Microsoft Windows 10 Version 21H2 vulnerabilities
3,631 known vulnerabilities affecting microsoft/windows_10_version_21h2.
Total CVEs
3,631
CISA KEV
98
actively exploited
Public exploits
68
Exploited in wild
126
Severity breakdown
CRITICAL104HIGH2642MEDIUM872LOW13
Vulnerabilities
Page 71 of 182
CVE-2026-70579P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-70579 [HIGH] CWE-125 CVE-2026-70579: Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose informati
Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50463P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50463 [HIGH] CWE-125 CVE-2026-50463: Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a
Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-45639P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-45639 [HIGH] CWE-125 CVE-2026-45639: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-42908P3HIGHCVSS 7.5≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42908 [HIGH] CWE-125 CVE-2026-42908: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50457P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50457 [HIGH] CWE-362 CVE-2026-50457: Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54125P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-54125 [HIGH] CWE-362 CVE-2026-54125: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50427P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50427 [HIGH] CWE-362 CVE-2026-50427: Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges local
Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50689P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-50689 [HIGH] CWE-362 CVE-2026-50689: Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges local
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32153P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32153 [HIGH] CWE-362 CVE-2026-32153: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32089P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32089 [HIGH] CWE-362 CVE-2026-32089: Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges lo
Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-64661P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.66912025-12-09
CVE-2025-64661 [HIGH] CWE-362 CVE-2025-64661: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58526P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58526 [HIGH] CWE-362 CVE-2026-58526: Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26167P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-26167 [HIGH] CWE-362 CVE-2026-26167: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-69799P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.77252026-09-08
CVE-2026-69799 [HIGH] CWE-362 CVE-2026-69799: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58628P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.75482026-07-14
CVE-2026-58628 [HIGH] CWE-362 CVE-2026-58628: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42991P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42991 [HIGH] CWE-362 CVE-2026-42991: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42978P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42978 [HIGH] CWE-362 CVE-2026-42978: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42979P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42979 [HIGH] CWE-362 CVE-2026-42979: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42977P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.74172026-06-09
CVE-2026-42977 [HIGH] CWE-362 CVE-2026-42977: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32164P3HIGHCVSS 7.8≥ 10.0.19044.0, < 10.0.19044.71842026-04-14
CVE-2026-32164 [HIGH] CWE-362 CVE-2026-32164: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
nvd