Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 111 of 182
CVE-2026-69280P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69280 [HIGH] CWE-416 CVE-2026-69280: Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges loc
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69654P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69654 [HIGH] CWE-416 CVE-2026-69654: Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges local
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69498P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69498 [HIGH] CWE-416 CVE-2026-69498: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-71353P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71353 [HIGH] CWE-415 CVE-2026-71353: Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to ele
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69652P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69652 [HIGH] CWE-416 CVE-2026-69652: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69648P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69648 [HIGH] CWE-416 CVE-2026-69648: Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-73022P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-73022 [HIGH] CWE-416 CVE-2026-73022: Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate pr
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69275P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69275 [HIGH] CWE-416 CVE-2026-69275: Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69567P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69567 [HIGH] CWE-416 CVE-2026-69567: Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69816P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69816 [HIGH] CWE-416 CVE-2026-69816: Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges local
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69834P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69834 [HIGH] CWE-416 CVE-2026-69834: Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62694P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-62694 [HIGH] CWE-416 CVE-2026-62694: Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-70577P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70577 [HIGH] CWE-416 CVE-2026-70577: Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate pr
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69605P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69605 [HIGH] CWE-416 CVE-2026-69605: Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges loca
Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-71351P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-71351 [HIGH] CWE-415 CVE-2026-71351: Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to ele
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-65678P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-65678 [HIGH] CWE-416 CVE-2026-65678: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61366P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61366 [HIGH] CWE-415 CVE-2026-61366: Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62773P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62773 [HIGH] CWE-416 CVE-2026-62773: Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62892P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62892 [HIGH] CWE-416 CVE-2026-62892: Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to ele
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-61939P3HIGHCVSS 7.0≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-61939 [HIGH] CWE-416 CVE-2026-61939: Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
nvd