Patch tracker / Products / Windows Server 2016

Windows Server 2016: vulnerabilities and security updates

Every CVE affecting Windows Server 2016 and the Microsoft update (KB) that fixes it, ranked by real-world risk. Actively exploited (CISA KEV) first, then EPSS exploit probability, on top of CVSS severity.

CVEs
44
Updates (KBs)
2
Actively exploited (KEV)
4
Critical Severity
6

CVEs affecting Windows Server 2016

CVESeverityCVSSEPSSStatus
CVE-2024-38178High9.871%KEV
CVE-2024-38193High9.871%KEV
CVE-2024-38106High9.871%KEV
CVE-2024-38107High9.871%KEV
CVE-2024-38199Critical9.871%-
CVE-2024-38063Critical9.871%-
CVE-2024-38140Critical9.871%-
CVE-2024-38143Critical9.871%-
CVE-2024-38159Critical9.171%-
CVE-2024-38160Critical9.171%-
CVE-2024-38114High8.871%-
CVE-2024-38115High8.871%-
CVE-2024-38116High8.871%-
CVE-2024-38121High8.871%-
CVE-2024-38128High8.871%-
CVE-2024-38130High8.871%-
CVE-2024-38131High8.871%-
CVE-2024-38144High8.871%-
CVE-2024-38154High8.871%-
CVE-2024-38180High8.871%-
CVE-2024-38120High8.871%-
CVE-2024-29995High8.171%-
CVE-2024-38196High7.871%-
CVE-2024-38117High7.871%-
CVE-2024-38125High7.871%-
CVE-2024-38127High7.871%-
CVE-2024-38134High7.871%-
CVE-2024-38141High7.871%-
CVE-2024-38152High7.871%-
CVE-2024-38142High7.871%-
CVE-2024-38153High7.871%-
CVE-2024-38198High7.571%-
CVE-2024-38126High7.571%-
CVE-2024-38132High7.571%-
CVE-2024-38145High7.571%-
CVE-2024-38146High7.571%-
CVE-2024-37968High7.571%-
CVE-2022-3775High7.171%-
CVE-2024-38223Medium6.871%-
CVE-2024-38214Medium6.571%-
CVE-2026-50480High7.864%-
CVE-2024-38118Medium5.571%-
CVE-2024-38122Medium5.571%-
CVE-2024-38151Medium5.571%-

Updates (KBs) for Windows Server 2016

UpdateReleasedSeverityCVSSEPSSCVEsStatus
KB50417732024-08-13Critical9.871%43KEV
KB50994152026-07-14High7.80.2%1-

Ranked across all products on the Microsoft patch tracker and the CVE and vulnerability management reference. Browse every product: product index.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.