Microsoft Windows Server 2012 R2
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Windows Server 2012 R2.
By the Year
In 2026 there have been 994 vulnerabilities in Microsoft Windows Server 2012 R2 with an average score of 7.3 out of ten. Last year, in 2025 Windows Server 2012 R2 had 474 security vulnerabilities published. That is, 520 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.02.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 994 | 7.32 |
| 2025 | 474 | 7.31 |
| 2024 | 223 | 7.62 |
| 2023 | 96 | 7.60 |
| 2022 | 46 | 7.60 |
| 2021 | 192 | 7.48 |
| 2020 | 110 | 7.12 |
| 2019 | 45 | 7.07 |
| 2018 | 95 | 7.85 |
It may take a day or so for new Windows Server 2012 R2 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Windows Server 2012 R2 Security Vulnerabilities
Sep 2026: Microsoft Graphics Component Remote Code Execution Vulnerability
CVE-2026-84000
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
Heap-based Buffer Overflow
Sep 2026: Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-83995
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-83992
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability
CVE-2026-83989
7.5 - High
- September 08, 2026
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
Out-of-bounds Read
Sep 2026: Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-70145
5.5 - Medium
- September 08, 2026
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Sep 2026: Windows iSCSI Remote Code Execution Vulnerability
CVE-2026-69598
8.8 - High
- September 08, 2026
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
Incorrect Calculation of Buffer Size
Sep 2026: Windows WebClient Service Elevation of Privilege Vulnerability
CVE-2026-72965
7.8 - High
- September 08, 2026
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Storage Port Driver Information Disclosure Vulnerability
CVE-2026-69381
4.6 - Medium
- September 08, 2026
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds Read
Sep 2026: Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-81955
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-80096
8.8 - High
- September 08, 2026
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Out-of-bounds Read
Sep 2026: Windows Storage Information Disclosure Vulnerability
CVE-2026-78516
4.3 - Medium
- September 08, 2026
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
Buffer Over-read
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2026-69595
9.8 - Critical
- September 08, 2026
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78453
6.5 - Medium
- September 08, 2026
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
Integer underflow
Sep 2026: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78449
8.1 - High
- September 08, 2026
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows Distributed File System (DFS) Denial of Service Vulnerability
CVE-2026-78446
5.3 - Medium
- September 08, 2026
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
Dangling pointer
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2026-78445
9.8 - Critical
- September 08, 2026
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-77905
7 - High
- September 08, 2026
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73016
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows iSCSI Security Feature Bypass Vulnerability
CVE-2026-73025
9.8 - Critical
- September 08, 2026
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
1390
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73013
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73023
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-73009
9.8 - Critical
- September 08, 2026
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-73012
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability
CVE-2026-73024
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Graphic Fonts Remote Code Execution Vulnerability
CVE-2026-73018
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows URL Moniker Security Feature Bypass Vulnerability
CVE-2026-73019
4.3 - Medium
- September 08, 2026
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
Improper Resolution of Path Equivalence
Sep 2026: Windows DNS Remote Code Execution Vulnerability
CVE-2026-72987
8.1 - High
- September 08, 2026
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Volume Shadow Copy Elevation of Privilege Vulnerability
CVE-2026-72985
6.8 - Medium
- September 08, 2026
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
Heap-based Buffer Overflow
Sep 2026: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-70570
7.5 - High
- September 08, 2026
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Dangling pointer
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-70296
9.8 - Critical
- September 08, 2026
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Memory Corruption
Sep 2026: Windows Media Player Remote Code Execution Vulnerability
CVE-2026-70203
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Installer Elevation of Privilege Vulnerability
CVE-2026-69441
7 - High
- September 08, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
Race Condition
Sep 2026: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-69601
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-69590
9.8 - Critical
- September 08, 2026
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Heap-based Buffer Overflow
Sep 2026: Windows Deployment Services Remote Code Execution Vulnerability
CVE-2026-69607
7.5 - High
- September 08, 2026
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Storage Spaces Controller Information Disclosure Vulnerability
CVE-2026-69568
5.5 - Medium
- September 08, 2026
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Sep 2026: Windows Online Certificate Status Protocol (OCSP) Elevation of Privilege Vulnerability
CVE-2026-69564
7 - High
- September 08, 2026
Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Work Folder Service Elevation of Privilege Vulnerability
CVE-2026-69560
7 - High
- September 08, 2026
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows DHCP Server Remote Code Execution Vulnerability
CVE-2026-69510
8.1 - High
- September 08, 2026
Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Stack Overflow
Sep 2026: Windows USB Mass Storage Class Driver Elevation of Privilege Vulnerability
CVE-2026-69490
6.8 - Medium
- September 08, 2026
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.
Out-of-bounds Read
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-69499
8.8 - High
- September 08, 2026
Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Integer Overflow or Wraparound
Sep 2026: Windows VOLSNAP.SYS Remote Code Execution Vulnerability
CVE-2026-69426
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.
Heap-based Buffer Overflow
Sep 2026: Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability
CVE-2026-69395
6.5 - Medium
- September 08, 2026
Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.
Use of Externally-Controlled Format String
Sep 2026: Windows Audio Service Elevation of Privilege Vulnerability
CVE-2026-69311
7 - High
- September 08, 2026
Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
CVE-2026-69334
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
CVE-2026-69291
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2026-69290
7.8 - High
- September 08, 2026
Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
Stack Overflow
Sep 2026: Windows Print Spooler Components Elevation of Privilege Vulnerability
CVE-2026-69309
7 - High
- September 08, 2026
Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
Double-free
Sep 2026: Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-69287
7 - High
- September 08, 2026
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Network Connection Broker Elevation of Privilege Vulnerability
CVE-2026-72967
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Windows Server 2012 R2 or by Microsoft? Click the Watch button to subscribe.