CVE-2016-0189Active Exploitation(microsoft / internet_explorer)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft internet_explorer systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-18. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • internet_explorer
  • jscript
  • vbscript
  • windows_10_1507

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-17); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
internet_explorerjscriptvbscriptwindows_10_1507windows_10_1511windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2012

7 versions affected across 11 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-17: 1Mentions · 2026-08-15: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-08-15: 104-1708-15
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • kokumօtօ@__kokumoto
    Active Exploitation

    10件の脆弱性でランサムウェアによる悪用が確認された。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性が更新。対象は以下。 - CVE-2025-60710 (Windows) - CVE-2020-29574 (CyberoamOS) - CVE-2020-0618 (SQL Server) - CVE-2021-4034 (polkit) - CVE-2016-0189 (IE) - CVE-2022-21882 (Windows) - CVE-2019-5591 (FortiOS) - CVE-2019-0803 (Windows) - CVE-2018-0802 (Office) - CVE-2020-0968 (IE)

    Post summary

    The post announces that CISA has updated its list of known exploited vulnerabilities, noting that ransomware is actively exploiting ten listed CVEs, but provides no PoC, patches, or technical details.

    01121102.7K
    7.8K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2016-0189 Exploit in the wild confirmed for CVE-2016-0189 (CVSS null). The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other product... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The message announces confirmed active exploitation of CVE-2016-0189 via Microsoft JScript/VBScript engines in Internet Explorer, with no patch or PoC details shared.

    00000105
    5.6K followersView on X
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftinternet_explorer10--
Appmicrosoftinternet_explorer11--
Appmicrosoftinternet_explorer9--
Appmicrosoftjscript5.8--
Appmicrosoftvbscript5.7--
Appmicrosoftvbscript5.8--
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1511---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_vista---

Explore more