Windows Server 2025 vulnerabilities: known CVEs & security history
Microsoft · Operating System · 941 tracked CVEs · 8 actively exploited · updated September 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all Windows Server 2025 release lines — 941 in total, with 8 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Windows Server 2025's current status and the safe version to run.
Known Windows Server 2025 CVEs
Actively-exploited and most-severe first. Showing the top 80 of 941. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2026-33824⚡ exploited | critical | 9.8 | 56% | 2026 |
| CVE-2024-49039⚡ exploited | high | 8.8 | 14% | 2024 |
| CVE-2026-81963⚡ exploited | high | 7.8 | — | 2026 |
| CVE-2026-56155⚡ exploited | high | 7.8 | 0% | 2026 |
| CVE-2026-68820⚡ exploited | high | 7 | 0% | 2026 |
| CVE-2025-26633⚡ exploited | high | 7 | 32% | 2025 |
| CVE-2026-20805⚡ exploited | medium | 5.5 | 5% | 2026 |
| CVE-2026-32202⚡ exploited | medium | 4.3 | 64% | 2026 |
| CVE-2026-57092 | critical | 9.9 | 1% | 2026 |
| CVE-2026-78445 | critical | 9.8 | 1% | 2026 |
| CVE-2026-77493 | critical | 9.8 | 1% | 2026 |
| CVE-2026-69845 | critical | 9.8 | 1% | 2026 |
| CVE-2026-65791 | critical | 9.8 | 1% | 2026 |
| CVE-2026-62893 | critical | 9.8 | 3% | 2026 |
| CVE-2026-62878 | critical | 9.8 | 1% | 2026 |
| CVE-2026-62815 | critical | 9.8 | 1% | 2026 |
| CVE-2026-56190 | critical | 9.8 | 1% | 2026 |
| CVE-2026-56188 | critical | 9.8 | 1% | 2026 |
| CVE-2026-56159 | critical | 9.8 | 1% | 2026 |
| CVE-2026-50518 | critical | 9.8 | 7% | 2026 |
| CVE-2026-50447 | critical | 9.8 | 1% | 2026 |
| CVE-2026-54990 | critical | 9.8 | 1% | 2026 |
| CVE-2026-49172 | critical | 9.8 | 1% | 2026 |
| CVE-2026-42990 | critical | 9.8 | 1% | 2026 |
| CVE-2026-47291 | critical | 9.8 | 22% | 2026 |
| CVE-2026-45657 | critical | 9.8 | 15% | 2026 |
| CVE-2026-44815 | critical | 9.8 | 1% | 2026 |
| CVE-2026-50380 | critical | 9.6 | 1% | 2026 |
| CVE-2026-42904 | critical | 9.6 | 0% | 2026 |
| CVE-2026-49798 | critical | 9.3 | 2% | 2026 |
| CVE-2026-45602 | critical | 9.1 | 0% | 2026 |
| CVE-2026-83996 | high | 8.8 | 0% | 2026 |
| CVE-2026-83992 | high | 8.8 | 1% | 2026 |
| CVE-2026-80096 | high | 8.8 | 1% | 2026 |
| CVE-2026-80083 | high | 8.8 | 0% | 2026 |
| CVE-2026-73016 | high | 8.8 | 1% | 2026 |
| CVE-2026-73006 | high | 8.8 | 1% | 2026 |
| CVE-2026-69266 | high | 8.8 | 0% | 2026 |
| CVE-2026-62872 | high | 8.8 | 1% | 2026 |
| CVE-2026-62823 | high | 8.8 | 1% | 2026 |
| CVE-2026-62822 | high | 8.8 | 1% | 2026 |
| CVE-2026-62818 | high | 8.8 | 1% | 2026 |
| CVE-2026-62817 | high | 8.8 | 1% | 2026 |
| CVE-2026-62816 | high | 8.8 | 0% | 2026 |
| CVE-2026-62800 | high | 8.8 | 1% | 2026 |
| CVE-2026-62795 | high | 8.8 | 1% | 2026 |
| CVE-2026-62790 | high | 8.8 | 1% | 2026 |
| CVE-2026-62785 | high | 8.8 | 1% | 2026 |
| CVE-2026-62784 | high | 8.8 | 1% | 2026 |
| CVE-2026-49179 | high | 8.8 | 1% | 2026 |
| CVE-2026-58626 | high | 8.8 | 1% | 2026 |
| CVE-2026-58594 | high | 8.8 | 1% | 2026 |
| CVE-2026-58534 | high | 8.8 | 0% | 2026 |
| CVE-2026-57094 | high | 8.8 | 1% | 2026 |
| CVE-2026-57090 | high | 8.8 | 1% | 2026 |
| CVE-2026-57087 | high | 8.8 | 1% | 2026 |
| CVE-2026-56647 | high | 8.8 | 1% | 2026 |
| CVE-2026-56194 | high | 8.8 | 1% | 2026 |
| CVE-2026-54121 | high | 8.8 | 1% | 2026 |
| CVE-2026-50692 | high | 8.8 | 0% | 2026 |
| CVE-2026-50687 | high | 8.8 | 0% | 2026 |
| CVE-2026-50670 | high | 8.8 | 0% | 2026 |
| CVE-2026-50666 | high | 8.8 | 1% | 2026 |
| CVE-2026-50489 | high | 8.8 | 0% | 2026 |
| CVE-2026-50477 | high | 8.8 | 0% | 2026 |
| CVE-2026-50474 | high | 8.8 | 1% | 2026 |
| CVE-2026-50444 | high | 8.8 | 1% | 2026 |
| CVE-2026-50413 | high | 8.8 | 0% | 2026 |
| CVE-2026-50398 | high | 8.8 | 0% | 2026 |
| CVE-2026-50385 | high | 8.8 | 0% | 2026 |
| CVE-2026-50382 | high | 8.8 | 0% | 2026 |
| CVE-2026-50370 | high | 8.8 | 1% | 2026 |
| CVE-2026-50369 | high | 8.8 | 1% | 2026 |
| CVE-2026-50360 | high | 8.8 | 1% | 2026 |
| CVE-2026-58608 | high | 8.8 | 0% | 2026 |
| CVE-2026-54999 | high | 8.8 | 0% | 2026 |
| CVE-2026-54982 | high | 8.8 | 0% | 2026 |
| CVE-2026-54107 | high | 8.8 | 0% | 2026 |
| CVE-2026-49795 | high | 8.8 | 2% | 2026 |
| CVE-2026-49178 | high | 8.8 | 1% | 2026 |
861 older / lower-severity CVEs not shown — see Windows Server 2025's full record.
Is my Windows Server 2025 version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your Windows Server 2025 version → · Monitor Windows Server 2025 for new CVEs →
Windows Server 2025 vulnerabilities — frequently asked
How many known vulnerabilities does Windows Server 2025 have?
IsItPatched tracks 941 CVEs for Windows Server 2025, 8 of which are actively exploited (CISA KEV). 24 are critical-severity and 682 high-severity. These span every release line — what matters is whether the version you run is affected.
Does Windows Server 2025 have any actively-exploited vulnerabilities?
Yes — 8 Windows Server 2025 CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (2 linked to ransomware). Patch these as a priority.
What is the most severe Windows Server 2025 vulnerability?
Among tracked issues, CVE-2026-33824 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Double free weakness.
Is Windows Server 2025 safe to use?
It depends on the version. The latest supported Windows Server 2025 release (10.0.26100) clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Windows Server 2025 security status · Windows Server 2025 end-of-life · actively-exploited CVEs. Always verify against Microsoft's advisories — see our disclaimer.