Skip to content
VulniPulse

Microsoft Server Security Advisories & CVEs

1207 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your MS Server device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.

Official source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server advisories

High8.8MS Server

High [CVE-2026-96940] Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 14; Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server Subscription Edition RTM; Microsoft Exchange Server 2019 Cumulative Update 15.

CVE-2026-96940
Exchange Server
Oct 2, 2026
High7.8Vendor: CriticalMS Server

High [CVE-2026-83498] Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-83498
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-84000] Microsoft Graphics Component Remote Code Execution Vulnerability

Microsoft Graphics Component Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-84000
Windows Server
Sep 8, 2026
High8.1MS Server

High [CVE-2026-83997] Windows Message Queuing Remote Code Execution Vulnerability

Windows Message Queuing Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-83997
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-83995] Windows NTFS Elevation of Privilege Vulnerability

Windows NTFS Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-83995
Windows Server
Sep 8, 2026
High8.8MS Server

High [CVE-2026-83992] Windows Imaging Component Remote Code Execution Vulnerability

Windows Imaging Component Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-83992
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-83990] Microsoft Graphics Component Elevation of Privilege Vulnerability

Microsoft Graphics Component Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-83990
Windows Server
Sep 8, 2026
High7.5MS Server

High [CVE-2026-83989] Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability

Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-83989
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-83985] Windows Biometric Service Elevation of Privilege Vulnerability

Windows Biometric Service Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-83985
Windows Server
Sep 8, 2026
High8.8MS Server

High [CVE-2026-69598] Windows iSCSI Remote Code Execution Vulnerability

Windows iSCSI Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-69598
Windows Server
Sep 8, 2026
High7.8MS Server

High [CVE-2026-72965] Windows WebClient Service Elevation of Privilege Vulnerability

Windows WebClient Service Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-72965
Windows Server
Sep 8, 2026
High8.1Vendor: CriticalMS Server

High [CVE-2026-69530] Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.

CVE-2026-69530
Windows Server
Sep 8, 2026
High7.8MS Server Exploited CISA KEV

High [CVE-2026-81963] Windows Update Stack Elevation of Privilege Vulnerability

Windows Update Stack Elevation of Privilege Vulnerability Affected product named by the advisory: Windows Server 2025.

CVE-2026-81963
Windows Server
Sep 8, 2026
High7.0MS Server

High [CVE-2026-83940] Windows Device Association Service Elevation of Privilege Vulnerability

Windows Device Association Service Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.

CVE-2026-83940
Windows Server
Sep 8, 2026
High8.8Vendor: CriticalMS Server

High [CVE-2026-81955] Windows Graphics Component Remote Code Execution Vulnerability

Windows Graphics Component Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-81955
Windows Server
Sep 8, 2026
High8.2MS Server

High [CVE-2026-81354] Windows Hello Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation).

CVE-2026-81354
Windows Server
Sep 8, 2026
High8.8MS Server

High [CVE-2026-80096] Windows Remote Desktop Services Elevation of Privilege Vulnerability

Windows Remote Desktop Services Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-80096
Windows Server
Sep 8, 2026
High8.8MS Server

High [CVE-2026-77481] Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SQL Server 2017; Microsoft SQL Server 2019; Microsoft SQL Server 2022; Microsoft SQL Server 2025.

CVE-2026-77481
SQL Server
Sep 8, 2026
High8.8MS Server

High [CVE-2026-66819] Microsoft SQL Server Elevation of Privilege Vulnerability

Microsoft SQL Server Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft SQL Server 2017; Microsoft SQL Server 2019; Microsoft SQL Server 2022; Microsoft SQL Server 2025.

CVE-2026-66819
SQL Server
Sep 8, 2026
High7.0MS Server

High [CVE-2026-78457] Windows Security Health Service Elevation of Privilege Vulnerability

Windows Security Health Service Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-78457
Windows Server
Sep 8, 2026

← All vendors