Windows server 2025
This hub aggregates every CVE we track for Windows server 2025, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
1,938
CVEs tracked
38
Critical
1,368
High
40
In CISA KEV
Severity distribution
HIGH1,368MEDIUM523CRITICAL38LOW9
Monthly trend
1
32
58
127
37
38
83
40
43
97
68
59
127
34
36
84
29
39
122
66
110
388
214
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Windows server 2025.
- CVE-2026-25250EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."6.0
- CVE-2026-62727Windows Telephony Service Elevation of Privilege Vulnerability7.0
- CVE-2026-62738Windows Management Instrumentation Information Disclosure Vulnerability5.5
- CVE-2026-71331Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability8.1
- CVE-2026-56179Windows Network Address Translation (NAT) Spoofing Vulnerability8.3
- CVE-2026-66802Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability8.1
- CVE-2026-65798Windows DNS Elevation of Privilege Vulnerability6.7
- CVE-2026-65796Windows iSCSI Target Service Remote Code Execution Vulnerability8.1
- CVE-2026-65799Windows DNS Elevation of Privilege Vulnerability6.7
- CVE-2026-65797Windows DNS Elevation of Privilege Vulnerability6.7
- CVE-2026-65795Windows DNS Elevation of Privilege Vulnerability6.7
- CVE-2026-65794Windows SMB Client Information Disclosure Vulnerability6.5
- CVE-2026-65791Windows iSCSI Target Service Remote Code Execution Vulnerability9.8
- CVE-2026-65790Windows Message Queuing Elevation of Privilege Vulnerability7.8
- CVE-2026-65777Active Directory Security Feature Bypass Vulnerability5.3
Product normalization is registry-driven with AI assist and human review. How it works