Skip to content
VulniPulse

Microsoft Server Security Advisories & CVEs

59 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your MS Server device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.

Official source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server advisories

Critical9.1MS Server Exploited CISA KEV

Critical [CVE-2026-55040] Microsoft SharePoint Server Security Feature Bypass Vulnerability

Microsoft SharePoint Server Security Feature Bypass Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-55040
SharePoint Server
Jul 14, 2026
Critical9.8MS Server

Critical [CVE-2026-56159] DHCP Server Service Remote Code Execution Vulnerability

DHCP Server Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-56159
Windows Server
Jul 14, 2026
Critical9.8Vendor: HighMS Server

Critical [CVE-2026-56190] Remote Desktop Protocol Remote Code Execution Vulnerability

Remote Desktop Protocol Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-56190
Windows Server
Jul 14, 2026
Critical9.8MS Server

Critical [CVE-2026-56188] Windows Server Network driver Remote Code Execution Vulnerability

Windows Server Network driver Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-56188
Windows Server
Jul 14, 2026
Critical9.9MS Server

Critical [CVE-2026-57092] Microsoft Windows VMSwitch Elevation of Privilege Vulnerability

Microsoft Windows VMSwitch Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-57092
Windows Server
Jul 14, 2026
Critical9.6MS Server

Critical [CVE-2026-48582] Microsoft Exchange Online Elevation of Privilege Vulnerability

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

CVE-2026-48582
Exchange Server
Jun 19, 2026
Critical10.0MS Server

Critical [CVE-2026-45480] Azure Active Directory Elevation of Privilege Vulnerability

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-45480
Windows Server
Jun 19, 2026
Critical9.8MS Server

Critical [CVE-2026-45657] Windows Kernel Remote Code Execution Vulnerability

Windows Kernel Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-45657
Windows Server
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-47291] HTTP.sys Remote Code Execution Vulnerability

HTTP.sys Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-47291
Windows Server
Jun 9, 2026
Critical9.1Vendor: HighMS Server

Critical [CVE-2026-45602] Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability

Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45602
Windows Server
Jun 9, 2026
Critical9.6Vendor: HighMS Server

Critical [CVE-2026-42904] Windows TCP/IP Elevation of Privilege Vulnerability

Windows TCP/IP Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42904
Windows Server
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-44815] DHCP Client Service Remote Code Execution Vulnerability

DHCP Client Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-44815
Windows Server
Jun 9, 2026
Critical9.1MS Server

Critical [CVE-2026-48579] Microsoft Exchange Online Information Disclosure Vulnerability

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

CVE-2026-48579
Exchange Server
Jun 4, 2026
Critical9.3MS Server

Critical [CVE-2026-40402] Windows Hyper-V Elevation of Privilege Vulnerability

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. Affected product named by the advisory: Windows Server 2022.

CVE-2026-40402
Windows Server
May 12, 2026
Critical9.8MS Server

Critical [CVE-2026-41096] Windows DNS Client Remote Code Execution Vulnerability

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025; Windows Server 2025 (Server Core installation).

CVE-2026-41096
Windows Server
May 12, 2026
Critical9.8MS Server

Critical [CVE-2026-41089] Windows Netlogon Remote Code Execution Vulnerability

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 8 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-41089
Windows Server
May 12, 2026
Critical9.8MS Server Exploited CISA KEV

Critical [CVE-2026-33824] Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2022, 23H2 Edition (Server Core installation); Windows Server 2025 (Server Core installation).

CVE-2026-33824
Windows Server
Apr 14, 2026
Critical9.8MS Server Exploited CISA KEV

Critical [CVE-2026-20963] Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-20963
SharePoint Server
Jan 13, 2026
Critical9.8MS Server Exploited CISA KEV

Critical [CVE-2025-53770] Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2025-53770
SharePoint Server
Jul 20, 2025
Critical9.0MS Server

Critical [CVE-2024-38124] Windows Netlogon Elevation of Privilege Vulnerability

Windows Netlogon Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2024-38124
Windows Server
Oct 8, 2024

← All vendors