Known vulnerabilities in Windows Server - page 35

Vendor: Microsoft
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 6300
Public exploits: 488
Known exploited (KEV): 268
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Windows Server Windows Server is affected by 6300 known vulnerabilities: 95 critical, 1270 high, 1244 medium, 3689 low Critical High Medium Low

Vulnerabilities (6300)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU126023 - Out-of-bounds read
CVE-2026-32076
CWE-125 Low
No
No
2012 R2 6.3.9600.23132, 2022 23H2 10.0.25398.2274, 2025 10.0.26100.32690 14.04.2026 SB20260414143
#VU126022 - Integer underflow
CVE-2026-27907
CWE-191 Low
No
No
2012 R2 6.3.9600.23132, 2022 23H2 10.0.25398.2274, 2025 10.0.26100.32690 14.04.2026 SB20260414143
#VU126021 - Improper input validation
CVE-2026-27928
CWE-20 High
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414142
#VU126019 - Improper Access Control
CVE-2026-26183
CWE-284 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414141
#VU126018 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-32091
CWE-362 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414140
#VU126017 - Double Free
CVE-2026-32219
CWE-415 Low
No
No
2012 R2 6.3.9600.23132, 2025 10.0.26100.32690 14.04.2026 SB20260414140
#VU126016 - Use After Free
CVE-2026-26181
CWE-416 Low
No
No
2012 R2 6.3.9600.23132, 2022 23H2 10.0.25398.2274, 2025 10.0.26100.32690 14.04.2026 SB20260414140
#VU126015 - Use of Uninitialized Resource
CVE-2026-26175
CWE-908 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414139
#VU126014 - Type confusion
CVE-2026-26162
CWE-843 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414138
#VU126013 - Untrusted Pointer Dereference
CVE-2026-26161
CWE-822 Low
No
No
2012 R2 6.3.9600.23132, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414134
#VU126012 - Missing Authentication for Critical Function
CVE-2026-26160
CWE-306 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414133
#VU126011 - Missing Authentication for Critical Function
CVE-2026-26159
CWE-306 Low
No
No
2012 R2 6.3.9600.23132, 2012 6.2.9200.26026, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414133
#VU126006 - Out-of-bounds read
CVE-2026-33096
CWE-125 Medium
No
No
2012 R2 6.3.9600.23132, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414130
#VU126004 - Untrusted Pointer Dereference
CVE-2026-23670
CWE-822 Low
No
No
2012 R2 6.3.9600.23132, 2016 10.0.14393.9060, 2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414128
#VU126003 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-25184
CWE-362 Low
No
No
2012 R2 6.3.9600.23132, 2022 23H2 10.0.25398.2274, 2025 10.0.26100.32690 14.04.2026 SB20260414127
#VU126002 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-20930
CWE-362 Low
No
No
2019 10.0.17763.8644, 2022 23H2 10.0.25398.2274, 2022 10.0.20348.5020, 2025 10.0.26100.32690 14.04.2026 SB20260414126
#VU123879 - Exposure of sensitive information to an unauthorized actor
CVE-2026-25185
CWE-200 Medium
No
No
2012 R2 6.3.9600.23074, 2012 6.2.9200.25973, 2016 10.0.14393.8957, 2019 10.0.17763.8511, 2022 23H2 10.0.25398.2207, 2022 10.0.20348.4830, 2022 10.0.20348.4893, 2025 10.0.26100.32463, 2025 10.0.26100.32522 11.03.2026 SB2026031122
#VU123878 - Out-of-bounds read
CVE-2026-25174
CWE-125 Low
No
No
2012 R2 6.3.9600.23074, 2012 6.2.9200.25973, 2016 10.0.14393.8957, 2019 10.0.17763.8511, 2022 23H2 10.0.25398.2207, 2022 10.0.20348.4830, 2022 10.0.20348.4893, 2025 10.0.26100.32463, 2025 10.0.26100.32522 11.03.2026 SB2026031121
#VU123785 - NULL Pointer Dereference
CVE-2026-25165
CWE-476 Low
No
No
2012 R2 6.3.9600.23074, 2012 6.2.9200.25973, 2016 10.0.14393.8957, 2019 10.0.17763.8511, 2022 23H2 10.0.25398.2207, 2022 10.0.20348.4830, 2022 10.0.20348.4893, 2025 10.0.26100.32463, 2025 10.0.26100.32522 11.03.2026 SB2026031101
#VU123784 - Deserialization of Untrusted Data
CVE-2026-25166
CWE-502 Medium
No
No
2016 10.0.14393.8957, 2019 10.0.17763.8511, 2022 23H2 10.0.25398.2207, 2022 10.0.20348.4830, 2022 10.0.20348.4893, 2025 10.0.26100.32463 10.03.2026 SB20260310131


Showing elements 681 - 700 out of 6300