Microsoft Windows 11 26H1 vulnerabilities
708 known vulnerabilities affecting microsoft/windows_11_26h1.
Total CVEs
708
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH537MEDIUM144LOW4
Vulnerabilities
Page 29 of 36
CVE-2026-50668P3MEDIUMCVSS 6.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50668 [MEDIUM] CWE-122 CVE-2026-50668: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges wit
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-42903P3MEDIUMCVSS 6.5fixed in 10.0.28000.22692026-06-09
CVE-2026-42903 [MEDIUM] CWE-476 CVE-2026-42903: Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2026-26155P3MEDIUMCVSS 6.5fixed in 10.0.28000.18362026-04-14
CVE-2026-26155 [MEDIUM] CWE-126 CVE-2026-26155: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2026-49799P3MEDIUMCVSS 6.5fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-49799 [MEDIUM] CWE-400 CVE-2026-49799: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-55144P3HIGHCVSS 7.1fixed in 10.0.28000.25252026-07-14
CVE-2026-55144 [HIGH] CWE-325 CVE-2026-55144: Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering l
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-47648P3HIGHCVSS 7.0fixed in 10.0.28000.22692026-06-09
CVE-2026-47648 [HIGH] CWE-426 CVE-2026-47648: Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50297P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50297 [HIGH] CWE-284 CVE-2026-50297: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50325P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50325 [HIGH] CWE-284 CVE-2026-50325: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34341P3HIGHCVSS 7.0fixed in 10.0.28000.21132026-05-12
CVE-2026-34341 [HIGH] CWE-415 CVE-2026-34341: Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25184P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-25184 [HIGH] CWE-362 CVE-2026-25184: Concurrent execution using shared resource with improper synchronization ('race condition') in Applo
Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32086P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-32086 [HIGH] CWE-362 CVE-2026-32086: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32150P3HIGHCVSS 7.0fixed in 10.0.28000.18362026-04-14
CVE-2026-32150 [HIGH] CWE-362 CVE-2026-32150: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54991P3HIGHCVSS 7.0fixed in 10.0.28000.25252026-07-14
CVE-2026-54991 [HIGH] CWE-125 CVE-2026-54991: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50356P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50356 [HIGH] CWE-362 CVE-2026-50356: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49806P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-49806 [HIGH] CWE-362 CVE-2026-49806: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54996P3HIGHCVSS 7.0fixed in 10.0.28000.25252026-07-14
CVE-2026-54996 [HIGH] CWE-125 CVE-2026-54996: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49802P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-49802 [HIGH] CWE-362 CVE-2026-49802: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49784P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-49784 [HIGH] CWE-362 CVE-2026-49784: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54111P3HIGHCVSS 7.0fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-54111 [HIGH] CWE-125 CVE-2026-54111: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50492P3MEDIUMCVSS 6.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50492 [MEDIUM] CWE-122 CVE-2026-50492: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker t
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.
nvd