cbcvebase.

Microsoft Windows 11 26H1 vulnerabilities

708 known vulnerabilities affecting microsoft/windows_11_26h1.

Total CVEs
708
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH537MEDIUM144LOW4

Vulnerabilities

Page 22 of 36
CVE-2026-50424P3HIGHCVSS 7.5fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50424 [HIGH] CWE-822 CVE-2026-50424: Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny s Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50667P3HIGHCVSS 7.0fixed in 10.0.28000.25252026-07-14
CVE-2026-50667 [HIGH] CWE-362 CVE-2026-50667: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49805P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-49805 [HIGH] CWE-284 CVE-2026-49805: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-48575P3HIGHCVSS 7.9fixed in 10.0.28000.22692026-06-09
CVE-2026-48575 [HIGH] CWE-693 CVE-2026-48575: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48570P3HIGHCVSS 7.9fixed in 10.0.28000.22692026-06-09
CVE-2026-48570 [HIGH] CWE-693 CVE-2026-48570: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48568P3HIGHCVSS 7.9fixed in 10.0.28000.22692026-06-09
CVE-2026-48568 [HIGH] CWE-693 CVE-2026-48568: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-45588P3HIGHCVSS 7.9fixed in 10.0.28000.22692026-06-09
CVE-2026-45588 [HIGH] CWE-693 CVE-2026-45588: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48578P3HIGHCVSS 7.9fixed in 10.0.28000.22692026-06-09
CVE-2026-48578 [HIGH] CWE-284 CVE-2026-48578: Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges l Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50388P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50388 [HIGH] CWE-125 CVE-2026-50388: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally. Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50308P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50308 [HIGH] CWE-122 CVE-2026-50308: Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute co Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-58609P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-58609 [HIGH] CWE-125 CVE-2026-58609: Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code l Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-26161P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-26161 [HIGH] CWE-20 CVE-2026-26161: Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevat Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50673P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50673 [HIGH] CWE-367 CVE-2026-50673: Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges local Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35416P3HIGHCVSS 7.0fixed in 10.0.28000.21132026-05-12
CVE-2026-35416 [HIGH] CWE-416 CVE-2026-35416: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58529P3HIGHCVSS 7.1fixed in 10.0.28000.25252026-07-14
CVE-2026-58529 [HIGH] CWE-125 CVE-2026-58529: Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50364P3HIGHCVSS 7.3fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50364 [HIGH] CWE-59 CVE-2026-50364: Improper link resolution before file access ('link following') in Windows Server Backup allows an au Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32149P3HIGHCVSS 7.3fixed in 10.0.28000.18362026-04-14
CVE-2026-32149 [HIGH] CWE-20 CVE-2026-32149: Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2026-25190P3HIGHCVSS 7.8fixed in 10.0.28000.17192026-03-10
CVE-2026-25190 [HIGH] CWE-426 CVE-2026-25190: Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-32071P3HIGHCVSS 7.5fixed in 10.0.28000.18362026-04-14
CVE-2026-32071 [HIGH] CWE-476 CVE-2026-32071: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-40378P3HIGHCVSS 7.5fixed in 10.0.28000.22692026-07-14
CVE-2026-40378 [HIGH] CWE-789 CVE-2026-40378: Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (L Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd