Microsoft
Windows Server
Microsoft server operating system for on-premises and hybrid workloads.
2026-08 B (20348.5499)
- Release date
- August 11, 2026
- Security status
- 100 high-severity CVEs tracked in the last 90 days. Current version not affected.
Source
Vendor Release Information
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 2026-08 B (20348.5499) | 2026-08-11 | Release Notes |
| 2026-07 B (20348.5386) | 2026-07-14 | Release Notes |
| 2026-06 B (20348.5256) | 2026-06-09 | Release Notes |
| 2026-05 B (20348.5139) | 2026-05-12 | Release Notes |
| 2026-04 OOB (20348.5024) | 2026-04-19 | Release Notes |
| 2026-04 B (20348.5020) | 2026-04-14 | Release Notes |
| 2026-03 B (20348.4893) | 2026-03-10 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-62727 | HIGH (7.0) | 2026-08-19 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-71331 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-66802 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-65796 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-65791 | CRITICAL (9.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-65790 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65775 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65774 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65773 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65679 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-65681 | HIGH (7.5) | 2026-08-11 | Current versionnot affected | Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. Affected versions
|
| CVE-2026-62888 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62885 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62880 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62832 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62822 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62823 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. Affected versions
|
| CVE-2026-62811 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62807 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62803 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62790 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62800 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62781 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62778 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. Affected versions
|
| CVE-2026-62776 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62770 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62768 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62761 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62771 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62752 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62751 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62741 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62734 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62732 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62733 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62728 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62726 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62725 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62721 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62717 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62711 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62710 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62701 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62700 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62698 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61926 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61358 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61365 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61364 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61355 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61359 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61363 | HIGH (7.5) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-61349 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-59126 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-59125 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-59122 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-42976 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-70347 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-70346 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-70345 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-70344 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-61352 | HIGH (7.5) | 2026-08-11 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-70307 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-68820 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-66799 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65814 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65787 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65789 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-65786 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65678 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65672 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-65671 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62908 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62894 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62893 | CRITICAL (9.8) | 2026-08-11 | Current versionnot affected | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62892 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62890 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. Affected versions
|
| CVE-2026-62889 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62878 | CRITICAL (9.8) | 2026-08-11 | Current versionnot affected | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62877 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62876 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62820 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62819 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine Affected versions
|
| CVE-2026-62818 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62817 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. Affected versions
|
| CVE-2026-62816 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. Affected versions
|
| CVE-2026-62815 | CRITICAL (9.8) | 2026-08-11 | Current versionnot affected | Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62812 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62797 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62795 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62787 | HIGH (7.5) | 2026-08-11 | Current versionnot affected | Use after free in Windows DNS allows an authorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62784 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62792 | HIGH (8.1) | 2026-08-11 | Current versionnot affected | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62777 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62785 | HIGH (8.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-62774 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62773 | HIGH (7.0) | 2026-08-11 | Current versionnot affected | Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62758 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62755 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-62783 | HIGH (7.8) | 2026-08-11 | Current versionnot affected | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Affected versions
|
354 further matching CVEs are not displayed. The table shows the 100 most relevant of 454, recently published first.