Microsoft Windows 10 1607 vulnerabilities
1,426 known vulnerabilities affecting microsoft/windows_10_1607.
Total CVEs
1,426
CISA KEV
86
actively exploited
Public exploits
36
Exploited in wild
59
Severity breakdown
CRITICAL39HIGH1015MEDIUM366LOW6
Vulnerabilities
Page 8 of 72
CVE-2026-24282MEDIUMCVSS 5.5fixed in 10.0.14393.89572026-03-10
CVE-2026-24282 [MEDIUM] CWE-125 CVE-2026-24282: Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose informa
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-25185MEDIUMCVSS 5.3fixed in 10.0.14393.89572026-03-10
CVE-2026-25185 [MEDIUM] CWE-200 CVE-2026-25185: Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows a
Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-25169MEDIUMCVSS 5.5fixed in 10.0.14393.89572026-03-10
CVE-2026-25169 [MEDIUM] CWE-369 CVE-2026-25169: Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service local
Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-25168MEDIUMCVSS 5.5fixed in 10.0.14393.89572026-03-10
CVE-2026-25168 [MEDIUM] CWE-476 CVE-2026-25168: Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser
Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-25186MEDIUMCVSS 5.5fixed in 10.0.14393.89572026-03-10
CVE-2026-25186 [MEDIUM] CWE-200 CVE-2026-25186: Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-24297MEDIUMCVSS 4.8fixed in 10.0.14393.89572026-03-10
CVE-2026-24297 [MEDIUM] CWE-362 CVE-2026-24297: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-25180MEDIUMCVSS 5.5fixed in 10.0.14393.89572026-03-10
CVE-2026-25180 [MEDIUM] CWE-125 CVE-2026-25180: Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose infor
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-21510HIGHCVSS 8.8KEVfixed in 10.0.14393.88682026-02-10
CVE-2026-21510 [HIGH] CWE-693 CVE-2026-21510: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-21244HIGHCVSS 7.3PoCfixed in 10.0.14393.88682026-02-10
CVE-2026-21244 [HIGH] CWE-122 CVE-2026-21244: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2026-21239HIGHCVSS 7.8fixed in 10.0.14393.88682026-02-10
CVE-2026-21239 [HIGH] CWE-122 CVE-2026-21239: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21513HIGHCVSS 8.8KEVfixed in 10.0.14393.88682026-02-10
CVE-2026-21513 [HIGH] CWE-693 CVE-2026-21513: Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a securit
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-20846HIGHCVSS 7.5fixed in 10.0.14393.88682026-02-10
CVE-2026-20846 [HIGH] CWE-126 CVE-2026-20846: Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-21248HIGHCVSS 7.3PoCfixed in 10.0.14393.88682026-02-10
CVE-2026-21248 [HIGH] CWE-122 CVE-2026-21248: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2026-21255HIGHCVSS 8.8fixed in 10.0.14393.88682026-02-10
CVE-2026-21255 [HIGH] CWE-284 CVE-2026-21255: Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security featur
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-21236HIGHCVSS 7.8fixed in 10.0.14393.88682026-02-10
CVE-2026-21236 [HIGH] CWE-122 CVE-2026-21236: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21231HIGHCVSS 7.8fixed in 10.0.14393.88682026-02-10
CVE-2026-21231 [HIGH] CWE-362 CVE-2026-21231: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21238HIGHCVSS 7.8fixed in 10.0.14393.88682026-02-10
CVE-2026-21238 [HIGH] CWE-284 CVE-2026-21238: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21253HIGHCVSS 7.0fixed in 10.0.14393.88682026-02-10
CVE-2026-21253 [HIGH] CWE-416 CVE-2026-21253: Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21247HIGHCVSS 7.3fixed in 10.0.14393.88682026-02-10
CVE-2026-21247 [HIGH] CWE-20 CVE-2026-21247: Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2026-21508HIGHCVSS 7.0fixed in 10.0.14393.88682026-02-10
CVE-2026-21508 [HIGH] CWE-287 CVE-2026-21508: Improper authentication in Windows Storage allows an authorized attacker to elevate privileges local
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
nvd