Microsoft
Microsoft Windows 11 26h1: vulnerabilities and CVEs
Microsoft Windows 11 26h1 has 1,532 published vulnerabilities, 1,532 of them in the last 12 months. 49 are rated critical and 4 are listed by CISA as actively exploited.
CVEs1,532
Last 12 months1,532
Critical49
Actively exploited4
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81963 | High (7.8) | 0.39% | ⚠ Active exploitation | Sep 8, 2026 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. |
| CVE-2026-33824 | Critical (9.8) | 1.6% | ⚠ Active exploitation | Apr 14, 2026 | Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
| CVE-2026-68820 | High (7) | 0.33% | ⚠ Active exploitation | Aug 11, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32202 | Medium (4.3) | 4.9% | ⚠ Active exploitation | Apr 14, 2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85921 | High (8.2) | 0.35% | — | Sep 14, 2026 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83999 | High (7) | 0.28% | — | Sep 8, 2026 | Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83997 | High (8.1) | 0.71% | — | Sep 8, 2026 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. |
| CVE-2026-83991 | Medium (5.5) | 0.30% | — | Sep 8, 2026 | Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally. |
| CVE-2026-83990 | High (7.8) | 0.33% | — | Sep 8, 2026 | Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83988 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83987 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83986 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83985 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83983 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83982 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83981 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83980 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83979 | High (7.8) | 0.33% | — | Sep 8, 2026 | Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83978 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83977 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83976 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83975 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83974 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83973 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83972 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83971 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83970 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83969 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83968 | High (7.8) | 0.33% | — | Sep 8, 2026 | Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83967 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83955 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83954 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83952 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-83942 | High (7.8) | 0.30% | — | Sep 8, 2026 | Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.