Known Vulnerabilities for Windows Server by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Windows Server" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34515 json | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the stati... | Not Provided | 2026-04-01 | 2026-04-02 |
| CVE-2026-34045 json | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP serv... | Not Provided | 2026-04-07 | 2026-04-08 |
| CVE-2026-33682 json | Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 run... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-33623 json | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a ... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-32631 json | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers... | Not Provided | 2026-04-15 | 2026-04-15 |
| CVE-2026-32224 json | Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-04-14 | 2026-04-17 |
| CVE-2026-26174 json | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service ... | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-26154 json | Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a networ... | Not Provided | 2026-04-14 | 2026-04-16 |
| CVE-2026-5131 json | GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access control l... | Not Provided | 2026-04-17 | 2026-04-17 |
| CVE-2026-1352 json | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allo... | Not Provided | 2026-04-23 | 2026-04-22 |