CVE-2021-36942

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 20, 2026 4 articles

EPSS Score

Source: FIRST.org · 2026-05-24
93.73%
probability
This CVE has a 93.73% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Signal Intelligence

Confidence
85%
EPSS 93.73%
Mentions 4
Last Seen May 08, 2025

CNA Information

Analyst Note

CVE-2021-36942 is explicitly named in the August 2021 Microsoft Patch Tuesday article as a critical Windows LSA vulnerability included among three 0-day patches released that month. The explicit identification as a 0-day in an authoritative Qualys Patch Tuesday report, combined with simultaneous patch and vulnerability disclosure timing (August 2021), meets the confirmation criteria for zero-day classification.

Threat Actors 6

APT27
apt_group Information theft and espionage 🇨🇳 CN
Cron
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
TA505
apt_group Financial gain 🇷🇺 RU
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN

Triage Info

Decided atMar 20, 2026