Known vulnerabilities in Windows Server 2025 10.0.26100.2605 - page 39

Vendor: Microsoft
Version: 2025 10.0.26100.2605
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 1627
Public exploits: 49
Known exploited (KEV): 38
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2025 10.0.26100.2605 Windows Server 2025 10.0.26100.2605 is affected by 1627 vulnerabilities: 7 critical, 263 high, 300 medium, 1056 low Critical High Medium Low

Vulnerabilities (1627)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122541 - Heap-based Buffer Overflow
CVE-2026-21239
CWE-122 Low
No
No
2012 R2 6.3.9600.23022, 2012 6.2.9200.25923, 2016 10.0.14393.8868, 2019 10.0.17763.8389, 2022 23H2 10.0.25398.2149, 2022 10.0.20348.4711, 2022 10.0.20348.4773, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021054
#VU121460 - Stack-based buffer overflow
CVE-2023-31096
CWE-121 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB20260114106
#VU121454 - Use After Free
CVE-2026-20859
CWE-416 Low
No
No
2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB20260114103
#VU121453 - External Control of File Name or Path
CVE-2026-20872
CWE-73 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB20260114102
#VU121452 - External Control of File Name or Path
CVE-2026-20925
CWE-73 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB20260114102
#VU121451 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20834
CWE-22 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB20260114101
#VU121450 - Improper input validation
CVE-2026-20812
CWE-20 Medium
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB20260114100
#VU121449 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-20809
CWE-367 Low
No
No
2012 R2 6.3.9600.22968, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011499
#VU121448 - Information Exposure Through Log Files
CVE-2026-20818
CWE-532 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623 14.01.2026 SB2026011499
#VU121447 - Information Exposure Through an Error Message
CVE-2026-20838
CWE-209 Low
No
No
2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011499
#VU121446 - Heap-based Buffer Overflow
CVE-2024-55414
CWE-122 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011498
#VU121445 - External Control of File Name or Path
CVE-2026-20931
CWE-73 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011497
#VU121439 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20823
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121438 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20932
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121437 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20808
CWE-362 Low
No
No
2022 23H2 10.0.25398.2092, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121435 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20937
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121434 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20939
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011492
#VU121417 - Use After Free
CVE-2026-20870
CWE-416 Low
No
No
2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011470
#VU121405 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20869
CWE-362 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011458
#VU121391 - Heap-based Buffer Overflow
CVE-2026-20864
CWE-122 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011444


Showing elements 761 - 780 out of 1627