Skip to content
VulniPulse

Microsoft Server Security Advisories & CVEs

1724 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your MS Server device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.

Official source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server advisories

High7.0MS Server

High [CVE-2026-69410] Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2016; Windows Server 2012; Windows Server 2012 R2.

CVE-2026-69410
Windows Server
Sep 8, 2026
High7.1MS Server

High [CVE-2026-69396] Windows NDIS Elevation of Privilege Vulnerability

Windows NDIS Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69396
Windows Server
Sep 8, 2026
High8.8MS Server

High [CVE-2026-69386] Microsoft Windows Media Foundation Remote Code Execution Vulnerability

Microsoft Windows Media Foundation Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-69386
Windows Server
Sep 8, 2026
High8.0MS Server

High [CVE-2026-69365] Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability

Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-69365
Windows Server
Sep 8, 2026
High8.8MS Server

High [CVE-2026-69360] Microsoft Office Word Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 7 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022; Windows Server 2025 (Server Core installation).

CVE-2026-69360
Windows Server
Sep 8, 2026
High7.1MS Server

High [CVE-2026-69384] Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability

Virtual Hard Disk (VHD) Miniport Driver Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-69384
Windows Server
Sep 8, 2026
High7.1MS Server

High [CVE-2026-69358] Remote Desktop Client Remote Code Execution Vulnerability

Remote Desktop Client Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-69358
Windows Server
Sep 8, 2026
High7.5MS Server

High [CVE-2026-69342] Windows DHCP Server Denial of Service Vulnerability

Windows DHCP Server Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69342
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-69328] Windows Storage Elevation of Privilege Vulnerability

Windows Storage Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-69328
Windows Server
Sep 8, 2026
High7.5MS Server

High [CVE-2026-69329] BranchCache Denial of Service Vulnerability

BranchCache Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69329
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-69324] Windows Performance Monitor Elevation of Privilege Vulnerability

Windows Performance Monitor Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69324
Windows Server
Sep 8, 2026
High7.1MS Server

High [CVE-2026-69313] Microsoft Standard XPS Elevation of Privilege Vulnerability

Microsoft Standard XPS Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69313
Windows Server
Sep 8, 2026
High8.0MS Server

High [CVE-2026-69301] Windows Win32k Elevation of Privilege Vulnerability

Windows Win32k Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69301
Windows Server
Sep 8, 2026
High7.0MS Server

High [CVE-2026-69300] Windows Push Notifications Elevation of Privilege Vulnerability

Windows Push Notifications Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-69300
Windows Server
Sep 8, 2026
High7.1MS Server

High [CVE-2026-69314] Windows Device Association Broker Service Elevation of Privilege Vulnerability

Windows Device Association Broker Service Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-69314
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-69289] Windows Setup Files Cleanup Elevation of Privilege Vulnerability

Windows Setup Files Cleanup Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69289
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-69295] Windows USB Driver Elevation of Privilege Vulnerability

Windows USB Driver Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69295
Windows Server
Sep 8, 2026
High7.0MS Server

High [CVE-2026-69299] Microsoft COM for Windows Elevation of Privilege Vulnerability

Microsoft COM for Windows Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-69299
Windows Server
Sep 8, 2026
High7.0MS Server

High [CVE-2026-69275] Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69275
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-69284] Windows DCOM Server Elevation of Privilege Vulnerability

Windows DCOM Server Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69284
Windows Server
Sep 8, 2026

← All vendors