cbcvebase.

Microsoft Windows 11 Version 26H1 vulnerabilities

741 known vulnerabilities affecting microsoft/windows_11_version_26h1.

Total CVEs
741
CISA KEV
6
actively exploited
Public exploits
6
Exploited in wild
9
Severity breakdown
CRITICAL23HIGH567MEDIUM146LOW5

Vulnerabilities

Page 37 of 38
CVE-2026-45604P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-45604 [MEDIUM] CWE-125 CVE-2026-45604: Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker t Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34346P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-34346 [MEDIUM] CWE-319 CVE-2026-34346: Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock all Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50310P4MEDIUMCVSS 4.7≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50310 [MEDIUM] CWE-190 CVE-2026-50310: Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to d Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.
nvd
CVE-2026-25169P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.17192026-03-10
CVE-2026-25169 [MEDIUM] CWE-369 CVE-2026-25169: Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service local Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-32181P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32181 [MEDIUM] CWE-269 CVE-2026-32181: Improper privilege management in Microsoft Windows allows an authorized attacker to deny service loc Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
nvd
CVE-2026-25168P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.17192026-03-10
CVE-2026-25168 [MEDIUM] CWE-476 CVE-2026-25168: Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-32216P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32216 [MEDIUM] CWE-476 CVE-2026-32216: Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.
nvd
CVE-2026-34339P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-34339 [MEDIUM] CWE-476 CVE-2026-34339: Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorize Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
nvd
CVE-2026-26175P4MEDIUMCVSS 4.6≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-26175 [MEDIUM] CWE-908 CVE-2026-26175: Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a se Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-45606P4MEDIUMCVSS 5.5≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-45606 [MEDIUM] CWE-125 CVE-2026-45606: Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
nvd
CVE-2026-27906P4MEDIUMCVSS 4.4≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-27906 [MEDIUM] CWE-20 CVE-2026-27906: Improper input validation in Windows Hello allows an authorized attacker to bypass a security featur Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32220P4MEDIUMCVSS 4.4≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-32220 [MEDIUM] CWE-284 CVE-2026-32220: Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32209P4MEDIUMCVSS 4.4≥ 10.0.28000.0, < 10.0.28000.21132026-05-12
CVE-2026-32209 [MEDIUM] CWE-284 CVE-2026-32209: Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-58528P4MEDIUMCVSS 4.6≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-58528 [MEDIUM] CWE-125 CVE-2026-58528: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-20928P4MEDIUMCVSS 4.6≥ 10.0.28000.0, < 10.0.28000.18362026-04-14
CVE-2026-20928 [MEDIUM] CWE-212 CVE-2026-20928: Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-50453P4MEDIUMCVSS 4.6≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50453 [MEDIUM] CWE-125 CVE-2026-50453: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-49794P4MEDIUMCVSS 4.6≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-49794 [MEDIUM] CWE-125 CVE-2026-49794: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-45642P4LOWCVSS 3.9≥ 10.0.28000.0, < 10.0.28000.22692026-06-09
CVE-2026-45642 [LOW] CWE-20 CVE-2026-45642: Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Servi Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
nvd
CVE-2026-50416P4LOWCVSS 3.3≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-50416 [LOW] CWE-200 CVE-2026-50416: Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized at Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
nvd
CVE-2026-57085P4LOWCVSS 3.3≥ 10.0.28000.0, < 10.0.28000.25252026-07-14
CVE-2026-57085 [LOW] CWE-125 CVE-2026-57085: Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose inf Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.
nvd
Microsoft Windows 11 Version 26H1 vulnerabilities | cvebase