📦

windows_11_26h1

Vendor: microsoft

Actively Exploited 1 CISA KEV List
PoC / Exploits 14 Code Available
Total RCEs 16 Remote Access
Total CVEs 685 Total Indexed
Avg. EPSS 0.65% Exploit Prob.
Latest CVE CVE-2026-50507 Jun 09

Security Vulnerability Index

Page 22 / 69
5.5 CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

EPSS: 0.42%
5.5 CVSS

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

EPSS: 0.34%
7.8 CVSS

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

EPSS: 0.26%
7.8 CVSS

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

EPSS: 0.32%
7.8 CVSS

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

EPSS: 0.26%
7.0 CVSS

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

EPSS: 0.27%
7.8 CVSS

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

EPSS: 0.26%
7.0 CVSS

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

EPSS: 0.35%
6.2 CVSS

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

EPSS: 0.29%
7.5 CVSS

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

EPSS: 1.06%