📦

windows_11_26h1

Vendor: microsoft

Actively Exploited 1 CISA KEV List
PoC / Exploits 14 Code Available
Total RCEs 16 Remote Access
Total CVEs 685 Total Indexed
Avg. EPSS 0.65% Exploit Prob.
Latest CVE CVE-2026-50507 Jun 09

Security Vulnerability Index

Page 19 / 69
5.5 CVSS

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

EPSS: 0.31%
4.3 CVSS
CVE-2026-32202
Exploit Found

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

EPSS: 19.98%
7.0 CVSS

Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

EPSS: 0.24%
7.8 CVSS

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.

EPSS: 0.62%
5.5 CVSS

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

EPSS: 0.36%
7.8 CVSS

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

EPSS: 0.20%
7.8 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

EPSS: 0.16%
7.8 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

EPSS: 0.16%
8.4 CVSS

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.

EPSS: 1.99%
7.8 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

EPSS: 0.20%