cbcvebase.

Microsoft Windows 11 Version 26H1 vulnerabilities

741 known vulnerabilities affecting microsoft/windows_11_version_26h1.

Total CVEs
741
CISA KEV
6
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL23HIGH567MEDIUM146LOW5

Vulnerabilities

Page 28 of 38
CVE-2026-26173P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-26173 [HIGH] CWE-362 CVE-2026-26173: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54107P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-54107 [HIGH] CWE-362 CVE-2026-54107: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50404P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50404 [HIGH] CWE-362 CVE-2026-50404: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54112P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-54112 [HIGH] CWE-362 CVE-2026-54112: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50450P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50450 [HIGH] CWE-362 CVE-2026-50450: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50672P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50672 [HIGH] CWE-362 CVE-2026-50672: Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally. Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54132P3MEDIUMCVSS 6.8≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-54132 [MEDIUM] CWE-122 CVE-2026-54132: Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges w Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50668P3MEDIUMCVSS 6.8≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50668 [MEDIUM] CWE-122 CVE-2026-50668: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges wit Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50366P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50366 [MEDIUM] CWE-476 CVE-2026-50366: Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny s Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
nvd
CVE-2026-57976P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-57976 [MEDIUM] CWE-476 CVE-2026-57976: Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny s Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
nvd
CVE-2026-55003P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-55003 [MEDIUM] CWE-908 CVE-2026-55003: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58546P3MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-58546 [MEDIUM] CWE-908 CVE-2026-58546: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-21330P3HIGHCVSS 7.5≥ 10.0.28000.0, < 10.0.28000.22692025-01-14
CVE-2025-21330 [HIGH] CWE-400 CVE-2025-21330: Windows Remote Desktop Services Denial of Service Vulnerability Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2026-50354P3HIGHCVSS 7.1≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50354 [HIGH] CWE-416 CVE-2026-50354: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21240P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.15752026-02-10
CVE-2026-21240 [HIGH] CWE-367 CVE-2026-21240: Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50372P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50372 [HIGH] CWE-122 CVE-2026-50372: Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate priv Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32224P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32224 [HIGH] CWE-416 CVE-2026-32224: Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26166P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-26166 [HIGH] CWE-415 CVE-2026-26166: Double free in Windows Shell allows an authorized attacker to elevate privileges locally. Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27917P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-27917 [HIGH] CWE-416 CVE-2026-27917: Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized atta Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45640P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-45640 [HIGH] CWE-416 CVE-2026-45640: Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows 11 Version 26H1 vulnerabilities | cvebase