Technology · Microsoft
Microsoft Windows Server 2012 R2 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 29 vulnerabilities in Microsoft Windows Server 2012 R2: 0 in the last 7 days and 26 in the last 90 days, 3 of them critical and 1 exploited in the wild. The most recent, CVE-2026-58627, was published on 14 July 2026.
- Last 7 days
- 0
- Last 90 days
- 26
- Critical, all time
- 3
- Exploited in the wild
- 1
About Microsoft Windows Server 2012 R2
A server operating system based on the Windows 8.1 codebase.
Latest Microsoft Windows Server 2012 R2 vulnerabilities
- CVE-2026-58627: Microsoft Windows DHCP Server denial of servicehighCVSS 7.5
- CVE-2026-57096: Microsoft Windows RRAS heap overflow privilege escalationhighCVSS 7.8
- CVE-2026-56647: Microsoft Windows Remote Access Service privilege escalationhighCVSS 8.8
- CVE-2026-56159: Microsoft Windows DHCP Server heap overflow remote code executioncriticalCVSS 9.8
- CVE-2026-54121: Microsoft Active Directory Certificate Services privilege escalationhighCVSS 8.8
- CVE-2026-50686: Microsoft Windows OLE type confusion remote code executionhighCVSS 8.1
- CVE-2026-50685: Microsoft Windows DHCP Server double free remote code executionhighCVSS 7.5
- CVE-2026-50684: Microsoft AD FS cross-site scripting in web page generationmediumCVSS 4.8
- CVE-2026-50683: Microsoft Windows DHCP Server heap overflow privilege escalationhighCVSS 8
- CVE-2026-50666: Microsoft Windows Remote Access Connection Manager use after free privilege escalationhighCVSS 8.8
- CVE-2026-50518: Microsoft Windows DHCP Server heap overflow remote code executioncriticalCVSS 9.8
- CVE-2026-50480: Microsoft Windows heap overflow in WPADhighCVSS 7.8
- CVE-2026-50435: Microsoft Windows Overlay Filter privilege escalationhighCVSS 7.8
- CVE-2026-50426: Microsoft Windows DNS Server relative path traversal code executionmediumCVSS 6.8
- CVE-2026-50394: Microsoft Windows Media information disclosuremediumCVSS 5.5
- CVE-2026-50370: Microsoft Windows DHCP Server heap buffer overflowhighCVSS 8.8
- CVE-2026-50368: Microsoft Active Directory Federation Services stack overflow denial of servicehighCVSS 7.5
- CVE-2026-50363: Microsoft Windows Push Notifications heap overflow privilege escalationhighCVSS 7.8
- CVE-2026-50355: Microsoft Active Directory Federation Services stack buffer overflowhighCVSS 7.5
- CVE-2026-50324: Microsoft AD FS infinite loop denial of servicemediumCVSS 5.9
- CVE-2026-57979: Microsoft Windows RDP out-of-bounds read information disclosuremediumCVSS 6.5
- CVE-2026-56155: Microsoft AD FS privilege escalation via insufficient access control granularitycriticalexploited in the wildCVSS 7.8
- CVE-2026-54987: Microsoft Windows heap overflow in Windows Overlay FilterhighCVSS 7.8
- CVE-2026-50299: Microsoft Windows Storage Spaces Direct integer overflowmediumCVSS 6.8
- CVE-2026-49181: Microsoft Windows DHCP Client integer underflow privilege escalationhighCVSS 7.5
Most severe Microsoft Windows Server 2012 R2 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-56155: Microsoft AD FS privilege escalation via insufficient access control granularitycriticalexploited in the wildCVSS 7.8
- CVE-2026-56159: Microsoft Windows DHCP Server heap overflow remote code executioncriticalCVSS 9.8
- CVE-2026-50518: Microsoft Windows DHCP Server heap overflow remote code executioncriticalCVSS 9.8
- CVE-2026-56647: Microsoft Windows Remote Access Service privilege escalationhighCVSS 8.8
- CVE-2026-54121: Microsoft Active Directory Certificate Services privilege escalationhighCVSS 8.8
- CVE-2026-50666: Microsoft Windows Remote Access Connection Manager use after free privilege escalationhighCVSS 8.8
- CVE-2026-50370: Microsoft Windows DHCP Server heap buffer overflowhighCVSS 8.8
- CVE-2026-48564: Microsoft Windows DHCP Server heap buffer overflowhighCVSS 8.8
- CVE-2026-50686: Microsoft Windows OLE type confusion remote code executionhighCVSS 8.1
- CVE-2026-33826: Microsoft Windows Active Directory improper input validation remote code executionhighCVSS 8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 26 | 3 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/windows-server-2012-r2.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft Windows Server 2012 R2 vulnerabilities", https://junglewise.ai/threats/technologies/windows-server-2012-r2, 26 September 2026.