Microsoft Windows Server 2025 vulnerabilities
1,706 known vulnerabilities affecting microsoft/windows_server_2025.
Total CVEs
1,706
CISA KEV
38
actively exploited
Public exploits
32
Exploited in wild
46
Severity breakdown
CRITICAL40HIGH1216MEDIUM441LOW9
Vulnerabilities
Page 20 of 86
CVE-2026-50327P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50327 [HIGH] CWE-122 CVE-2026-50327: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2026-58542P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-58542 [HIGH] CWE-122 CVE-2026-58542: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50680P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50680 [HIGH] CWE-122 CVE-2026-50680: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges lo
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35420P3HIGHCVSS 7.8fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-35420 [HIGH] CWE-122 CVE-2026-35420: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50477P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50477 [HIGH] CWE-122 CVE-2026-50477: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56650P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-56650 [HIGH] CWE-122 CVE-2026-56650: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50484P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50484 [HIGH] CWE-122 CVE-2026-50484: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58538P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-58538 [HIGH] CWE-122 CVE-2026-58538: Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50679P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50679 [HIGH] CWE-122 CVE-2026-50679: Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to el
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50363P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50363 [HIGH] CWE-122 CVE-2026-50363: Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate pr
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50494P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50494 [HIGH] CWE-122 CVE-2026-50494: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50417P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50417 [HIGH] CWE-20 CVE-2026-50417: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-56175P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-56175 [HIGH] CWE-122 CVE-2026-56175: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges local
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33841P3HIGHCVSS 7.8fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-33841 [HIGH] CWE-122 CVE-2026-33841: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377P3HIGHCVSS 7.8fixed in 10.0.26100.32772≥ 10.0.26100.0, < 10.0.26100.328602026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26180P3HIGHCVSS 7.8fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-26180 [HIGH] CWE-122 CVE-2026-26180: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48814P3HIGHCVSS 7.5fixed in 10.0.26100.4652≥ 10.0.26100.0, < 10.0.26100.46522025-07-08
CVE-2025-48814 [HIGH] CWE-306 CVE-2025-48814: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an u
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50400P3HIGHCVSS 7.8fixed in 10.0.26100.33158≥ 10.0.26100.0, < 10.0.26100.331582026-07-14
CVE-2026-50400 [HIGH] CWE-121 CVE-2026-50400: Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privil
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26634P3HIGHCVSS 7.5fixed in 10.0.26100.3194≥ 10.0.26100.0, < 10.0.26100.31942025-03-11
CVE-2025-26634 [HIGH] CWE-122 CVE-2025-26634: Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-26178P3HIGHCVSS 8.8fixed in 10.0.26100.32690≥ 10.0.26100.0, < 10.0.26100.326902026-04-14
CVE-2026-26178 [HIGH] CWE-190 CVE-2026-26178: Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized att
Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.
nvd