Back to search

Microsoft

Windows Server

Microsoft server operating system for on-premises and hybrid workloads.

Current version
Last checked: 2026-06-03

2026-05 B (26100.32860)

Release date
May 12, 2026
Security status
25 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
2026-05 B (26100.32860) 2026-05-12 Release Notes
2026-04 OOB (26100.32698) 2026-04-19 Release Notes
2026-04 B (26100.32690) 2026-04-14 Release Notes
2026-03 B (26100.32522) 2026-03-10 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-42896 HIGH (7.8) 2026-05-12 Current versionnot affected

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32860
CVE-2026-42825 HIGH (7.0) 2026-05-12 Current versionnot affected

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32860
CVE-2026-41096 CRITICAL (9.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-41095 HIGH (7.8) 2026-05-12 Current versionnot affected

Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-41089 CRITICAL (9.8) 2026-05-12 Current versionnot affected

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-41088 HIGH (7.8) 2026-05-12 Current versionnot affected

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40415 HIGH (8.1) 2026-05-12 Current versionnot affected

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40414 HIGH (7.4) 2026-05-12 Current versionnot affected

Windows TCP/IP Denial of Service Vulnerability

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40413 HIGH (7.4) 2026-05-12 Current versionnot affected

Windows TCP/IP Denial of Service Vulnerability

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40410 HIGH (7.0) 2026-05-12 Current versionnot affected

Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40408 HIGH (7.8) 2026-05-12 Current versionnot affected

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40407 HIGH (7.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40406 HIGH (7.5) 2026-05-12 Current versionnot affected

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40405 HIGH (7.5) 2026-05-12 Current versionnot affected

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40403 HIGH (8.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40401 HIGH (7.1) 2026-05-12 Current versionnot affected

Windows TCP/IP Denial of Service Vulnerability

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40399 HIGH (7.8) 2026-05-12 Current versionnot affected

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40398 HIGH (7.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40397 HIGH (7.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40382 HIGH (7.8) 2026-05-12 Current versionnot affected

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40377 HIGH (7.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-40369 HIGH (7.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-35424 HIGH (7.5) 2026-05-12 Current versionnot affected

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-35421 HIGH (7.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772
CVE-2026-35420 HIGH (7.8) 2026-05-12 Current versionnot affected

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected versions
  • Up to (excluding) 10.0.26100.32772