Microsoft Windows 11 Version 26H1 vulnerabilities
741 known vulnerabilities affecting microsoft/windows_11_version_26h1.
Total CVEs
741
CISA KEV
6
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL23HIGH567MEDIUM146LOW5
Vulnerabilities
Page 36 of 38
CVE-2026-42970P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-42970 [MEDIUM] CWE-200 CVE-2026-42970: Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an a
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42906P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-42906 [MEDIUM] CWE-200 CVE-2026-42906: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
nvd
CVE-2026-48566P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.21132026-06-09
CVE-2026-48566 [MEDIUM] CWE-125 CVE-2026-48566: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42968P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-42968 [MEDIUM] CWE-125 CVE-2026-42968: Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose informatio
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-35419P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-35419 [MEDIUM] CWE-125 CVE-2026-35419: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50316P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50316 [MEDIUM] CWE-532 CVE-2026-50316: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50409P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50409 [MEDIUM] CWE-200 CVE-2026-50409: Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an autho
Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32084P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32084 [MEDIUM] CWE-200 CVE-2026-32084: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32079P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32079 [MEDIUM] CWE-200 CVE-2026-32079: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-44814P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-44814 [MEDIUM] CWE-122 CVE-2026-44814: Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50295P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50295 [MEDIUM] CWE-269 CVE-2026-50295: Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a sec
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-21249P4LOWCVSS 3.3≥ 10.0.28000.0, < 10.0.28000.15752026-02-10
CVE-2026-21249 [LOW] CWE-73 CVE-2026-21249: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2026-50661P4MEDIUMCVSS 4.6≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50661 [MEDIUM] CWE-693 CVE-2026-50661: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-27931P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-27931 [MEDIUM] CWE-125 CVE-2026-27931: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-50431P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50431 [MEDIUM] CWE-200 CVE-2026-50431: Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
nvd
CVE-2026-32218P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32218 [MEDIUM] CWE-532 CVE-2026-32218: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32215P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32215 [MEDIUM] CWE-532 CVE-2026-32215: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32217P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32217 [MEDIUM] CWE-532 CVE-2026-32217: Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-27930P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-27930 [MEDIUM] CWE-125 CVE-2026-27930: Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-42915P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-42915 [MEDIUM] CWE-131 CVE-2026-42915: Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny servi
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.
nvd