microsoft / windows_11_26h1
1,009 known vulnerabilities in microsoft windows_11_26h1.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-33824 | Act now | 72.7% | 9.8 | ● | Double free in Windows IKE Extension allows an unauthorized attacker to execute … |
| CVE-2026-32202 | Act now | 63.7% | 4.3 | ● | Protection mechanism failure in Windows Shell allows an unauthorized attacker to… |
| CVE-2026-68820 | Act now | 6.2% | 7.0 | ● | Use after free in Windows Ancillary Function Driver for WinSock allows an author… |
| CVE-2026-81963 | Act now | 0.6% | 7.8 | ● | Improper link resolution before file access ('link following') in Windows Update… |
| CVE-2026-49160 | High | 53.8% | 7.5 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to d… | |
| CVE-2026-47291 | Medium | 22.8% | 9.8 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attack… | |
| CVE-2026-45657 | Medium | 15.5% | 9.8 | Use after free in Windows Kernel allows an unauthorized attacker to execute code… | |
| CVE-2026-42980 | Medium | 6.9% | 7.8 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authori… | |
| CVE-2026-66804 | Medium | 5.3% | 7.8 | Improper access control in Windows Cross Device Service allows an authorized att… | |
| CVE-2026-61358 | Medium | 3.7% | 7.8 | Improper link resolution before file access ('link following') in Windows Access… | |
| CVE-2026-45586 | Medium | 3.6% | 7.8 | Improper link resolution before file access ('link following') in Windows Collab… | |
| CVE-2026-50509 | Medium | 3.5% | 7.8 | Deserialization of untrusted data in Windows Wireless Wide Area Network Service … | |
| CVE-2026-62696 | Medium | 3.4% | 7.8 | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan… | |
| CVE-2026-62832 | Medium | 3.3% | 7.8 | Improper link resolution before file access ('link following') in Windows User P… | |
| CVE-2026-62737 | Medium | 2.8% | 7.8 | Untrusted pointer dereference in Windows Kernel allows an authorized attacker to… | |
| CVE-2026-65775 | Medium | 2.6% | 7.8 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-42989 | Medium | 2.3% | 7.8 | Improper link resolution before file access ('link following') in Winlogon allow… | |
| CVE-2026-33116 | Medium | 2.1% | 7.5 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, … | |
| CVE-2026-61930 | Medium | 2.1% | 7.8 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-62741 | Medium | 2.1% | 7.8 | Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized … | |
| CVE-2026-42905 | Medium | 2.0% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-42986 | Medium | 2.0% | 7.8 | Use after free in Microsoft Graphics Component allows an authorized attacker to … | |
| CVE-2026-62783 | Medium | 2.0% | 7.8 | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an… | |
| CVE-2026-62888 | Medium | 2.0% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-62713 | Medium | 2.0% | 7.8 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an a… | |
| CVE-2026-50652 | Medium | 1.7% | 7.5 | Deserialization of untrusted data in Azure Active Directory allows an unauthoriz… | |
| CVE-2026-59132 | Medium | 1.7% | 7.5 | Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to de… | |
| CVE-2026-61929 | Medium | 1.7% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-65788 | Medium | 1.7% | 7.0 | Use after free in Desktop Window Manager allows an authorized attacker to elevat… | |
| CVE-2026-61348 | Medium | 1.6% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-62766 | Medium | 1.5% | 7.0 | Double free in Windows Kerberos allows an authorized attacker to elevate privile… | |
| CVE-2026-42985 | Medium | 1.3% | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-50330 | Medium | 1.3% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-33096 | Medium | 1.2% | 7.5 | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny s… | |
| CVE-2026-62815 | Medium | 1.2% | 9.8 | Use after free in Microsoft QUIC allows an unauthorized attacker to execute code… | |
| CVE-2026-69587 | Medium | 1.2% | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacke… | |
| CVE-2026-69588 | Medium | 1.2% | 7.5 | Missing release of memory after effective lifetime in Windows TCP/IP allows an u… | |
| CVE-2026-32225 | Medium | 1.2% | 8.8 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to… | |
| CVE-2026-69881 | Medium | 1.2% | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacke… | |
| CVE-2026-40378 | Medium | 1.2% | 7.5 | Memory allocation with excessive size value in Windows Local Security Authority … | |
| CVE-2026-49787 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in Windows HTTP.sys allows … | |
| CVE-2026-49788 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in HTTP/2 allows an unautho… | |
| CVE-2026-50355 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50368 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50411 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allo… | |
| CVE-2026-50424 | Medium | 1.2% | 7.5 | Untrusted pointer dereference in Windows Domain Controller allows an unauthorize… | |
| CVE-2026-50496 | Medium | 1.2% | 7.5 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized … | |
| CVE-2026-50647 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Active Directory Feder… | |
| CVE-2026-50653 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory… | |
| CVE-2026-50695 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… |
Page 1 of 21
Next →