VYPR

Windows 11 26h1

by Microsoft

Source repositories

CVEs (926)

  • CVE-2026-45585MedMay 20, 2026
    risk 0.44cvss 6.8epss 0.00

    Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide…

  • CVE-2026-41097MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.02

    Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-32170MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.00

    Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

  • CVE-2026-21530MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.00

    Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

  • CVE-2026-32223MedApr 14, 2026
    risk 0.44cvss 6.8epss 0.01

    Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-61920MedAug 11, 2026
    risk 0.43cvss 6.6epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

  • CVE-2026-65794MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-65785MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

  • CVE-2026-62782MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-62750MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.

  • CVE-2026-62708MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.00

    Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-61924MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-61921MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-61918MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-61345MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

  • CVE-2026-59138MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

  • CVE-2026-42907MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

  • CVE-2026-42903MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.01

    Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

  • CVE-2026-35422MedMay 12, 2026
    risk 0.42cvss 6.5epss 0.01

    Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.

  • CVE-2026-32151MedApr 14, 2026
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

Page 23 of 47