cbcvebase.

Microsoft Windows 11 26H1 vulnerabilities

708 known vulnerabilities affecting microsoft/windows_11_26h1.

Total CVEs
708
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH537MEDIUM144LOW4

Vulnerabilities

Page 17 of 36
CVE-2026-27923P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-27923 [HIGH] CWE-416 CVE-2026-27923: Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58602P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-58602 [HIGH] CWE-416 CVE-2026-58602: Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges loc Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49171P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-49171 [HIGH] CWE-416 CVE-2026-49171: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50405P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50405 [HIGH] CWE-1220 CVE-2026-50405: Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32160P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-32160 [HIGH] CWE-362 CVE-2026-32160: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32159P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-32159 [HIGH] CWE-362 CVE-2026-32159: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50393P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50393 [HIGH] CWE-416 CVE-2026-50393: Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50396P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50396 [HIGH] CWE-416 CVE-2026-50396: Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32158P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-32158 [HIGH] CWE-362 CVE-2026-32158: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32153P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-32153 [HIGH] CWE-362 CVE-2026-32153: Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42979P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-06-09
CVE-2026-42979 [HIGH] CWE-362 CVE-2026-42979: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42977P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-06-09
CVE-2026-42977 [HIGH] CWE-362 CVE-2026-42977: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50457P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50457 [HIGH] CWE-362 CVE-2026-50457: Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54125P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-54125 [HIGH] CWE-362 CVE-2026-54125: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50427P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50427 [HIGH] CWE-362 CVE-2026-50427: Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges local Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58628P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-07-14
CVE-2026-58628 [HIGH] CWE-362 CVE-2026-58628: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26168P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-26168 [HIGH] CWE-362 CVE-2026-26168: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26167P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-26167 [HIGH] CWE-362 CVE-2026-26167: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42991P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-06-09
CVE-2026-42991 [HIGH] CWE-362 CVE-2026-42991: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-44800P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-07-14
CVE-2026-44800 [HIGH] CWE-362 CVE-2026-44800: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 11 26H1 vulnerabilities | cvebase