Microsoft Windows 11 Version 26H1 vulnerabilities
741 known vulnerabilities affecting microsoft/windows_11_version_26h1.
Total CVEs
741
CISA KEV
6
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL23HIGH567MEDIUM146LOW5
Vulnerabilities
Page 25 of 38
CVE-2026-32073P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32073 [HIGH] CWE-416 CVE-2026-32073: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21242P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.15752026-02-10
CVE-2026-21242 [HIGH] CWE-416 CVE-2026-21242: Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges lo
Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-23667P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.17192026-03-10
CVE-2026-23667 [HIGH] CWE-416 CVE-2026-23667: Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25170P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.17192026-03-10
CVE-2026-25170 [HIGH] CWE-416 CVE-2026-25170: Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32075P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32075 [HIGH] CWE-416 CVE-2026-32075: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42984P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-42984 [HIGH] CWE-416 CVE-2026-42984: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56173P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-56173 [HIGH] CWE-416 CVE-2026-56173: Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58629P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-58629 [HIGH] CWE-416 CVE-2026-58629: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50397P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50397 [HIGH] CWE-416 CVE-2026-50397: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56186P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-56186 [MEDIUM] CWE-125 CVE-2026-56186: Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50376P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50376 [MEDIUM] CWE-908 CVE-2026-50376: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-56168P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-56168 [MEDIUM] CWE-476 CVE-2026-56168: Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
nvd
CVE-2026-32151P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32151 [MEDIUM] CWE-200 CVE-2026-32151: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50432P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50432 [MEDIUM] CWE-416 CVE-2026-50432: Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny ser
Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.
nvd
CVE-2024-49075P3HIGHCVSS 7.5≥ 10.0.28000.0, < 10.0.28000.22692024-12-12
CVE-2024-49075 [HIGH] CWE-400 CVE-2024-49075: Windows Remote Desktop Services Denial of Service Vulnerability
Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2026-40413P3HIGHCVSS 7.4≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-40413 [HIGH] CWE-476 CVE-2026-40413: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an a
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.
cvelistv5nvd
CVE-2026-41097P3MEDIUMCVSS 6.7≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-41097 [MEDIUM] CWE-1329 CVE-2026-41097: Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-25179P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.17192026-03-10
CVE-2026-25179 [HIGH] CWE-1287 CVE-2026-25179: Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allo
Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32070P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32070 [HIGH] CWE-416 CVE-2026-32070: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate pri
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd