cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 27 of 227
CVE-2024-26230P3HIGHCVSS 7.8fixed in 10.0.14393.6897≥ 10.0.14393.0, < 10.0.14393.68972024-04-09
CVE-2024-26230 [HIGH] CWE-416 CVE-2024-26230: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2025-21285P3HIGHCVSS 7.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21285 [HIGH] CWE-476 CVE-2025-21285: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2021-28445P3HIGHCVSS 8.8v20h2v1909+2 more2021-04-13
CVE-2021-28445 [HIGH] CVE-2021-28445: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2026-50380P3CRITICALCVSS 9.6fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50380 [CRITICAL] CWE-122 CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21371P3HIGHCVSS 8.8fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33780P3HIGHCVSS 8.8v20h2v2004+1 more2021-07-14
CVE-2021-33780 [HIGH] CVE-2021-33780: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2018-8634P3HIGHCVSS 8.8v1709v1803+1 more2018-12-12
CVE-2018-8634 [HIGH] CVE-2018-8634: A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to prop A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka "Microsoft Text-To-Speech Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2022-23294P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.50062022-03-09
CVE-2022-23294 [HIGH] CVE-2022-23294: Windows Event Tracing Remote Code Execution Vulnerability Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2021-24088P3HIGHCVSS 8.8v20h2v1909+2 more2021-02-25
CVE-2021-24088 [HIGH] CVE-2021-24088: Windows Local Spooler Remote Code Execution Vulnerability Windows Local Spooler Remote Code Execution Vulnerability
nvd
CVE-2026-24294P3HIGHCVSS 7.8fixed in 10.0.14393.8957≥ 10.0.14393.0, < 10.0.14393.89572026-03-10
CVE-2026-24294 [HIGH] CWE-287 CVE-2026-24294: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50177P3HIGHCVSS 8.1fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50177 [HIGH] CWE-362 CVE-2025-50177: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-28455P3HIGHCVSS 8.8v20h2v1909+2 more2021-05-11
CVE-2021-28455 [HIGH] CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2022-24487P3HIGHCVSS 8.8v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24487 [HIGH] CVE-2022-24487: Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
nvd
CVE-2021-34525P3HIGHCVSS 8.8v20h2v2004+1 more2021-07-14
CVE-2021-34525 [HIGH] CVE-2021-34525: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-34508P3HIGHCVSS 8.8v20h2v20042021-07-14
CVE-2021-34508 [HIGH] CVE-2021-34508: Windows Kernel Remote Code Execution Vulnerability Windows Kernel Remote Code Execution Vulnerability
nvd
CVE-2020-1412P3HIGHCVSS 8.8v1903v1909+1 more2020-07-14
CVE-2020-1412 [HIGH] CWE-269 CVE-2020-1412: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2025-21407P3HIGHCVSS 8.8fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21406P3HIGHCVSS 8.8fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21406 [HIGH] CWE-416 CVE-2025-21406: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21190P3HIGHCVSS 8.8fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21201P3HIGHCVSS 8.8fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability Windows Telephony Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase