Skip to content
VulniPulse

Microsoft Server Security Advisories & CVEs

1358 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your MS Server device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.

Official source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server advisories

Medium6.5Vendor: HighMS Server

Medium [CVE-2026-54126] Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012.

CVE-2026-54126
Windows Server
Jul 14, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-50468] Microsoft SQL Server Information Disclosure Vulnerability

Microsoft SQL Server Information Disclosure Vulnerability Affected product named by the advisory: Microsoft SQL Server 2025.

CVE-2026-50468
SQL Server
Jul 14, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-56168] Windows SMB Server Denial of Service Vulnerability

Windows SMB Server Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-56168
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-56184] Win32k Information Disclosure Vulnerability

Win32k Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-56184
Windows Server
Jul 14, 2026
Medium5.9Vendor: HighMS Server

Medium [CVE-2026-56649] Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-56649
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-57083] Windows Media Photo Codec Information Disclosure Vulnerability

Windows Media Photo Codec Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-57083
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-57085] Windows Print Spooler Information Disclosure Vulnerability

Windows Print Spooler Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-57085
Windows Server
Jul 14, 2026
Medium6.8Vendor: HighMS Server

Medium [CVE-2026-58528] Windows USB Audio Class Driver Information Disclosure Vulnerability

Windows USB Audio Class Driver Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-58528
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-58547] Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-58547
Windows Server
Jul 14, 2026
Medium6.0Vendor: HighMS Server

Medium [CVE-2026-58638] Windows Boot Loader Security Feature Bypass Vulnerability

Windows Boot Loader Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-58638
Windows Server
Jul 14, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-50659] .NET Spoofing Vulnerability

.NET Spoofing Vulnerability Affected products named by the advisory: Microsoft.NET Framework 4.8 on Windows Server 2016; Microsoft.NET Framework 4.8 on Windows Server 2012; Microsoft.NET Framework 4.8 on Windows Server 2012 R2; Microsoft.NET Framework 3.5 AND 4.8 on Windows Server 2019; and 4 more. Affected products named by the advisory: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022; Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019; Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016; Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012.

CVE-2026-50659
Windows Server
Jul 14, 2026
High8.8MS Server

High [CVE-2026-54998] Microsoft Exchange Online Elevation of Privilege Vulnerability

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

CVE-2026-54998
Exchange Server
Jul 2, 2026
Critical9.6MS Server

Critical [CVE-2026-48582] Microsoft Exchange Online Elevation of Privilege Vulnerability

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

CVE-2026-48582
Exchange Server
Jun 19, 2026
Critical10.0MS Server

Critical [CVE-2026-45480] Azure Active Directory Elevation of Privilege Vulnerability

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-45480
Windows Server
Jun 19, 2026
Critical9.8MS Server

Critical [CVE-2026-45657] Windows Kernel Remote Code Execution Vulnerability

Windows Kernel Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-45657
Windows Server
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-47291] HTTP.sys Remote Code Execution Vulnerability

HTTP.sys Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-47291
Windows Server
Jun 9, 2026
Critical9.1Vendor: HighMS Server

Critical [CVE-2026-45602] Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability

Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45602
Windows Server
Jun 9, 2026
Critical9.6Vendor: HighMS Server

Critical [CVE-2026-42904] Windows TCP/IP Elevation of Privilege Vulnerability

Windows TCP/IP Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42904
Windows Server
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-44815] DHCP Client Service Remote Code Execution Vulnerability

DHCP Client Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-44815
Windows Server
Jun 9, 2026
High8.4Vendor: CriticalMS Server

High [CVE-2026-45458] Microsoft Outlook and Word Remote Code Execution Vulnerability

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-45458
SharePoint Server
Jun 9, 2026

← All vendors