CVE-2021-4389

✓ Confirmed 0-Day
Triaged: March 20, 2026 1 article

EPSS Score

Source: FIRST.org · 2026-05-24
0.14%
probability
This CVE has a 0.14% probability of being exploited in the next 30 days.
0% Top 33.3th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Signal Intelligence

Confidence
75%
EPSS 0.14%
Mentions 1
Last Seen Dec 14, 2021

CNA Information

Analyst Note

Article explicitly identifies CVE-2021-4389 as a 'zero-day used by Emotet' in the title, with Microsoft patching it. The 2021 CVE year and active Emotet exploitation in the wild strongly support zero-day classification, though the truncated excerpt limits full timeline verification of patch-vs-exploitation timing.

Triage Info

Decided atMar 20, 2026