Known vulnerabilities in Windows Server 2025 10.0.26100.2605 - page 42

Vendor: Microsoft
Version: 2025 10.0.26100.2605
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 1627
Public exploits: 49
Known exploited (KEV): 38
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2025 10.0.26100.2605 Windows Server 2025 10.0.26100.2605 is affected by 1627 vulnerabilities: 7 critical, 263 high, 300 medium, 1056 low Critical High Medium Low

Vulnerabilities (1627)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121263 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20934
CWE-362 Medium
No
No
2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011390
#VU121260 - NULL Pointer Dereference
CVE-2026-20875
CWE-476 Medium
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011388
#VU121259 - Use After Free
CVE-2026-20854
CWE-416 Medium
No
No
2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011388
#VU121257 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20827
CWE-200 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011386
#VU121256 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20826
CWE-362 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011386
#VU121255 - Improper Access Control
CVE-2026-20825
CWE-284 Low
No
No
2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011385
#VU121254 - Use After Free
CVE-2026-20822
CWE-416 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011384
#VU121253 - Double Free
CVE-2026-20832
CWE-415 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011383
#VU121252 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20821
CWE-200 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011382
#VU121251 - Heap-based Buffer Overflow
CVE-2026-20820
CWE-122 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011381
#VU121248 - Heap-based Buffer Overflow
CVE-2026-20876
CWE-122 Low
No
No
2022 23H2 10.0.25398.2092, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011380
#VU121246 - Permissions, Privileges, and Access Controls
CVE-2026-20817
CWE-264 Low
Public exploit available
No
2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011377
#VU121245 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-20816
CWE-367 Low
No
No
2008 R2 6.1.7601.28117, 2008 6.0.6003.23717, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011376
#VU121244 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-21221
CWE-362 Low
No
No
2025 10.0.26100.7623 13.01.2026 SB2026011375
#VU121243 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20830
CWE-362 Low
No
No
2025 10.0.26100.7623 13.01.2026 SB2026011375
#VU121242 - Out-of-bounds read
CVE-2026-20851
CWE-125 Low
No
No
2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011375
#VU121241 - Out-of-bounds read
CVE-2026-20835
CWE-125 Low
No
No
2022 23H2 10.0.25398.2092, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011375
#VU121240 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20815
CWE-362 Low
No
No
2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011375
#VU121239 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20836
CWE-362 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011374
#VU121238 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20814
CWE-362 Low
No
No
2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB2026011374


Showing elements 821 - 840 out of 1627