Skip to content
VulniPulse

Microsoft Server Windows Server Vulnerabilities & Security Advisories

418 advisories tracked · Microsoft Security Update Guide (MSRC) · 5 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Microsoft Server advisory that VulniPulse classified as Windows Server, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 17 critical, 295 high, 122 medium, 3 low.

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server Windows Server advisories

High7.0MS Server Updated

High [CVE-2026-42836] Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42836
Windows Server
Jun 9, 2026
High7.8MS Server Updated

High [CVE-2026-42905] Windows DWM Core Library Elevation of Privilege Vulnerability

Windows DWM Core Library Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42905
Windows Server
Jun 9, 2026
High7.8MS Server Updated

High [CVE-2026-42916] NT OS Kernel Elevation of Privilege Vulnerability

NT OS Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42916
Windows Server
Jun 9, 2026
High7.5MS Server Updated

High [CVE-2026-42913] Remote Desktop Client Remote Code Execution Vulnerability

Remote Desktop Client Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42913
Windows Server
Jun 9, 2026
High7.0MS Server Updated

High [CVE-2026-42912] Windows Telephony Service Elevation of Privilege Vulnerability

Windows Telephony Service Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42912
Windows Server
Jun 9, 2026
High8.1MS Server Updated

High [CVE-2026-42981] Windows Performance Monitor Remote Code Execution Vulnerability

Windows Performance Monitor Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42981
Windows Server
Jun 9, 2026
High7.8MS Server Updated

High [CVE-2026-42986] Microsoft Graphics Component Elevation of Privilege Vulnerability

Microsoft Graphics Component Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42986
Windows Server
Jun 9, 2026
High7.8MS Server Updated

High [CVE-2026-42978] Windows Push Notifications Elevation of Privilege Vulnerability

Windows Push Notifications Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-42978
Windows Server
Jun 9, 2026
High7.8MS Server Updated

High [CVE-2026-42989] Winlogon Elevation of Privilege Vulnerability

Winlogon Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42989
Windows Server
Jun 9, 2026
High7.8MS Server Updated

High [CVE-2026-44809] Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-44809
Windows Server
Jun 9, 2026
High8.4Vendor: CriticalMS Server Updated

High [CVE-2026-44810] Microsoft Cryptographic Services Elevation of Privilege Vulnerability

Microsoft Cryptographic Services Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-44810
Windows Server
Jun 9, 2026
High7.8MS Server Updated

High [CVE-2026-42983] Windows DWM Core Library Elevation of Privilege Vulnerability

Windows DWM Core Library Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-42983
Windows Server
Jun 9, 2026
High8.1Vendor: CriticalMS Server Updated

High [CVE-2026-42987] Windows Deployment Services (WDS) Remote Code Execution

Windows Deployment Services (WDS) Remote Code Execution Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42987
Windows Server
Jun 9, 2026
High7.8MS Server

High [CVE-2026-20941] Host Process for Windows Tasks Elevation of Privilege Vulnerability

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-20941
Windows Server
Jan 13, 2026
High8.0MS Server

High [CVE-2026-20931] Windows Telephony Service Elevation of Privilege Vulnerability

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2026-20931
Windows Server
Jan 13, 2026
High7.5MS Server

High [CVE-2026-20929] Windows HTTP.sys Elevation of Privilege Vulnerability

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2026-20929
Windows Server
Jan 13, 2026
High7.8MS Server

High [CVE-2026-20874] Windows Management Services Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).

CVE-2026-20874
Windows Server
Jan 13, 2026
High7.8MS Server

High [CVE-2026-20871] Desktop Window Manager Elevation of Privilege Vulnerability

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-20871
Windows Server
Jan 13, 2026
High7.8MS Server

High [CVE-2026-20870] Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-20870
Windows Server
Jan 13, 2026
High8.8MS Server

High [CVE-2026-20868] Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2026-20868
Windows Server
Jan 13, 2026

← All MS Server advisories