Microsoft Server Windows Server Vulnerabilities & Security Advisories
1523 advisories tracked · Microsoft Security Update Guide (MSRC) · 61 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Microsoft Server advisory that VulniPulse classified as Windows Server, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 65 critical, 1087 high, 417 medium, 4 low.
Android app · Google Play
Monitor MS Server CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Microsoft Security Update Guide (MSRC)
Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.
Latest MS Server Windows Server advisories
Medium [CVE-2026-34339] Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32170] Windows Rich Text Edit Elevation of Privilege Vulnerability
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-40380] Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-35423] Windows 11 Telnet Client Information Disclosure Vulnerability
Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-35422] Windows TCP/IP Driver Security Feature Bypass Vulnerability
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-35419] Windows DWM Core Library Information Disclosure Vulnerability
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2025; Windows Server 2025 (Server Core installation).
Medium [CVE-2026-34350] Windows Storport Miniport Driver Denial of Service Vulnerability
Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network. Affected products named by the advisory: Windows Server 2025; Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32214] Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-33829] Windows Snipping Tool Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32151] Windows Shell Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32088] Windows Biometric Service Security Feature Bypass Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32084] Windows Print Spooler Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32079] Web Account Manager Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32072] Active Directory Spoofing Vulnerability
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-27930] Windows GDI Information Disclosure Vulnerability
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-27925] Windows UPnP Device Host Information Disclosure Vulnerability
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-26169] Windows Kernel Memory Information Disclosure Vulnerability
Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-20806] Windows COM Server Information Disclosure Vulnerability
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).
Medium [CVE-2026-20928] Windows Recovery Environment Security Feature Bypass Vulnerability
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).
Medium [CVE-2026-32212] Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).