Microsoft Windows Server 2016
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Windows Server 2016.
By the Year
In 2026 there have been 1279 vulnerabilities in Microsoft Windows Server 2016 with an average score of 7.3 out of ten. Last year, in 2025 Windows Server 2016 had 601 security vulnerabilities published. That is, 678 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.10.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1279 | 7.31 |
| 2025 | 601 | 7.21 |
| 2024 | 494 | 7.49 |
| 2023 | 505 | 7.50 |
| 2022 | 515 | 7.43 |
| 2021 | 506 | 7.39 |
| 2020 | 801 | 7.34 |
| 2019 | 460 | 7.30 |
| 2018 | 249 | 7.29 |
It may take a day or so for new Windows Server 2016 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Windows Server 2016 Security Vulnerabilities
Sep 2026: Microsoft Graphics Component Remote Code Execution Vulnerability
CVE-2026-84000
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
Heap-based Buffer Overflow
Sep 2026: Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-83995
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-83992
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability
CVE-2026-83989
7.5 - High
- September 08, 2026
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
Out-of-bounds Read
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83985
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83987
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83983
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83982
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83980
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83978
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83981
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83977
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-70145
5.5 - Medium
- September 08, 2026
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83973
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83972
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83968
7.8 - High
- September 08, 2026
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83970
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83967
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83954
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83971
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows iSCSI Remote Code Execution Vulnerability
CVE-2026-69598
8.8 - High
- September 08, 2026
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
Incorrect Calculation of Buffer Size
Sep 2026: Windows WebClient Service Elevation of Privilege Vulnerability
CVE-2026-72965
7.8 - High
- September 08, 2026
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Storage Port Driver Information Disclosure Vulnerability
CVE-2026-69381
4.6 - Medium
- September 08, 2026
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds Read
Sep 2026: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-83940
7 - High
- September 08, 2026
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-81955
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-80096
8.8 - High
- September 08, 2026
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Out-of-bounds Read
Sep 2026: Windows Storage Information Disclosure Vulnerability
CVE-2026-78516
4.3 - Medium
- September 08, 2026
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
Buffer Over-read
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2026-69595
9.8 - Critical
- September 08, 2026
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-78454
5.5 - Medium
- September 08, 2026
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Sep 2026: Xbox Information Disclosure Vulnerability
CVE-2026-78455
4.3 - Medium
- September 08, 2026
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds Read
Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78453
6.5 - Medium
- September 08, 2026
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
Integer underflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78448
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78447
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78449
8.1 - High
- September 08, 2026
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
CVE-2026-78445
9.8 - Critical
- September 08, 2026
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows Distributed File System (DFS) Denial of Service Vulnerability
CVE-2026-78446
5.3 - Medium
- September 08, 2026
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
Dangling pointer
Sep 2026: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-77905
7 - High
- September 08, 2026
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73016
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows iSCSI Security Feature Bypass Vulnerability
CVE-2026-73025
9.8 - Critical
- September 08, 2026
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
1390
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73013
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73023
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-73009
9.8 - Critical
- September 08, 2026
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73006
8.8 - High
- September 08, 2026
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Stack Overflow
Sep 2026: Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-73012
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-73007
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-73026
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability
CVE-2026-73024
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Authentication Methods Elevation of Privilege Vulnerability
CVE-2026-73005
7 - High
- September 08, 2026
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Biometric Service Information Disclosure Vulnerability
CVE-2026-73008
5.5 - Medium
- September 08, 2026
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.
Privacy violation
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-73011
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Windows Server 2016 or by Microsoft? Click the Watch button to subscribe.
