Microsoft Windows 11 Version 26H1 vulnerabilities
741 known vulnerabilities affecting microsoft/windows_11_version_26h1.
Total CVEs
741
CISA KEV
6
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL23HIGH567MEDIUM146LOW5
Vulnerabilities
Page 31 of 38
CVE-2026-50325P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50325 [HIGH] CWE-284 CVE-2026-50325: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34341P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-34341 [HIGH] CWE-415 CVE-2026-34341: Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-25184P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-25184 [HIGH] CWE-362 CVE-2026-25184: Concurrent execution using shared resource with improper synchronization ('race condition') in Applo
Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32086P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32086 [HIGH] CWE-362 CVE-2026-32086: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32150P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32150 [HIGH] CWE-362 CVE-2026-32150: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54991P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-54991 [HIGH] CWE-125 CVE-2026-54991: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50356P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50356 [HIGH] CWE-362 CVE-2026-50356: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49806P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49806 [HIGH] CWE-362 CVE-2026-49806: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54996P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-54996 [HIGH] CWE-125 CVE-2026-54996: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49802P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49802 [HIGH] CWE-362 CVE-2026-49802: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49784P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49784 [HIGH] CWE-362 CVE-2026-49784: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54111P3HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-54111 [HIGH] CWE-125 CVE-2026-54111: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50492P3MEDIUMCVSS 6.8≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50492 [MEDIUM] CWE-122 CVE-2026-50492: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker t
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-27929P4HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-27929 [HIGH] CWE-367 CVE-2026-27929: Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45487P4HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-45487 [HIGH] CWE-367 CVE-2026-45487: Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49168P4MEDIUMCVSS 6.8≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49168 [MEDIUM] CWE-190 CVE-2026-49168: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-27925P4MEDIUMCVSS 6.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-27925 [MEDIUM] CWE-416 CVE-2026-27925: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2026-49165P4HIGHCVSS 7.1≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49165 [HIGH] CWE-908 CVE-2026-49165: Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50465P4HIGHCVSS 7.1≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50465 [HIGH] CWE-284 CVE-2026-50465: Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-26152P4HIGHCVSS 7.0≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-26152 [HIGH] CWE-922 CVE-2026-26152: Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized att
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd