Skip to content
VulniPulse

Microsoft Server Windows Server Vulnerabilities & Security Advisories

1523 advisories tracked · Microsoft Security Update Guide (MSRC) · 61 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Microsoft Server advisory that VulniPulse classified as Windows Server, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 65 critical, 1087 high, 417 medium, 4 low.

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server Windows Server advisories

High7.0MS Server

High [CVE-2026-34342] Windows Print Spooler Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-34342
Windows Server
May 12, 2026
High7.0MS Server

High [CVE-2026-34331] Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-34331
Windows Server
May 12, 2026
High8.8MS Server

High [CVE-2026-34329] Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-34329
Windows Server
May 12, 2026
High7.8MS Server

High [CVE-2026-33841] Windows Kernel Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-33841
Windows Server
May 12, 2026
High7.8MS Server

High [CVE-2026-33840] Win32k Elevation of Privilege Vulnerability

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-33840
Windows Server
May 12, 2026
High7.0MS Server

High [CVE-2026-33839] Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).

CVE-2026-33839
Windows Server
May 12, 2026
High7.8MS Server

High [CVE-2026-33834] Windows Event Logging Service Elevation of Privilege Vulnerability

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-33834
Windows Server
May 12, 2026
High8.1MS Server

High [CVE-2026-33827] Windows TCP/IP Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-33827
Windows Server
Apr 14, 2026
High7.8MS Server

High [CVE-2026-33101] Windows Print Spooler Elevation of Privilege Vulnerability

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-33101
Windows Server
Apr 14, 2026
High7.0MS Server

High [CVE-2026-33100] Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-33100
Windows Server
Apr 14, 2026
High7.0MS Server

High [CVE-2026-33099] Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 6 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation).

CVE-2026-33099
Windows Server
Apr 14, 2026
High8.8MS Server

High [CVE-2026-32225] Windows Shell Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-32225
Windows Server
Apr 14, 2026
High7.8MS Server

High [CVE-2026-32164] Windows User Interface Core Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-32164
Windows Server
Apr 14, 2026
High7.8MS Server

High [CVE-2026-32163] Windows User Interface Core Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).

CVE-2026-32163
Windows Server
Apr 14, 2026
High8.4MS Server

High [CVE-2026-32162] Windows COM Elevation of Privilege Vulnerability

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).

CVE-2026-32162
Windows Server
Apr 14, 2026
High7.8MS Server

High [CVE-2026-32155] Desktop Window Manager Elevation of Privilege Vulnerability

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-32155
Windows Server
Apr 14, 2026
High7.0MS Server

High [CVE-2026-32150] Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-32150
Windows Server
Apr 14, 2026
High7.3MS Server

High [CVE-2026-32149] Windows Hyper-V Remote Code Execution Vulnerability

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-32149
Windows Server
Apr 14, 2026
High8.4MS Server

High [CVE-2026-32091] Microsoft Brokering File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-32091
Windows Server
Apr 14, 2026
High7.0MS Server

High [CVE-2026-32080] Windows WalletService Elevation of Privilege Vulnerability

Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-32080
Windows Server
Apr 14, 2026

← All MS Server advisories