Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 165 of 198
CVE-2026-20937P4MEDIUMCVSS 5.5fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20937 [MEDIUM] CWE-200 CVE-2026-20937: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42972P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42972 [MEDIUM] CWE-200 CVE-2026-42972: Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized a
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42971P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42971 [MEDIUM] CWE-200 CVE-2026-42971: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2025-60706P4MEDIUMCVSS 5.5fixed in 10.0.17763.8027≥ 10.0.17763.0, < 10.0.17763.80272025-11-11
CVE-2025-60706 [MEDIUM] CWE-125 CVE-2025-60706: Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32085P4MEDIUMCVSS 5.5fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32085 [MEDIUM] CWE-200 CVE-2026-32085: Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows a
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21340P4MEDIUMCVSS 5.5fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21340 [MEDIUM] CWE-284 CVE-2025-21340: Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
nvd
CVE-2025-49684P4MEDIUMCVSS 5.5fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49684 [MEDIUM] CWE-126 CVE-2025-49684: Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locall
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2024-21362P4MEDIUMCVSS 5.5fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21362 [MEDIUM] CWE-367 CVE-2024-21362: Windows Kernel Security Feature Bypass Vulnerability
Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2026-32081P4MEDIUMCVSS 5.5fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32081 [MEDIUM] CWE-200 CVE-2026-32081: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42973P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42973 [MEDIUM] CWE-200 CVE-2026-42973: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42970P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42970 [MEDIUM] CWE-200 CVE-2026-42970: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59184P4MEDIUMCVSS 5.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59184 [MEDIUM] CWE-200 CVE-2025-59184: Exposure of sensitive information to an unauthorized actor in Windows High Availability Services all
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42968P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42968 [MEDIUM] CWE-125 CVE-2026-42968: Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-44805P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-44805 [MEDIUM] CWE-416 CVE-2026-44805: Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny s
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
nvd
CVE-2026-34349P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-34349 [MEDIUM] CWE-200 CVE-2026-34349: Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50394P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50394 [MEDIUM] CWE-200 CVE-2026-50394: Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50334P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50334 [MEDIUM] CWE-200 CVE-2026-50334: Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authori
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50339P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50339 [MEDIUM] CWE-200 CVE-2026-50339: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-33842P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-33842 [MEDIUM] CWE-200 CVE-2026-33842: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50409P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50409 [MEDIUM] CWE-200 CVE-2026-50409: Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an autho
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.
nvd