windows_server_2016 vulnerabilities
CVEs whose affected-version data names the windows_server_2016 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
1350 CVEsRSS
CVE-2026-50362High· 7.8Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-50480High· 7.8Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
CVE-2026-50476High· 7.8Windows Network Connections Service Elevation of Privilege Vulnerability
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
CVE-2026-50475Medium· 5.5Windows Kernel Information Disclosure Vulnerability
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50474High· 8.8Remote Desktop Client Remote Code Execution Vulnerability
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-50470High· 7.5Windows Network Policy Server SNMP Information Disclosure Vulnerability
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50461High· 7.8Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50453Medium· 6.1Windows USB Audio Class Driver Information Disclosure Vulnerability
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-50447Critical· 9.8Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-50444High· 8.8Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-50431Medium· 5.5Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
CVE-2026-50429High· 8.2Windows Kernel Information Disclosure Vulnerability
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
CVE-2026-50394Medium· 5.5Windows Media Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
CVE-2026-50505High· 7.5Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
CVE-2026-50502High· 8.0Windows Event Logging Service Remote Code Execution Vulnerability
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
CVE-2026-50500High· 7.5Windows Netlogon Elevation of Privilege Vulnerability
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
CVE-2026-50498High· 7.8Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-50494High· 7.8Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50492Medium· 6.8Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-50491High· 7.0Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-50490High· 7.0Windows Installer Elevation of Privilege Vulnerability
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-50489High· 8.8Win32k Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50485Medium· 4.5Windows Hyper-V Denial of Service Vulnerability
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2026-50482High· 7.3Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50477High· 8.8Windows Kernel Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50518Critical· 9.8Windows DHCP Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50509High· 7.8Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50504Medium· 6.5Windows Remote Desktop Client Information Disclosure Vulnerability
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-50497Medium· 6.5Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
CVE-2026-50496High· 7.5Windows Network Policy Server SNMP Information Disclosure Vulnerability
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.