Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 78 of 227
CVE-2025-49761P3HIGHCVSS 7.8fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-49761 [HIGH] CWE-416 CVE-2025-49761: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50155P3HIGHCVSS 7.8fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50155 [HIGH] CWE-122 CVE-2025-50155: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53725P3HIGHCVSS 7.8fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53725 [HIGH] CWE-843 CVE-2025-53725: Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows a
Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54102P3HIGHCVSS 7.8fixed in 10.0.14393.8422≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-54102 [HIGH] CWE-416 CVE-2025-54102: Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevat
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53132P3HIGHCVSS 7.8fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53132 [HIGH] CWE-362 CVE-2025-53132: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33838P3HIGHCVSS 7.8fixed in 10.0.14393.9140≥ 10.0.14393.0, < 10.0.14393.91402026-05-12
CVE-2026-33838 [HIGH] CWE-415 CVE-2026-33838: Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50152P3HIGHCVSS 7.8≤ 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-50152 [HIGH] CWE-125 CVE-2025-50152: Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59505P3HIGHCVSS 7.8fixed in 10.0.14393.8594≥ 10.0.14393.0, < 10.0.14393.85942025-11-11
CVE-2025-59505 [HIGH] CWE-415 CVE-2025-59505: Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60713P3HIGHCVSS 7.8fixed in 10.0.14393.8594≥ 10.0.14393.0, < 10.0.14393.85942025-11-11
CVE-2025-60713 [HIGH] CWE-822 CVE-2025-60713: Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authoriz
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20822P3HIGHCVSS 7.8fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20822 [HIGH] CWE-416 CVE-2026-20822: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23673P3HIGHCVSS 7.8fixed in 10.0.14393.8957≥ 10.0.14393.0, < 10.0.14393.89572026-03-10
CVE-2026-23673 [HIGH] CWE-125 CVE-2026-23673: Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62466P3HIGHCVSS 7.8fixed in 10.0.14393.8688≥ 10.0.14393.0, < 10.0.14393.86882025-12-09
CVE-2025-62466 [HIGH] CWE-476 CVE-2025-62466: Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47159P3HIGHCVSS 7.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-47159 [HIGH] CWE-693 CVE-2025-47159: Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an author
Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45607P3HIGHCVSS 7.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45607 [HIGH] CWE-125 CVE-2026-45607: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59514P3HIGHCVSS 7.8fixed in 10.0.14393.8594≥ 10.0.14393.0, < 10.0.14393.85942025-11-11
CVE-2025-59514 [HIGH] CWE-269 CVE-2025-59514: Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevat
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54111P3HIGHCVSS 7.8fixed in 10.0.14393.8422≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-54111 [HIGH] CWE-416 CVE-2025-54111: Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate pr
Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40404P3HIGHCVSS 7.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-40404 [HIGH] CWE-122 CVE-2026-40404: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
nvd
CVE-2026-25175P3HIGHCVSS 7.8fixed in 10.0.14393.8957≥ 10.0.14393.0, < 10.0.14393.89572026-03-10
CVE-2026-25175 [HIGH] CWE-125 CVE-2026-25175: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49726P3HIGHCVSS 7.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49726 [HIGH] CWE-416 CVE-2025-49726: Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26687P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-26687 [HIGH] CWE-416 CVE-2025-26687: Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.
nvd