Technology · Microsoft
Microsoft Windows Server 2008 R2 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in Microsoft Windows Server 2008 R2: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-20936, was published on 13 January 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About Microsoft Windows Server 2008 R2
A server operating system produced by Microsoft as part of the Windows NT family, based on the Windows 7 codebase.
Latest Microsoft Windows Server 2008 R2 vulnerabilities
- CVE-2026-20936: Microsoft Windows NDIS out-of-bounds readmediumCVSS 4.3EPSS 0.4%
- CVE-2026-20927: Microsoft Windows SMB Server race condition denial of servicemediumCVSS 5.3EPSS 0.9%
- CVE-2026-20925: Microsoft Windows NTLM spoofing via external path controlmediumCVSS 6.5EPSS 17.3%
- CVE-2026-20922: Microsoft Windows NTFS heap overflowhighCVSS 7.8EPSS 1.0%
- CVE-2026-20875: Microsoft Windows LSASS null pointer dereference denial of servicehighCVSS 7.5EPSS 1.5%
- CVE-2026-20872: Microsoft Windows NTLM spoofing via external file path controlmediumCVSS 6.5EPSS 19.1%
- CVE-2026-20869: Microsoft Windows race condition in Local Session ManagerhighCVSS 7EPSS 0.3%
- CVE-2026-20868: Microsoft Windows RRAS heap buffer overflowhighCVSS 8.8EPSS 1.3%
- CVE-2026-20860: Microsoft Windows Ancillary Function Driver type confusion privilege escalationhighCVSS 7.8EPSS 8.0%
- CVE-2026-20849: Microsoft Windows Kerberos privilege escalation via untrusted inputhighCVSS 7.5EPSS 1.0%
- CVE-2026-20847: Microsoft Windows Shell information disclosure and spoofingmediumCVSS 6.5EPSS 1.3%
- CVE-2026-20843: Microsoft Windows RRAS privilege escalation via improper access controlhighCVSS 7.8EPSS 3.3%
- CVE-2026-20840: Microsoft Windows NTFS heap overflow local code executionhighCVSS 7.8EPSS 4.4%
- CVE-2026-20839: Microsoft Windows Client-Side Caching Service improper access controlmediumCVSS 5.5EPSS 0.5%
- CVE-2026-20834: Microsoft Windows Shell absolute path traversalmediumCVSS 4.6EPSS 0.7%
- CVE-2026-20831: Microsoft Windows Ancillary Function Driver privilege escalationhighCVSS 7.8EPSS 0.3%
- CVE-2026-20828: Microsoft Windows Internet Connection Sharing out-of-bounds readmediumCVSS 4.6EPSS 0.6%
- CVE-2026-20821: Microsoft Windows RPC information disclosuremediumCVSS 6.2EPSS 0.7%
- CVE-2026-20820: Microsoft Windows CLFS Driver heap overflow privilege escalationhighCVSS 7.8EPSS 2.5%
- CVE-2026-20816: Microsoft Windows Installer privilege escalation via TOCTOU race conditionhighCVSS 7.8EPSS 2.4%
Most severe Microsoft Windows Server 2008 R2 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-20868: Microsoft Windows RRAS heap buffer overflowhighCVSS 8.8EPSS 1.3%
- CVE-2026-20860: Microsoft Windows Ancillary Function Driver type confusion privilege escalationhighCVSS 7.8EPSS 8.0%
- CVE-2026-20840: Microsoft Windows NTFS heap overflow local code executionhighCVSS 7.8EPSS 4.4%
- CVE-2026-20843: Microsoft Windows RRAS privilege escalation via improper access controlhighCVSS 7.8EPSS 3.3%
- CVE-2026-20820: Microsoft Windows CLFS Driver heap overflow privilege escalationhighCVSS 7.8EPSS 2.5%
- CVE-2026-20816: Microsoft Windows Installer privilege escalation via TOCTOU race conditionhighCVSS 7.8EPSS 2.4%
- CVE-2026-20922: Microsoft Windows NTFS heap overflowhighCVSS 7.8EPSS 1.0%
- CVE-2026-20831: Microsoft Windows Ancillary Function Driver privilege escalationhighCVSS 7.8EPSS 0.3%
- CVE-2026-20875: Microsoft Windows LSASS null pointer dereference denial of servicehighCVSS 7.5EPSS 1.5%
- CVE-2026-20849: Microsoft Windows Kerberos privilege escalation via untrusted inputhighCVSS 7.5EPSS 1.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/windows-server-2008-r2.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft Windows Server 2008 R2 vulnerabilities", https://junglewise.ai/threats/technologies/windows-server-2008-r2, 26 September 2026.