📦

windows_11_26h1

Vendor: microsoft

Actively Exploited 1 CISA KEV List
PoC / Exploits 14 Code Available
Total RCEs 16 Remote Access
Total CVEs 685 Total Indexed
Avg. EPSS 0.65% Exploit Prob.
Latest CVE CVE-2026-50507 Jun 09

Security Vulnerability Index

Page 13 / 69
6.2 CVSS

Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

EPSS: 0.45%
7.8 CVSS

Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.

EPSS: 0.30%
7.8 CVSS
CVE-2026-40369
Exploit Found

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

EPSS: 3.52%
7.5 CVSS

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.

EPSS: 1.19%
5.4 CVSS

Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network.

EPSS: 0.75%
6.5 CVSS

Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.

EPSS: 0.61%
7.8 CVSS

Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.

EPSS: 0.52%
5.5 CVSS

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

EPSS: 0.37%
7.8 CVSS

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

EPSS: 0.20%
7.8 CVSS

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

EPSS: 0.33%