| Windows Server | Number Of NVD | 5229 | CRITICAL | 126 | HIGH | 3568 | MEDIUM | 1464 | LOW | 71 |
| URL | https://www.microsoft.com/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | Server products offered by Microsoft. For business, developer, and desktop operating system products, 10 years of support at the supported Service Pack level (with a minimum of 5 years of mainstream support, followed by a minimum of 5 years of extended support). You may need to deploy the latest updates to be eligible for support. For some products, the support organization may be less than 10 years. For consumer and multimedia products, five years of mainstream support at the supported Service Pack level. The above text is excerpted from Microsoft's Fixed Lifecycle Policy. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://support.microsoft.com//lifecycle/search | ||
| 2 | https://www.microsoft.com/ja-jp/cloud-platform/windows-server | ||
| 3 | https://support.microsoft.com/ja-jp/hub/4095338/microsoft-lifecycle-policy | ||
| 4 | https://docs.microsoft.com/ja-jp/windows-server/get-started/windows-server-release-info |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 101 | Windows Server 2022 | 21H2 | Nov. 2, 2021 | Nov. 2, 2021 | Oct. 13, 2026 | Oct. 14, 2031 | 60 | 1398 | 449 | 6 | |
| 102 | Windows Server 2019 | 1809 | Oct. 2, 2018 | Nov. 13, 2018 | Jan. 9, 2024 | Jan. 9, 2029 | 98 | 2567 | 911 | 12 | |
| 103 | Windows Server 2016 | 20H2 | Oct. 20, 2020 | Oct. 15, 2016 | Jan. 11, 2022 | Jan. 12, 2027 | 107 | 2641 | 1033 | 16 | |
| 104 | Windows Server 2012 | Oct. 30, 2012 | Oct. 30, 2012 | Oct. 9, 2018 | Oct. 10, 2023 | 98 | 2256 | 929 | 51 | ||
| 105 | Windows Server 2008 R2( Service Pack 1適用) | Feb. 22, 2011 | Jan. 14, 2020 | 0 | 0 | 0 | 0 | ||||
| 106 | Windows Server 2008(Service Pack 2適用) | April 29, 2009 | Jan. 14, 2020 | 0 | 0 | 0 | 0 | ||||
| 107 | Microsoft Windows Server 2003(Service Pack 2適用) | May 28, 2003 | July 13, 2010 | July 14, 2015 | 0 | 128 | 53 | 15 | |||
| 108 | Microsoft Windows Storage Server 2003 | May 5, 2003 | Oct. 11, 2011 | Oct. 9, 2016 | 0 | 128 | 53 | 15 | |||
| 109 | Microsoft Windows 2000(Service Pack 4適用) | March 31, 2000 | June 30, 2005 | July 13, 2010 | 2 | 40 | 19 | 0 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 101 |
7.8 - |
HIGH
Local |
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
CWE-416
Use After Free |
CVE-2026-40382 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-16 00:32 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 102 |
6.2 - |
MEDIUM
Physics |
Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack. |
CWE-122 CWE-125 CWE-197 Heap-based Buffer Overflow Out-of-bounds Read Numeric Truncation Error |
CVE-2026-40380 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-15 02:49 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 103 |
7.8 - |
HIGH
Local |
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. |
CWE-122
Heap-based Buffer Overflow |
CVE-2026-40377 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-15 02:52 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 104 |
7.5 - |
HIGH
Network |
Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. |
CWE-401
Missing Release of Memory after Effective Lifetime |
CVE-2026-35424 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-15 03:02 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 105 |
5.4 - |
MEDIUM
Network |
Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. |
CWE-125
Out-of-bounds Read |
CVE-2026-35423 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-15 03:03 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 106 |
6.5 - |
MEDIUM
Network |
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. |
CWE-288
Authentication Bypass Using an Alternate Path or Channel |
CVE-2026-35422 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-15 03:04 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 107 |
7.8 - |
HIGH
Local |
Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. |
CWE-122
Heap-based Buffer Overflow |
CVE-2026-35421 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-15 03:05 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 108 |
7.8 - |
HIGH
Local |
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
CWE-122
Heap-based Buffer Overflow |
CVE-2026-35420 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8755 10.0.14393.9140 |
2026-05-15 03:06 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |
| 109 |
7.0 - |
HIGH
Local |
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
CWE-367 CWE-416 Time-of-check Time-of-use (TOCTOU) Race Condition Use After Free |
CVE-2026-35418 | cpe:2.3:o:microsoft:windows_server_2019:*:* | 10.0.17763.8755 |
2026-05-15 00:53 2026-05-13 |
Show | GitHub Exploit DB Packet Storm | |||
| 110 |
7.8 - |
HIGH
Local |
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
CWE-843
Type Confusion |
CVE-2026-35417 | cpe:2.3:o:microsoft:windows_server_2019:*:* | 10.0.17763.8755 |
2026-05-15 00:54 2026-05-13 |
Show | GitHub Exploit DB Packet Storm |