Known vulnerabilities in Windows Server 2025 10.0.26100.2605 - page 30

Vendor: Microsoft
Version: 2025 10.0.26100.2605
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 1627
Public exploits: 49
Known exploited (KEV): 38
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2025 10.0.26100.2605 Windows Server 2025 10.0.26100.2605 is affected by 1627 vulnerabilities: 7 critical, 263 high, 300 medium, 1056 low Critical High Medium Low

Vulnerabilities (1627)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126206 - Heap-based Buffer Overflow
CVE-2026-32221
CWE-122 High
No
No
2012 R2 6.3.9600.23132, 2025 10.0.26100.32690 15.04.2026 SB20260415127
#VU126186 - Improper Access Control
CVE-2026-32220
CWE-284 Low
No
No
2012 R2 6.3.9600.23132, 2025 10.0.26100.32690 15.04.2026 SB20260415123
#VU126184 - Use After Free
CVE-2026-32157
CWE-416 High
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415122
#VU126183 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-32090
CWE-362 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415121
#VU126182 - Use After Free
CVE-2026-32089
CWE-416 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415121
#VU126181 - Exposure of sensitive information to an unauthorized actor
CVE-2026-32085
CWE-200 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415111
#VU126180 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-32083
CWE-362 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415110
#VU126172 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-32082
CWE-362 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415110
#VU126166 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-32068
CWE-362 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415110
#VU126165 - Heap-based Buffer Overflow
CVE-2026-26176
CWE-122 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB20260415102
#VU126164 - Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-20928
CWE-212 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041589
#VU126163 - Heap-based Buffer Overflow
CVE-2026-32223
CWE-122 Low
Public exploit available
No
2012 R2 6.3.9600.23132, 2025 10.0.26100.32690 15.04.2026 SB2026041588
#VU126162 - Use After Free
CVE-2026-33098
CWE-416 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041587
#VU126159 - Improper Privilege Management
CVE-2026-32181
CWE-269 Low
No
No
2012 R2 6.3.9600.23132, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041584
#VU126158 - Command injection
CVE-2026-32183
CWE-77 High
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041583
#VU126157 - Exposure of sensitive information to an unauthorized actor
CVE-2026-33829
CWE-200 Medium
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041583
#VU126156 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-32212
CWE-59 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041582
#VU126155 - Improper Access Control
CVE-2026-32214
CWE-284 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041582
#VU126154 - Type confusion
CVE-2026-20806
CWE-843 Low
No
No
2012 R2 6.3.9600.23132, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041581
#VU126151 - Insecure Storage of Sensitive Information
CVE-2026-26152
CWE-922 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 15.04.2026 SB2026041579


Showing elements 581 - 600 out of 1627