Technology · Microsoft
Microsoft Windows NT vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 35 vulnerabilities in Microsoft Windows NT: 0 in the last 7 days and 0 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-42980, was published on 9 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 3
- Exploited in the wild
- 1
About Microsoft Windows NT
Windows NT is a family of operating systems produced by Microsoft for workstation and server environments.
Latest Microsoft Windows NT vulnerabilities
- CVE-2026-42980: Microsoft Windows NT OS Kernel privilege escalation via integer underflowhighCVSS 7.8
- CVE-2026-42916: Microsoft Windows NT OS Kernel privilege escalation via integer underflowhighCVSS 7.8
- CVE-2004-0210: Microsoft Windows Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-1999-1361: Microsoft Windows NT WINS denial of service via malformed packetsmediumCVSS 6.4
- CVE-1999-0225: Microsoft Windows NT denial of service in SMB logon requestmediumCVSS 5
- CVE-1999-0258: Microsoft Windows TCP/IP stack denial of service in IP fragmentationmediumCVSS 5
- CVE-1999-0256: War FTP buffer overflow allows remote command executionhighCVSS 7.5
- CVE-1999-1581: Microsoft Windows NT SNMP agent memory leak in snmp.exemediumCVSS 5
- CVE-1999-1217: Microsoft Windows NT privilege escalation via current directory in PATHmediumCVSS 4.6
- CVE-1999-1463: Microsoft Windows NT IP stack improper fragment reassemblymediumCVSS 5
- CVE-1999-0153: Microsoft Windows 95/NT denial of service in NetBIOS via OOB datamediumCVSS 5
- CVE-1999-0074: TCP/IP Stack sequential port allocation allows spoofingmediumCVSS 6.4
- CVE-1999-0275: Microsoft Windows NT DNS server denial of service via port 53 floodingmediumCVSS 5
- CVE-1999-0227: Microsoft Windows NT denial of service in LSASS.EXEmediumCVSS 5
- CVE-1999-1387: Microsoft Windows NT denial of service via malformed SMB packetsmediumCVSS 5
- CVE-1999-0612: Generic finger service information disclosureinfoCVSS 0
- CVE-1999-0228: Microsoft Windows NT denial of service in RPC LocatormediumCVSS 5
- CVE-1999-0504: Microsoft Windows NT default or blank password for local accountshighCVSS 7.5
- CVE-1999-0534: Microsoft Windows NT excessive user privileges assignmentmediumCVSS 4.6
- CVE-1999-0249: Microsoft Windows NT arbitrary command execution in RSHSVChighCVSS 7.2
- CVE-1999-0503: Microsoft Windows NT guessable password for local accountshighCVSS 7.2
- CVE-1999-0575: Microsoft Windows NT missing security audit logging policyhighCVSS 7.5
- CVE-1999-0265: Microsoft Windows NT Denial of Service via ICMP RedirectmediumCVSS 5
- CVE-1999-0345: Microsoft Windows 95 and NT denial of service via Jolt ICMP attackmediumCVSS 5
- CVE-1999-0496: Microsoft Windows NT privilege escalation in NtOpenProcessTokenhighCVSS 7.2
Most severe Microsoft Windows NT vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2004-0210: Microsoft Windows Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-1999-0535: Microsoft Windows NT insecure password policy configurationcriticalCVSS 10
- CVE-1999-0572: Microsoft Windows NT Registry Editor file association vulnerabilitycriticalCVSS 9.3
- CVE-2026-42980: Microsoft Windows NT OS Kernel privilege escalation via integer underflowhighCVSS 7.8
- CVE-2026-42916: Microsoft Windows NT OS Kernel privilege escalation via integer underflowhighCVSS 7.8
- CVE-1999-0256: War FTP buffer overflow allows remote command executionhighCVSS 7.5
- CVE-1999-0519: Microsoft NetBIOS and SMB null or default password on network shareshighCVSS 7.5
- CVE-1999-0575: Microsoft Windows NT missing security audit logging policyhighCVSS 7.5
- CVE-1999-0504: Microsoft Windows NT default or blank password for local accountshighCVSS 7.5
- CVE-1999-0511: Generic Operating System IP forwarding enabled on non-router hosthighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/windows-nt.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft Windows NT vulnerabilities", https://junglewise.ai/threats/technologies/windows-nt, 26 September 2026.