Skip to content
VulniPulse

Microsoft Server Security Advisories & CVEs

360 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your MS Server device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.

Official source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server advisories

Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50431] Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability

Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50431
Windows Server
Jul 14, 2026
Medium6.2Vendor: HighMS Server

Medium [CVE-2026-50420] HTTP.sys Information Disclosure Vulnerability

HTTP.sys Information Disclosure Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-50420
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50394] Windows Media Information Disclosure Vulnerability

Windows Media Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50394
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50483] Windows Graphics Component Information Disclosure Vulnerability

Windows Graphics Component Information Disclosure Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-50483
Windows Server
Jul 14, 2026
Medium4.5Vendor: HighMS Server

Medium [CVE-2026-50485] Windows Hyper-V Denial of Service Vulnerability

Windows Hyper-V Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50485
Windows Server
Jul 14, 2026
Medium6.8Vendor: HighMS Server

Medium [CVE-2026-50492] Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-50492
Windows Server
Jul 14, 2026
Medium6.1Vendor: HighMS Server PoC reported

Medium [CVE-2026-50661] Windows BitLocker Security Feature Bypass Vulnerability

Windows BitLocker Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-50661
Windows Server
Jul 14, 2026
Medium6.8Vendor: HighMS Server

Medium [CVE-2026-50668] Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-50668
Windows Server
Jul 14, 2026
Medium4.8Vendor: HighMS Server

Medium [CVE-2026-50684] Active Directory Federation Server Spoofing Vulnerability

Active Directory Federation Server Spoofing Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-50684
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-50681] Windows Secure Channel Information Disclosure Vulnerability

Windows Secure Channel Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-50681
Windows Server
Jul 14, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-54126] Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012.

CVE-2026-54126
Windows Server
Jul 14, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-50468] Microsoft SQL Server Information Disclosure Vulnerability

Microsoft SQL Server Information Disclosure Vulnerability Affected product named by the advisory: Microsoft SQL Server 2025.

CVE-2026-50468
SQL Server
Jul 14, 2026
Medium6.5Vendor: HighMS Server

Medium [CVE-2026-56168] Windows SMB Server Denial of Service Vulnerability

Windows SMB Server Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-56168
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-56184] Win32k Information Disclosure Vulnerability

Win32k Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-56184
Windows Server
Jul 14, 2026
Medium5.9Vendor: HighMS Server

Medium [CVE-2026-56649] Windows Network File System Remote Code Execution Vulnerability

Windows Network File System Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-56649
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-57083] Windows Media Photo Codec Information Disclosure Vulnerability

Windows Media Photo Codec Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-57083
Windows Server
Jul 14, 2026
Medium6.2Vendor: HighMS Server

Medium [CVE-2026-57095] Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-57095
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-57085] Windows Print Spooler Information Disclosure Vulnerability

Windows Print Spooler Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-57085
Windows Server
Jul 14, 2026
Medium6.8Vendor: HighMS Server

Medium [CVE-2026-58528] Windows USB Audio Class Driver Information Disclosure Vulnerability

Windows USB Audio Class Driver Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-58528
Windows Server
Jul 14, 2026
Medium5.5Vendor: HighMS Server

Medium [CVE-2026-58547] Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-58547
Windows Server
Jul 14, 2026

← All vendors