Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 86 of 227
CVE-2023-38162P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.62522023-09-12
CVE-2023-38162 [HIGH] CWE-191 CVE-2023-38162: DHCP Server Service Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2021-26415P3HIGHCVSS 7.8v20h2v1909+2 more2021-04-13
CVE-2021-26415 [HIGH] CWE-20 CVE-2021-26415: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1466P3HIGHCVSS 7.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1466 [HIGH] CVE-2020-1466: A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an atta
A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RD Gateway service on the target system to stop responding.
To exploit this vulnerability, an attacker wou
nvd
CVE-2021-26868P3HIGHCVSS 7.8v20h2v1909+2 more2021-03-11
CVE-2021-26868 [HIGH] CWE-119 CVE-2021-26868: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-32009P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-32009 [HIGH] CWE-284 CVE-2023-32009: Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability
nvd
CVE-2024-21371P3HIGHCVSS 7.0fixed in 10.0.14393.6709≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21371 [HIGH] CWE-367 CVE-2024-21371: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-21878P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21878 [HIGH] CVE-2022-21878: Windows Geolocation Service Remote Code Execution Vulnerability
Windows Geolocation Service Remote Code Execution Vulnerability
nvd
CVE-2020-0908P3HIGHCVSS 7.5v1903v1909+2 more2020-09-11
CVE-2020-0908 [HIGH] CVE-2020-0908: <p>A remote code execution vulnerability exists when the Windows Text Service Module improperly hand
A remote code execution vulnerability exists when the Windows Text Service Module improperly handles memory. An attacker who successfully exploited the vulnerability could gain execution on a victim system.
An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft Edge (Chromium-based), and then convince
nvd
CVE-2022-21992P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.49462022-02-09
CVE-2022-21992 [HIGH] CVE-2022-21992: Windows Mobile Device Management Remote Code Execution Vulnerability
Windows Mobile Device Management Remote Code Execution Vulnerability
nvd
CVE-2021-1726P3HIGHCVSS 8.0v20h2v1909+1 more2021-02-25
CVE-2021-1726 [HIGH] CVE-2021-1726: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2022-29115P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29115 [HIGH] CVE-2022-29115: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2021-27089P3HIGHCVSS 7.8v20h2v1909+2 more2021-04-13
CVE-2021-27089 [HIGH] CVE-2021-27089: Microsoft Internet Messaging API Remote Code Execution Vulnerability
Microsoft Internet Messaging API Remote Code Execution Vulnerability
nvd
CVE-2018-8335P3HIGHCVSS 7.5v(Server Core installation)2018-09-13
CVE-2018-8335 [HIGH] CVE-2018-8335: A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacke
A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2022-22027P3HIGHCVSS 7.8v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22027 [HIGH] CVE-2022-22027: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-22024P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22024 [HIGH] CVE-2022-22024: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2023-35317P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35317 [HIGH] CWE-502 CVE-2023-35317: Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
nvd
CVE-2026-23668P3HIGHCVSS 7.0fixed in 10.0.14393.8957≥ 10.0.14393.0, < 10.0.14393.89572026-03-10
CVE-2026-23668 [HIGH] CWE-362 CVE-2026-23668: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38127P3HIGHCVSS 7.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38127 [HIGH] CWE-126 CVE-2024-38127: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2026-49805P3HIGHCVSS 7.0fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49805 [HIGH] CWE-284 CVE-2026-49805: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27473P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27473 [HIGH] CWE-400 CVE-2025-27473: Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny servic
Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
nvd