Windows Server 2008 R2
2,817 CVEs tracked. 143 of them are in CISA KEV.
This hub aggregates every CVE we track for Windows Server 2008 R2, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Windows Server 2008 R2 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 37 |
| 2024-11 | 20 |
| 2024-12 | 23 |
| 2025-01 | 79 |
| 2025-02 | 21 |
| 2025-03 | 23 |
| 2025-04 | 42 |
| 2025-05 | 28 |
| 2025-06 | 16 |
| 2025-07 | 53 |
| 2025-08 | 40 |
| 2025-09 | 30 |
| 2025-10 | 36 |
| 2025-11 | 14 |
| 2025-12 | 11 |
| 2026-01 | 27 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 2,817 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical112
- High1,938
- Medium746
- Low21
Latest CVEs
The 15 most recently published vulnerabilities affecting Windows Server 2008 R2.
- CVE-2026-20936Windows NDIS Information Disclosure Vulnerability4.3
- CVE-2026-20931Windows Telephony Service Elevation of Privilege Vulnerability8.0
- CVE-2026-20929Windows HTTP.sys Elevation of Privilege Vulnerability7.5
- CVE-2026-20872NTLM Hash Disclosure Spoofing Vulnerability6.5
- CVE-2026-20868Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability8.8
- CVE-2026-20849Windows Kerberos Elevation of Privilege Vulnerability7.5
- CVE-2026-20843Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability7.8
- CVE-2026-20940Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability7.8
- CVE-2026-20927Windows SMB Server Denial of Service Vulnerability5.3
- CVE-2026-20925NTLM Hash Disclosure Spoofing Vulnerability6.5
- CVE-2026-20922Windows NTFS Remote Code Execution Vulnerability7.8
- CVE-2026-20921Windows SMB Server Elevation of Privilege Vulnerability7.5
- CVE-2026-20875Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability7.5
- CVE-2026-20869Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability7.0
- CVE-2026-20860Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability7.8
Product grouping is registry-driven, with AI assist and human review. How it works