Microsoft Windows Server

Our sources currently list 3151 known vulnerabilities affecting Microsoft Windows Server. 75 are rated critical severity. 106 of 3151 are actively exploited according to CISA, the most recent added 14 July 2026.

Last updated: 22 July 2026, 20:30 AEST

No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.

Known vulnerabilities in Microsoft Windows Server, highest risk first.Showing the 50 highest-risk of 3151 total.
CVESeverityExploitationPublishedSummary
CVE-2023-44487High (7.5)Actively exploitedThe HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through…
CVE-2025-59287Critical (9.8)Actively exploitedDeserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVE-2021-34527High (8.8)Actively exploited · ransomware<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this v…
CVE-2022-30190High (7.8)Actively exploited · ransomwareA remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerab…
CVE-2023-36884High (7.5)Actively exploited · ransomwareWindows Search Remote Code Execution Vulnerability
CVE-2024-29059High (7.5)Actively exploited.NET Framework Information Disclosure Vulnerability
CVE-2021-40444High (8.8)Actively exploited · ransomware<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to expl…
CVE-2024-21412High (8.1)Actively exploited · ransomwareInternet Shortcut Files Security Feature Bypass Vulnerability
CVE-2023-36025High (8.8)Actively exploitedWindows SmartScreen Security Feature Bypass Vulnerability
CVE-2024-38112High (7.5)Actively exploitedWindows MSHTML Platform Spoofing Vulnerability
CVE-2022-26923High (8.8)Actively exploitedActive Directory Domain Services Elevation of Privilege Vulnerability
CVE-2025-33053High (8.8)Actively exploitedExternal control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
CVE-2024-43451Medium (6.5)Actively exploitedNTLM Hash Disclosure Spoofing Vulnerability
CVE-2025-33073High (8.8)Actively exploitedImproper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2023-24880Medium (4.4)Actively exploited · ransomwareWindows SmartScreen Security Feature Bypass Vulnerability
CVE-2022-44698Medium (5.4)Actively exploited · ransomwareWindows SmartScreen Security Feature Bypass Vulnerability
CVE-2021-42287High (7.5)Actively exploited · ransomwareActive Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-40449High (7.8)Actively exploited · ransomwareWin32k Elevation of Privilege Vulnerability
CVE-2021-42278High (7.5)Actively exploited · ransomwareActive Directory Domain Services Elevation of Privilege Vulnerability
CVE-2024-30088High (7.0)Actively exploited · ransomwareWindows Kernel Elevation of Privilege Vulnerability
CVE-2022-34713High (7.8)Actively exploitedMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CVE-2024-43572High (7.8)Actively exploitedMicrosoft Management Console Remote Code Execution Vulnerability
CVE-2026-32202Medium (4.3)Actively exploitedProtection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-24054Medium (6.5)Actively exploitedExternal control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2022-21882High (7.0)Actively exploitedWin32k Elevation of Privilege Vulnerability
CVE-2022-21971High (7.8)Actively exploitedWindows Runtime Remote Code Execution Vulnerability
CVE-2024-43461High (8.8)Actively exploitedWindows MSHTML Platform Spoofing Vulnerability
CVE-2024-21338High (7.8)Actively exploited · ransomwareWindows Kernel Elevation of Privilege Vulnerability
CVE-2023-28252High (7.8)Actively exploited · ransomwareWindows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2024-29988High (8.8)Actively exploitedSmartScreen Prompt Security Feature Bypass Vulnerability
CVE-2013-3900Medium (5.5)Actively exploitedWhy is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the …
CVE-2024-43573Medium (6.5)Actively exploitedWindows MSHTML Platform Spoofing Vulnerability
CVE-2023-36874High (7.8)Actively exploitedWindows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2023-21674High (8.8)Actively exploitedWindows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVE-2022-21999High (7.8)Actively exploited · ransomwareWindows Print Spooler Elevation of Privilege Vulnerability
CVE-2024-38178High (7.5)Actively exploitedScripting Engine Memory Corruption Vulnerability
CVE-2025-26633High (7.0)Actively exploited · ransomwareImproper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
CVE-2024-21351High (7.6)Actively exploitedWindows SmartScreen Security Feature Bypass Vulnerability
CVE-2022-37969High (7.8)Actively exploitedWindows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2024-38193High (7.8)Actively exploitedWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2023-36802High (7.8)Actively exploitedMicrosoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVE-2026-21510High (8.8)Actively exploitedProtection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
CVE-2024-49138High (7.8)Actively exploitedWindows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2024-35250High (7.8)Actively exploitedWindows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2022-41128High (8.8)Actively exploitedWindows Scripting Languages Remote Code Execution Vulnerability
CVE-2023-29360High (8.4)Actively exploitedMicrosoft Streaming Service Elevation of Privilege Vulnerability
CVE-2025-30397High (7.5)Actively exploitedAccess of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
CVE-2023-36563Medium (6.5)Actively exploitedMicrosoft WordPad Information Disclosure Vulnerability
CVE-2021-41379Medium (5.5)Actively exploited · ransomwareWindows Installer Elevation of Privilege Vulnerability
CVE-2022-22047High (7.8)Actively exploitedWindows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.

Let's talk

106 of these are being actively exploited right now.

Our Newcastle team can audit your Microsoft estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.