« Volver al listado

Microsoft

Microsoft Windows 11 26h1: vulnerabilidades y CVE

Microsoft Windows 11 26h1 tiene 1532 vulnerabilidades publicadas, 1532 de ellas en los últimos 12 meses. 49 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE1532
Últimos 12 meses1532
Críticas49
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81963Alta (7.8)0.39%⚠ Explotación activa8 sept 2026
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-33824Crítica (9.8)1.6%⚠ Explotación activa14 abr 2026
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-68820Alta (7)0.33%⚠ Explotación activa11 ago 2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-32202Media (4.3)4.9%⚠ Explotación activa14 abr 2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85921Alta (8.2)0.35%—14 sept 2026
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-83999Alta (7)0.28%—8 sept 2026
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83997Alta (8.1)0.71%—8 sept 2026
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-83991Media (5.5)0.30%—8 sept 2026
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2026-83990Alta (7.8)0.33%—8 sept 2026
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-83988Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83987Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83986Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83985Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83983Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83982Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83981Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83980Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83979Alta (7.8)0.33%—8 sept 2026
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83978Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83977Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83976Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83975Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83974Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83973Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83972Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83971Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83970Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83969Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83968Alta (7.8)0.33%—8 sept 2026
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83967Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83955Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83954Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83952Alta (7.8)0.33%—8 sept 2026
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-83942Alta (7.8)0.30%—8 sept 2026
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation950
  2. T1059 Command and Scripting Interpreter801
  3. T1203 Exploitation for Client Execution137
  4. T1190 Exploit Public-Facing Application134
  5. T1210 Exploitation of Remote Services70
  6. T1548 Abuse Elevation Control Mechanism55

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Microsoft