Microsoft Windows 11 26H1 vulnerabilities
708 known vulnerabilities affecting microsoft/windows_11_26h1.
Total CVEs
708
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL23HIGH537MEDIUM144LOW4
Vulnerabilities
Page 7 of 36
CVE-2026-58547P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-07-14
CVE-2026-58547 [HIGH] CWE-122 CVE-2026-58547: Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to el
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50332P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50332 [HIGH] CWE-122 CVE-2026-50332: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50327P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50327 [HIGH] CWE-122 CVE-2026-50327: Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
nvd
CVE-2026-58542P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-07-14
CVE-2026-58542 [HIGH] CWE-122 CVE-2026-58542: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50680P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50680 [HIGH] CWE-122 CVE-2026-50680: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges lo
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50477P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50477 [HIGH] CWE-122 CVE-2026-50477: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56650P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-07-14
CVE-2026-56650 [HIGH] CWE-122 CVE-2026-56650: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50484P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50484 [HIGH] CWE-122 CVE-2026-50484: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58538P3HIGHCVSS 7.8fixed in 10.0.28000.22692026-07-14
CVE-2026-58538 [HIGH] CWE-122 CVE-2026-58538: Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate pri
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50679P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50679 [HIGH] CWE-122 CVE-2026-50679: Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to el
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50363P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50363 [HIGH] CWE-122 CVE-2026-50363: Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate pr
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50494P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50494 [HIGH] CWE-122 CVE-2026-50494: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50417P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-50417 [HIGH] CWE-20 CVE-2026-50417: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50336P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50336 [HIGH] CWE-122 CVE-2026-50336: Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges loca
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56175P3HIGHCVSS 7.8fixed in 10.0.28000.25252026-07-14
CVE-2026-56175 [HIGH] CWE-122 CVE-2026-56175: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges local
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33841P3HIGHCVSS 7.8fixed in 10.0.28000.21132026-05-12
CVE-2026-33841 [HIGH] CWE-122 CVE-2026-33841: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377P3HIGHCVSS 7.8fixed in 10.0.28000.21132026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26180P3HIGHCVSS 7.8fixed in 10.0.28000.18362026-04-14
CVE-2026-26180 [HIGH] CWE-122 CVE-2026-26180: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50400P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50400 [HIGH] CWE-121 CVE-2026-50400: Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privil
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50423P3HIGHCVSS 7.8fixed in 10.0.28000.2269fixed in 10.0.28000.25252026-07-14
CVE-2026-50423 [HIGH] CWE-284 CVE-2026-50423: Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locall
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd