📦

windows_11_26h1

Vendor: microsoft

Actively Exploited 1 CISA KEV List
PoC / Exploits 14 Code Available
Total RCEs 16 Remote Access
Total CVEs 685 Total Indexed
Avg. EPSS 0.65% Exploit Prob.
Latest CVE CVE-2026-50507 Jun 09

Security Vulnerability Index

Page 23 / 69
7.0 CVSS

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

EPSS: 0.32%
7.8 CVSS

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

EPSS: 0.26%
7.0 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

EPSS: 0.16%
5.5 CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

EPSS: 0.49%
5.5 CVSS

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

EPSS: 0.38%
7.0 CVSS

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.

EPSS: 0.19%
7.8 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

EPSS: 0.19%
7.0 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

EPSS: 0.18%
6.5 CVSS

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.

EPSS: 0.36%
7.8 CVSS

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

EPSS: 0.23%