Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2641MEDIUM873LOW13
Vulnerabilities
Page 51 of 182
CVE-2026-50695P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50695 [HIGH] CWE-121 CVE-2026-50695: Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50411P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50411 [HIGH] CWE-121 CVE-2026-50411: Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized a
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-54983P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54983 [HIGH] CWE-121 CVE-2026-54983: Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized a
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50696P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50696 [HIGH] CWE-122 CVE-2026-50696: Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized at
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-29969P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.58542025-05-13
CVE-2025-29969 [HIGH] CWE-367 CVE-2025-29969: Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attac
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
nvd
CVE-2026-26128P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.70582026-03-10
CVE-2026-26128 [HIGH] CWE-287 CVE-2026-26128: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58530P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58530 [HIGH] CWE-122 CVE-2026-58530: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker t
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-69758P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69758 [HIGH] CWE-122 CVE-2026-69758: Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an auth
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69541P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69541 [HIGH] CWE-122 CVE-2026-69541: Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69467P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69467 [HIGH] CWE-121 CVE-2026-69467: Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69592P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69592 [HIGH] CWE-122 CVE-2026-69592: Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an auth
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-84000P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-84000 [HIGH] CWE-122 CVE-2026-84000: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
nvd
CVE-2026-62894P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62894 [HIGH] CWE-122 CVE-2026-62894: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62713P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62713 [HIGH] CWE-122 CVE-2026-62713: Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker t
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-62771P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.76632026-08-11
CVE-2026-62771 [HIGH] CWE-122 CVE-2026-62771: Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker t
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49793P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-49793 [HIGH] CWE-122 CVE-2026-49793: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
nvd
CVE-2026-58534P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58534 [HIGH] CWE-122 CVE-2026-58534: Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to e
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40397P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40397 [HIGH] CWE-191 CVE-2026-40397: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40407P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.72912026-05-12
CVE-2026-40407 [HIGH] CWE-122 CVE-2026-40407: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26176P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26176 [HIGH] CWE-122 CVE-2026-26176: Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized atta
Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.
nvd