Skip to content
VulniPulse

Microsoft Server Windows Server Vulnerabilities & Security Advisories

1523 advisories tracked · Microsoft Security Update Guide (MSRC) · 61 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Microsoft Server advisory that VulniPulse classified as Windows Server, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 65 critical, 1087 high, 417 medium, 4 low.

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server Windows Server advisories

Critical9.8MS Server

Critical [CVE-2026-69730] Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69730
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69819] RPC Runtime Library Remote Code Execution Vulnerability

RPC Runtime Library Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69819
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69525] Remote Desktop Services Remote Code Execution Vulnerability

Remote Desktop Services Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69525
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69496] Windows Compressed Folder Remote Code Execution Vulnerability

Windows Compressed Folder Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69496
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69463] Windows NTFS Remote Code Execution Vulnerability

Windows NTFS Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69463
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69491] Microsoft DirectMusic Remote Code Execution Vulnerability

Microsoft DirectMusic Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69491
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69431] Telnet Client Remote Code Execution Vulnerability

Telnet Client Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69431
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69408] Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Microsoft Windows Media Foundation Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69408
Windows Server
Sep 8, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-69276] Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability

Microsoft UxTheme Library (uxtheme.dll) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69276
Windows Server
Sep 8, 2026
Critical9.8MS Server

Critical [CVE-2026-65791] Windows iSCSI Target Service Remote Code Execution Vulnerability

Windows iSCSI Target Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-65791
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62893] Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-62893
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62815] Microsoft QUIC Remote Code Execution Vulnerability

Microsoft QUIC Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-62815
Windows Server
Aug 11, 2026
Critical9.9MS Server

Critical [CVE-2026-50481] Azure Active Directory Elevation of Privilege Vulnerability

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

CVE-2026-50481
Windows Server
Aug 6, 2026
Critical9.3Vendor: HighMS Server

Critical [CVE-2026-49798] Windows Kernel Elevation of Privilege Vulnerability

Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-49798
Windows Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-54990] Remote Desktop Client Remote Code Execution Vulnerability

Remote Desktop Client Remote Code Execution Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-54990
Windows Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-49172] Windows FTP Service Remote Code Execution Vulnerability

Windows FTP Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2025; Windows Server 2022; Windows Server 2019.

CVE-2026-49172
Windows Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-42990] SQL Server ODBC driver Elevation of Privilege Vulnerability

SQL Server ODBC driver Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-42990
Windows Server
Jul 14, 2026
Critical9.6MS Server

Critical [CVE-2026-50380] Windows GDI+ Remote Code Execution Vulnerability

Windows GDI+ Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50380
Windows Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-50447] Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability

Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50447
Windows Server
Jul 14, 2026
Critical9.8MS Server

Critical [CVE-2026-56159] DHCP Server Service Remote Code Execution Vulnerability

DHCP Server Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-56159
Windows Server
Jul 14, 2026

← All MS Server advisories