cbcvebase.

Microsoft Windows 11 26H1 vulnerabilities

708 known vulnerabilities affecting microsoft/windows_11_26h1.

Total CVEs
708
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH537MEDIUM144LOW4

Vulnerabilities

Page 23 of 36
CVE-2026-27908P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-27908 [HIGH] CWE-416 CVE-2026-27908: Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27921P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-27921 [HIGH] CWE-362 CVE-2026-27921: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-41108P3HIGHCVSS 7.0fixed in 10.0.28000.22692026-06-09
CVE-2026-41108 [HIGH] CWE-122 CVE-2026-41108: Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45653P3HIGHCVSS 7.0fixed in 10.0.28000.22692026-06-09
CVE-2026-45653 [HIGH] CWE-122 CVE-2026-45653: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32195P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-32195 [HIGH] CWE-121 CVE-2026-32195: Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges lo Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50682P3HIGHCVSS 7.1fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50682 [HIGH] CWE-125 CVE-2026-50682: Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
nvd
CVE-2026-57982P3MEDIUMCVSS 6.5fixed in 10.0.28000.25252026-07-14
CVE-2026-57982 [MEDIUM] CWE-908 CVE-2026-57982: Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information o Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-40414P3HIGHCVSS 7.4fixed in 10.0.28000.21132026-05-12
CVE-2026-40414 [HIGH] CWE-476 CVE-2026-40414: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an a Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.
nvd
CVE-2026-26151P3HIGHCVSS 7.1fixed in 10.0.28000.18362026-04-14
CVE-2026-26151 [HIGH] CWE-357 CVE-2026-26151: Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized att Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-25171P3HIGHCVSS 7.0fixed in 10.0.28000.17192026-03-10
CVE-2026-25171 [HIGH] CWE-416 CVE-2026-25171: Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32087P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-32087 [HIGH] CWE-122 CVE-2026-32087: Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker t Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42907P3MEDIUMCVSS 6.5fixed in 10.0.28000.22692026-06-09
CVE-2026-42907 [MEDIUM] CWE-200 CVE-2026-42907: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-34348P3MEDIUMCVSS 6.5fixed in 10.0.28000.22692026-07-14
CVE-2026-34348 [MEDIUM] CWE-693 CVE-2026-34348: Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to discl Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50302P3MEDIUMCVSS 6.5fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50302 [MEDIUM] CWE-295 CVE-2026-50302: Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-32093P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-32093 [HIGH] CWE-122 CVE-2026-32093: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32073P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-32073 [HIGH] CWE-416 CVE-2026-32073: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23667P3HIGHCVSS 7.0fixed in 10.0.28000.17192026-03-10
CVE-2026-23667 [HIGH] CWE-416 CVE-2026-23667: Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25170P3HIGHCVSS 7.0fixed in 10.0.28000.17192026-03-10
CVE-2026-25170 [HIGH] CWE-416 CVE-2026-25170: Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32075P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-32075 [HIGH] CWE-416 CVE-2026-32075: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347P3HIGHCVSS 7.0fixed in 10.0.28000.21132026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd