Microsoft Windows Server
Our sources currently list 3151 known vulnerabilities affecting Microsoft Windows Server. 75 are rated critical severity. 106 of 3151 are actively exploited according to CISA, the most recent added 14 July 2026.
Last updated: 22 July 2026, 20:30 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2023-44487 | High (7.5) | Actively exploited | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through… | |
| CVE-2025-59287 | Critical (9.8) | Actively exploited | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | |
| CVE-2021-34527 | High (8.8) | Actively exploited · ransomware | <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this v… | |
| CVE-2022-30190 | High (7.8) | Actively exploited · ransomware | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerab… | |
| CVE-2023-36884 | High (7.5) | Actively exploited · ransomware | Windows Search Remote Code Execution Vulnerability | |
| CVE-2024-29059 | High (7.5) | Actively exploited | .NET Framework Information Disclosure Vulnerability | |
| CVE-2021-40444 | High (8.8) | Actively exploited · ransomware | <p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to expl… | |
| CVE-2024-21412 | High (8.1) | Actively exploited · ransomware | Internet Shortcut Files Security Feature Bypass Vulnerability | |
| CVE-2023-36025 | High (8.8) | Actively exploited | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2024-38112 | High (7.5) | Actively exploited | Windows MSHTML Platform Spoofing Vulnerability | |
| CVE-2022-26923 | High (8.8) | Actively exploited | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2025-33053 | High (8.8) | Actively exploited | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | |
| CVE-2024-43451 | Medium (6.5) | Actively exploited | NTLM Hash Disclosure Spoofing Vulnerability | |
| CVE-2025-33073 | High (8.8) | Actively exploited | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | |
| CVE-2023-24880 | Medium (4.4) | Actively exploited · ransomware | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2022-44698 | Medium (5.4) | Actively exploited · ransomware | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2021-42287 | High (7.5) | Actively exploited · ransomware | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2021-40449 | High (7.8) | Actively exploited · ransomware | Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-42278 | High (7.5) | Actively exploited · ransomware | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2024-30088 | High (7.0) | Actively exploited · ransomware | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2022-34713 | High (7.8) | Actively exploited | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | |
| CVE-2024-43572 | High (7.8) | Actively exploited | Microsoft Management Console Remote Code Execution Vulnerability | |
| CVE-2026-32202 | Medium (4.3) | Actively exploited | Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2025-24054 | Medium (6.5) | Actively exploited | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2022-21882 | High (7.0) | Actively exploited | Win32k Elevation of Privilege Vulnerability | |
| CVE-2022-21971 | High (7.8) | Actively exploited | Windows Runtime Remote Code Execution Vulnerability | |
| CVE-2024-43461 | High (8.8) | Actively exploited | Windows MSHTML Platform Spoofing Vulnerability | |
| CVE-2024-21338 | High (7.8) | Actively exploited · ransomware | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2023-28252 | High (7.8) | Actively exploited · ransomware | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2024-29988 | High (8.8) | Actively exploited | SmartScreen Prompt Security Feature Bypass Vulnerability | |
| CVE-2013-3900 | Medium (5.5) | Actively exploited | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the … | |
| CVE-2024-43573 | Medium (6.5) | Actively exploited | Windows MSHTML Platform Spoofing Vulnerability | |
| CVE-2023-36874 | High (7.8) | Actively exploited | Windows Error Reporting Service Elevation of Privilege Vulnerability | |
| CVE-2023-21674 | High (8.8) | Actively exploited | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | |
| CVE-2022-21999 | High (7.8) | Actively exploited · ransomware | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2024-38178 | High (7.5) | Actively exploited | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2025-26633 | High (7.0) | Actively exploited · ransomware | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | |
| CVE-2024-21351 | High (7.6) | Actively exploited | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2022-37969 | High (7.8) | Actively exploited | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2024-38193 | High (7.8) | Actively exploited | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | |
| CVE-2023-36802 | High (7.8) | Actively exploited | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | |
| CVE-2026-21510 | High (8.8) | Actively exploited | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2024-49138 | High (7.8) | Actively exploited | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2024-35250 | High (7.8) | Actively exploited | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | |
| CVE-2022-41128 | High (8.8) | Actively exploited | Windows Scripting Languages Remote Code Execution Vulnerability | |
| CVE-2023-29360 | High (8.4) | Actively exploited | Microsoft Streaming Service Elevation of Privilege Vulnerability | |
| CVE-2025-30397 | High (7.5) | Actively exploited | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | |
| CVE-2023-36563 | Medium (6.5) | Actively exploited | Microsoft WordPad Information Disclosure Vulnerability | |
| CVE-2021-41379 | Medium (5.5) | Actively exploited · ransomware | Windows Installer Elevation of Privilege Vulnerability | |
| CVE-2022-22047 | High (7.8) | Actively exploited | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
106 of these are being actively exploited right now.
Our Newcastle team can audit your Microsoft estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
