Microsoft Windows 11 Version 26H1 vulnerabilities
741 known vulnerabilities affecting microsoft/windows_11_version_26h1.
Total CVEs
741
CISA KEV
6
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL23HIGH567MEDIUM146LOW5
Vulnerabilities
Page 33 of 38
CVE-2026-32088P4MEDIUMCVSS 5.7≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32088 [MEDIUM] CWE-362 CVE-2026-32088: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-50475P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50475 [MEDIUM] CWE-126 CVE-2026-50475: Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50341P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50341 [MEDIUM] CWE-126 CVE-2026-50341: Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42914P4MEDIUMCVSS 5.3≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-42914 [MEDIUM] CWE-125 CVE-2026-42914: Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-40401P4HIGHCVSS 7.1≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-40401 [HIGH] CWE-476 CVE-2026-40401: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.
cvelistv5nvd
CVE-2026-25180P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.17192026-03-10
CVE-2026-25180 [MEDIUM] CWE-125 CVE-2026-25180: Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose infor
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-25186P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.17192026-03-10
CVE-2026-25186 [MEDIUM] CWE-200 CVE-2026-25186: Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50681P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50681 [MEDIUM] CWE-200 CVE-2026-50681: Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50352P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50352 [MEDIUM] CWE-200 CVE-2026-50352: Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42969P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-42969 [MEDIUM] CWE-908 CVE-2026-42969: Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclos
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50690P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50690 [MEDIUM] CWE-908 CVE-2026-50690: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20806P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-20806 [MEDIUM] CWE-843 CVE-2026-20806: Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized at
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50483P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50483 [MEDIUM] CWE-200 CVE-2026-50483: Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an
Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49180P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49180 [MEDIUM] CWE-59 CVE-2026-49180: Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll)
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50383P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50383 [MEDIUM] CWE-126 CVE-2026-50383: Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose infor
Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49801P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49801 [MEDIUM] CWE-908 CVE-2026-49801: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-40422P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-40422 [MEDIUM] CWE-908 CVE-2026-40422: Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose inf
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49177P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49177 [MEDIUM] CWE-125 CVE-2026-49177: Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
nvd
CVE-2026-54997P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-54997 [MEDIUM] CWE-908 CVE-2026-54997: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50300P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50300 [MEDIUM] CWE-125 CVE-2026-50300: Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose i
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
nvd