cbcvebase.

Microsoft Windows 11 26H1 vulnerabilities

708 known vulnerabilities affecting microsoft/windows_11_26h1.

Total CVEs
708
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL23HIGH537MEDIUM144LOW4

Vulnerabilities

Page 11 of 36
CVE-2026-34343P3HIGHCVSS 7.8fixed in 10.0.28000.21132026-05-12
CVE-2026-34343 [HIGH] CWE-122 CVE-2026-34343: Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized at Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50687P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50687 [HIGH] CWE-416 CVE-2026-50687: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50478P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50478 [HIGH] CWE-416 CVE-2026-50478: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50326P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50326 [HIGH] CWE-416 CVE-2026-50326: Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56643P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-56643 [HIGH] CWE-416 CVE-2026-56643: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50353P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50353 [HIGH] CWE-416 CVE-2026-50353: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56644P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-56644 [HIGH] CWE-416 CVE-2026-56644: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45641P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-06-09
CVE-2026-45641 [HIGH] CWE-843 CVE-2026-45641: Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthori Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50471P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50471 [HIGH] CWE-122 CVE-2026-50471: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-34333P3HIGHCVSS 7.8fixed in 10.0.28000.21132026-05-12
CVE-2026-34333 [HIGH] CWE-190 CVE-2026-34333: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58632P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-07-14
CVE-2026-58632 [HIGH] CWE-416 CVE-2026-58632: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49791P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-49791 [HIGH] CWE-59 CVE-2026-49791: Improper link resolution before file access ('link following') in Windows Routing and Remote Access Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50469P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50469 [HIGH] CWE-59 CVE-2026-50469: Improper link resolution before file access ('link following') in Windows Projected File System allo Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-48583P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-06-09
CVE-2026-48583 [HIGH] CWE-416 CVE-2026-48583: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26159P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-26159 [HIGH] CWE-306 CVE-2026-26159: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26176P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-26176 [HIGH] CWE-122 CVE-2026-26176: Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized atta Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50333P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50333 [HIGH] CWE-306 CVE-2026-50333: Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50459P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50459 [HIGH] CWE-416 CVE-2026-50459: Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-50504P3HIGHCVSS 7.5fixed in 10.0.28000.25252026-07-14
CVE-2026-50504 [HIGH] CWE-126 CVE-2026-50504: Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information ov Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-42992P3HIGHCVSS 7.5fixed in 10.0.28000.22692026-06-09
CVE-2026-42992 [HIGH] CWE-122 CVE-2026-42992: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
Microsoft Windows 11 26H1 vulnerabilities | cvebase