CVE-2021-36942
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 20, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
93.73%
probability
This CVE has a 93.73% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Microsoft and Adobe Patch Tuesday (August 2021) – Microsoft 51 Vulnerabilities with 7 Critical, Adobe 29 Vulnerabilities
Qualys
Aug 10, 2021
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
Qualys
May 08, 2025
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Signal Intelligence
Confidence
85%
EPSS
93.73%
Mentions
4
Last Seen
May 08, 2025
CNA Information
Analyst Note
CVE-2021-36942 is explicitly named in the August 2021 Microsoft Patch Tuesday article as a critical Windows LSA vulnerability included among three 0-day patches released that month. The explicit identification as a 0-day in an authoritative Qualys Patch Tuesday report, combined with simultaneous patch and vulnerability disclosure timing (August 2021), meets the confirmation criteria for zero-day classification.
Threat Actors 6
APT27
apt_group
Information theft and espionage
🇨🇳 CN
Cron
apt_group
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
TA505
apt_group
Financial gain
🇷🇺 RU
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Operation Shadow Force
apt_group
🇨🇳 CN
Triage Info
Decided atMar 20, 2026