Windows 11 25h2
Vendor:
First CVE: Jun 5, 2025 · Active for 1 year
996
Total CVEs
More Total CVEs than 100% of tracked products
498.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
1.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows 11 25h2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2025
13 months ago
Most Recent CVE
Jul 16, 2026
12 days ago
CVE Severity & Scoring
Windows 11 25h2996 CVEs
22%
75%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local771 (77.4%)
Network175 (17.6%)
Unknown0 (0.0%)
Physical35 (3.5%)
Adjacent Network15 (1.5%)
Attack Complexity
Low739 (74.2%)
High257 (25.8%)
Unknown0 (0.0%)
User Interaction
None890 (89.4%)
Unknown0 (0.0%)
Required106 (10.6%)
Privileges Required
Low739 (74.2%)
High22 (2.2%)
None235 (23.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (996 CVEs).
996 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32202MEDIUM Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | Apr 14, 2026 | 4.3 | 93 | YES | YES |
CVE-2026-21510HIGH Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 | 8.8 | 84 | YES | NO |
CVE-2026-21513HIGH Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 | 8.8 | 81 | YES | NO |
CVE-2025-62215HIGH Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | Nov 11, 2025 | 7.0 | 80 | YES | YES |
CVE-2026-33824CRITICAL Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | Apr 14, 2026 | 9.8 | 74 | NO | NO |
CVE-2026-21533HIGH Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 | 7.8 | 73 | YES | NO |
CVE-2025-60710HIGH Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | Nov 11, 2025 | 7.8 | 73 | YES | NO |
CVE-2025-24990HIGH Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming r | Oct 14, 2025 | 7.8 | 72 | YES | NO |
CVE-2025-59230HIGH Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | Oct 14, 2025 | 7.8 | 71 | YES | NO |
CVE-2026-21519HIGH Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | Feb 10, 2026 | 7.8 | 70 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (996 CVEs).
CISA KEV
13 CVEs
1.3% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
0.7% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (996 CVEs).
Media Mentions
Signals from CVEs in this product scope (996 CVEs).
Top CNAs Publishing CVEs For Windows 11 25h2
Top CWEs
Versions
No cataloged versions.