CVE Tools

Windows Server 2008

3,629 CVEs tracked. 157 of them are in CISA KEV.

This hub aggregates every CVE we track for Windows Server 2008, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Windows Server 2008 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Windows Server 2008 CVEs per month
MonthCVEs
2024-1037
2024-1121
2024-1223
2025-0179
2025-0221
2025-0322
2025-0442
2025-0528
2025-0616
2025-0753
2025-0840
2025-0930
2025-1036
2025-1114
2025-1211
2026-0126
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 3,629 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2717%
  • High2,28363%
  • Medium1,03228%
  • Low431%

Latest CVEs

The 15 most recently published vulnerabilities affecting Windows Server 2008.

  1. CVE-2026-20936Windows NDIS Information Disclosure Vulnerability4.3
  2. CVE-2026-20931Windows Telephony Service Elevation of Privilege Vulnerability8.0
  3. CVE-2026-20929Windows HTTP.sys Elevation of Privilege Vulnerability7.5
  4. CVE-2026-20872NTLM Hash Disclosure Spoofing Vulnerability6.5
  5. CVE-2026-20868Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability8.8
  6. CVE-2026-20849Windows Kerberos Elevation of Privilege Vulnerability7.5
  7. CVE-2026-20843Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability7.8
  8. CVE-2026-20940Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability7.8
  9. CVE-2026-20927Windows SMB Server Denial of Service Vulnerability5.3
  10. CVE-2026-20925NTLM Hash Disclosure Spoofing Vulnerability6.5
  11. CVE-2026-20922Windows NTFS Remote Code Execution Vulnerability7.8
  12. CVE-2026-20921Windows SMB Server Elevation of Privilege Vulnerability7.5
  13. CVE-2026-20875Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability7.5
  14. CVE-2026-20869Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability7.0
  15. CVE-2026-20860Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store