VulnSea

windows_11_26h1 vulnerabilities

CVEs whose affected-version data names the windows_11_26h1 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

676 CVEsRSS

CVE-2026-34328Medium· 5.5
2mo ago

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.48%via NVD
CVE-2026-33842Medium· 5.5
2mo ago

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.48%via NVD
CVE-2026-48566Medium· 5.5
3mo ago

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ Sunlitmicrosoft · windows_11_24h2EPSS 0.40%via NVD
CVE-2026-42980High· 7.8PoC
3mo ago

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-32157High· 8.8
5mo ago

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · remote_desktop_clientEPSS 0.82%via NVD
CVE-2026-26174High· 7.0
5mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-33824Critical· 9.8CISA KEVPoC
5mo ago

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

▾ Hadalmicrosoft · windows_10_1607EPSS 1.6%via NVD
CVE-2026-32202Medium· 4.3CISA KEVPoC
5mo ago

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.9%via NVD
CVE-2026-32153High· 7.8
5mo ago

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.26%via NVD
CVE-2026-32225High· 8.8
5mo ago

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-32224High· 7.0
5mo ago

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_26h1EPSS 0.26%via NVD
CVE-2026-32223Medium· 6.8PoC
5mo ago

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.56%via NVD
CVE-2026-32222High· 7.8
5mo ago

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.33%via NVD
CVE-2026-32221High· 8.4
5mo ago

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.36%via NVD
CVE-2026-32220Medium· 4.4
5mo ago

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

▾ Sunlitmicrosoft · windows_11_24h2EPSS 0.34%via NVD
CVE-2026-24294High· 7.8PoC
6mo ago

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.7%via NVD
windows_11_26h1 vulnerabilities (CVEs) — page 23 · VulnSea