windows NULL Pointer Dereference Vulnerability

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.

Microsoft · WindowsRansomware use: Unknown

CISA entry

Showing the 6 most recently added of 23 product-family matches.

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYReady

Microsoft lifecycle discovery

{"display_products": ["Office"], "end": "2025-10-15T06:59:59.999Z", "last_modified": "2024-08-29T00:00:00Z", "locale": "en-us", "products": ["office"], "start": "2018-09-24T08:00:00Z", "summary": "Access 2019 follows the Fixed Lifecycle Policy.", "title": "Access 2019", "url": "/lifecycle/products/access-2019"}

Official vendor lifecycle or product-change property. Extracted records require human review.

First collected 25 Aug 2026 · Last collected 16 Sep 2026 · Review state accepted

Open official vendor source