Windows 11 26h1
by Microsoft
CVEs (900)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-23670 | Med | 0.37 | 5.7 | 0.00 | Apr 14, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-72971 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-70348 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. | ||
| CVE-2026-65784 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-65662 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62887 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62798 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62796 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62793 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62786 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62775 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62746 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62743 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62740 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62738 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62730 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62709 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62703 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61936 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-61933 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
- risk 0.37cvss 5.7epss 0.00
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.00
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
- risk 0.36cvss 5.5epss 0.00
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Page 23 of 45