cbcvebase.

Microsoft Windows 11 26H1 vulnerabilities

708 known vulnerabilities affecting microsoft/windows_11_26h1.

Total CVEs
708
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH537MEDIUM144LOW4

Vulnerabilities

Page 35 of 36
CVE-2026-32218P4MEDIUMCVSS 5.5fixed in 10.0.28000.18362026-04-14
CVE-2026-32218 [MEDIUM] CWE-532 CVE-2026-32218: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32215P4MEDIUMCVSS 5.5fixed in 10.0.28000.18362026-04-14
CVE-2026-32215 [MEDIUM] CWE-532 CVE-2026-32215: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32217P4MEDIUMCVSS 5.5fixed in 10.0.28000.18362026-04-14
CVE-2026-32217 [MEDIUM] CWE-532 CVE-2026-32217: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-27930P4MEDIUMCVSS 5.5fixed in 10.0.28000.18362026-04-14
CVE-2026-27930 [MEDIUM] CWE-125 CVE-2026-27930: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-42915P4MEDIUMCVSS 5.5fixed in 10.0.28000.22692026-06-09
CVE-2026-42915 [MEDIUM] CWE-131 CVE-2026-42915: Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny servi Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
nvd
CVE-2026-50316P4MEDIUMCVSS 5.5fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50316 [MEDIUM] CWE-532 CVE-2026-50316: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45604P4MEDIUMCVSS 5.5fixed in 10.0.28000.22692026-06-09
CVE-2026-45604 [MEDIUM] CWE-125 CVE-2026-45604: Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker t Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34346P4MEDIUMCVSS 5.5fixed in 10.0.28000.22692026-07-14
CVE-2026-34346 [MEDIUM] CWE-319 CVE-2026-34346: Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock all Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50661P4MEDIUMCVSS 4.6fixed in 10.0.28000.25252026-07-14
CVE-2026-50661 [MEDIUM] CWE-693 CVE-2026-50661: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-50310P4MEDIUMCVSS 4.7fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50310 [MEDIUM] CWE-190 CVE-2026-50310: Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to d Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
nvd
CVE-2026-25169P4MEDIUMCVSS 5.5fixed in 10.0.28000.17192026-03-10
CVE-2026-25169 [MEDIUM] CWE-369 CVE-2026-25169: Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service local Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-32181P4MEDIUMCVSS 5.5fixed in 10.0.28000.18362026-04-14
CVE-2026-32181 [MEDIUM] CWE-269 CVE-2026-32181: Improper privilege management in Microsoft Windows allows an authorized attacker to deny service loc Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
nvd
CVE-2026-25168P4MEDIUMCVSS 5.5fixed in 10.0.28000.17192026-03-10
CVE-2026-25168 [MEDIUM] CWE-476 CVE-2026-25168: Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-32216P4MEDIUMCVSS 5.5fixed in 10.0.28000.18362026-04-14
CVE-2026-32216 [MEDIUM] CWE-476 CVE-2026-32216: Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.
nvd
CVE-2026-34339P4MEDIUMCVSS 5.5fixed in 10.0.28000.21132026-05-12
CVE-2026-34339 [MEDIUM] CWE-476 CVE-2026-34339: Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorize Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
nvd
CVE-2026-26175P4MEDIUMCVSS 4.6fixed in 10.0.28000.18362026-04-14
CVE-2026-26175 [MEDIUM] CWE-908 CVE-2026-26175: Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a se Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-45606P4MEDIUMCVSS 5.5fixed in 10.0.28000.22692026-06-09
CVE-2026-45606 [MEDIUM] CWE-125 CVE-2026-45606: Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
nvd
CVE-2026-27906P4MEDIUMCVSS 4.4fixed in 10.0.28000.18362026-04-14
CVE-2026-27906 [MEDIUM] CWE-20 CVE-2026-27906: Improper input validation in Windows Hello allows an authorized attacker to bypass a security featur Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32220P4MEDIUMCVSS 4.4fixed in 10.0.28000.18362026-04-14
CVE-2026-32220 [MEDIUM] CWE-284 CVE-2026-32220: Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32209P4MEDIUMCVSS 4.4fixed in 10.0.28000.21132026-05-12
CVE-2026-32209 [MEDIUM] CWE-284 CVE-2026-32209: Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
nvd
Microsoft Windows 11 26H1 vulnerabilities | cvebase