Skip to content
VulniPulse

Microsoft Server Windows Server Vulnerabilities & Security Advisories

418 advisories tracked · Microsoft Security Update Guide (MSRC) · 5 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Microsoft Server advisory that VulniPulse classified as Windows Server, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 17 critical, 295 high, 122 medium, 3 low.

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server Windows Server advisories

Medium5.5MS Server

Medium [CVE-2026-20839] Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2012; Windows Server 2012 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); and 1 more.

CVE-2026-20839
Windows Server
Jan 13, 2026
Medium5.5MS Server

Medium [CVE-2026-20838] Windows Kernel Information Disclosure Vulnerability

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-20838
Windows Server
Jan 13, 2026
Medium5.5MS Server

Medium [CVE-2026-20835] Capability Access Management Service (camsvc) Information Disclosure Vulnerability

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-20835
Windows Server
Jan 13, 2026
Medium4.6MS Server

Medium [CVE-2026-20834] Windows Spoofing Vulnerability

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2026-20834
Windows Server
Jan 13, 2026
Medium5.5MS Server

Medium [CVE-2026-20833] Windows Kerberos Information Disclosure Vulnerability

Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2026-20833
Windows Server
Jan 13, 2026
Medium5.5MS Server

Medium [CVE-2026-20829] TPM Trustlet Information Disclosure Vulnerability

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).

CVE-2026-20829
Windows Server
Jan 13, 2026
Medium4.6MS Server

Medium [CVE-2026-20828] Windows rndismp6.sys Information Disclosure Vulnerability

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2026-20828
Windows Server
Jan 13, 2026
Medium5.5MS Server

Medium [CVE-2026-20827] Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-20827
Windows Server
Jan 13, 2026
Medium4.4MS Server

Medium [CVE-2026-20825] Windows Hyper-V Information Disclosure Vulnerability

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).

CVE-2026-20825
Windows Server
Jan 13, 2026
Medium5.5MS Server

Medium [CVE-2026-20824] Windows Remote Assistance Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-20824
Windows Server
Jan 13, 2026
Medium6.2MS Server

Medium [CVE-2026-20821] Remote Procedure Call Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2026-20821
Windows Server
Jan 13, 2026
Medium6.2MS Server

Medium [CVE-2026-20818] Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-20818
Windows Server
Jan 13, 2026
Medium6.5MS Server

Medium [CVE-2026-20812] LDAP Tampering Vulnerability

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-20812
Windows Server
Jan 13, 2026
Medium5.5MS Server Exploited CISA KEV

Medium [CVE-2026-20805] Desktop Window Manager Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-20805
Windows Server
Jan 13, 2026
Medium6.4MS Server

Medium [CVE-2026-21265] Secure Boot Certificate Expiration Security Feature Bypass Vulnerability

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 Signs updates to the DB and DBX 06/24/2026 DB Signs 3rd party boot loaders, Option ROMs, etc. Microsoft Windows Production PCA 2011 Signs the Windows Boot Manager For more information see this CVE and Windows Secure Boot certificate expiration and CA updates. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more.

CVE-2026-21265
Windows Server
Jan 13, 2026
Medium4.4MS Server

Medium [CVE-2026-20962] Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation); and 2 more. Affected products named by the advisory: Windows Server 2025 (Server Core installation).

CVE-2026-20962
Windows Server
Jan 13, 2026
Medium5.5MS Server

Medium [CVE-2024-30096] Windows Cryptographic Services Information Disclosure Vulnerability

Windows Cryptographic Services Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2022, 23H2 Edition (Server Core installation).

CVE-2024-30096
Windows Server
Jun 11, 2024
Medium5.5MS Server

Medium [CVE-2024-30067] Winlogon Elevation of Privilege Vulnerability

Winlogon Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 6 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation).

CVE-2024-30067
Windows Server
Jun 11, 2024
Medium5.5MS Server

Medium [CVE-2024-30065] Windows Themes Denial of Service Vulnerability

Windows Themes Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 6 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation).

CVE-2024-30065
Windows Server
Jun 11, 2024
Medium6.7MS Server

Medium [CVE-2024-30063] Windows Distributed File System (DFS) Remote Code Execution Vulnerability

Windows Distributed File System (DFS) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2024-30063
Windows Server
Jun 11, 2024

← All MS Server advisories