Microsoft Windows 11 Version 26H1 vulnerabilities
741 known vulnerabilities affecting microsoft/windows_11_version_26h1.
Total CVEs
741
CISA KEV
6
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL23HIGH567MEDIUM146LOW5
Vulnerabilities
Page 34 of 38
CVE-2026-50381P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50381 [MEDIUM] CWE-843 CVE-2026-50381: Access of resource using incompatible type ('type confusion') in Composite Image File System Driver
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50495P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50495 [MEDIUM] CWE-284 CVE-2026-50495: Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
nvd
CVE-2026-58614P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-58614 [MEDIUM] CWE-125 CVE-2026-58614: Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature loca
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-58545P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-58545 [MEDIUM] CWE-284 CVE-2026-58545: Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-58638P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-58638 [MEDIUM] CWE-325 CVE-2026-58638: Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50303P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50303 [MEDIUM] CWE-1240 CVE-2026-50303: Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authoriz
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50485P4MEDIUMCVSS 5.7≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50485 [MEDIUM] CWE-126 CVE-2026-50485: Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent n
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2026-57084P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-57084 [MEDIUM] CWE-908 CVE-2026-57084: Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose i
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-57083P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-57083 [MEDIUM] CWE-908 CVE-2026-57083: Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-50389P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50389 [MEDIUM] CWE-200 CVE-2026-50389: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-56184P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-56184 [MEDIUM] CWE-200 CVE-2026-56184: Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45594P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-45594 [MEDIUM] CWE-200 CVE-2026-45594: Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) S
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50420P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50420 [MEDIUM] CWE-125 CVE-2026-50420: Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information local
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-45634P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-45634 [MEDIUM] CWE-125 CVE-2026-45634: Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information loca
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34349P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-34349 [MEDIUM] CWE-200 CVE-2026-34349: Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50394P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50394 [MEDIUM] CWE-200 CVE-2026-50394: Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50434P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50434 [MEDIUM] CWE-200 CVE-2026-50434: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50334P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50334 [MEDIUM] CWE-200 CVE-2026-50334: Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authori
Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50339P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50339 [MEDIUM] CWE-200 CVE-2026-50339: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-33842P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-33842 [MEDIUM] CWE-200 CVE-2026-33842: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd