Windows 11 26h1
by Microsoft
Source repositories
CVEs (926)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-23673 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23672 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | ||
| CVE-2026-21248 | Hig | 0.51 | 7.3 | 0.01 | Feb 10, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2026-21245 | Hig | 0.51 | 7.8 | 0.00 | Feb 10, 2026 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21244 | Hig | 0.51 | 7.3 | 0.01 | Feb 10, 2026 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2026-21240 | Hig | 0.51 | 7.8 | 0.00 | Feb 10, 2026 | Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21238 | Hig | 0.51 | 7.8 | 0.03 | Feb 10, 2026 | Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21236 | Hig | 0.51 | 7.8 | 0.00 | Feb 10, 2026 | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21232 | Hig | 0.51 | 7.8 | 0.00 | Feb 10, 2026 | Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21231 | Hig | 0.51 | 7.8 | 0.03 | Feb 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61363 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-61352 | Hig | 0.49 | 7.5 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-59134 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-59132 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2026 | Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-54113 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2026 | Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50696 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-49160 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2026 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-48563 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-44801 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-44799 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.3epss 0.01
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.3epss 0.01
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Page 15 of 47