Known vulnerabilities in Windows Server - page 3

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137989 - Improper Privilege Management
CVE-2026-50295
CWE-269 Low
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137988 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-50384
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137987 - Improper Access Control
CVE-2026-50325
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137986 - Improper Access Control
CVE-2026-50297
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137985 - Use After Free
CVE-2026-50293
CWE-416 Low
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137984 - Integer overflow
CVE-2026-50298
CWE-190 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137983 - Exposure of sensitive information to an unauthorized actor
CVE-2026-49807
CWE-200 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137982 - Improper Access Control
CVE-2026-50351
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137981 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-49803
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137980 - Improper Access Control
CVE-2026-49805
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137979 - Missing Authentication for Critical Function
CVE-2026-50333
CWE-306 Low
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137978 - Heap-based Buffer Overflow
CVE-2026-49804
CWE-122 Medium
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137977 - Improper Access Control
CVE-2026-50311
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137976 - Integer underflow
CVE-2026-50308
CWE-191 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137975 - Resource exhaustion
CVE-2026-49799
CWE-400 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137974 - Heap-based Buffer Overflow
CVE-2026-49797
CWE-122 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137973 - Heap-based Buffer Overflow
CVE-2026-49796
CWE-122 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137972 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-49791
CWE-59 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137971 - Improper Access Control
CVE-2026-49790
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137970 - Stack-based buffer overflow
CVE-2026-49789
CWE-121 Low
No
No
2012 R2 6.3.9600.23291, 2012 6.2.9200.26226, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705


Showing elements 41 - 60 out of 6300