« Back to list

Microsoft

Microsoft Windows 11 26h1: vulnerabilities and CVEs

Microsoft Windows 11 26h1 has 1,532 published vulnerabilities, 1,532 of them in the last 12 months. 49 are rated critical and 4 are listed by CISA as actively exploited.

CVEs1,532
Last 12 months1,532
Critical49
Actively exploited4

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-81963High (7.8)0.39%⚠ Active exploitationSep 8, 2026
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-33824Critical (9.8)1.6%⚠ Active exploitationApr 14, 2026
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-68820High (7)0.33%⚠ Active exploitationAug 11, 2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-32202Medium (4.3)4.9%⚠ Active exploitationApr 14, 2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-85921High (8.2)0.35%—Sep 14, 2026
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-83999High (7)0.28%—Sep 8, 2026
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83997High (8.1)0.71%—Sep 8, 2026
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-83991Medium (5.5)0.30%—Sep 8, 2026
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
CVE-2026-83990High (7.8)0.33%—Sep 8, 2026
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-83988High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83987High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83986High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83985High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83983High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83982High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83981High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83980High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83979High (7.8)0.33%—Sep 8, 2026
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83978High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83977High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83976High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83975High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83974High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83973High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83972High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83971High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83970High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83969High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83968High (7.8)0.33%—Sep 8, 2026
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83967High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83955High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83954High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83952High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-83942High (7.8)0.30%—Sep 8, 2026
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation950
  2. T1059 Command and Scripting Interpreter801
  3. T1203 Exploitation for Client Execution137
  4. T1190 Exploit Public-Facing Application134
  5. T1210 Exploitation of Remote Services70
  6. T1548 Abuse Elevation Control Mechanism55

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Microsoft