Windows 11 26h1

Vendor:

First CVE: Mar 10, 2026 · Active for under a year

709
Total CVEs
More Total CVEs than 100% of tracked products
709.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows 11 26h1 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2026
4 months ago
Most Recent CVE
Jul 16, 2026
12 days ago

CVE Severity & Scoring

Windows 11 26h1709 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local541 (76.3%)
Network131 (18.5%)
Unknown0 (0.0%)
Physical23 (3.2%)
Adjacent Network14 (2.0%)
Attack Complexity
Low560 (79.0%)
High149 (21.0%)
Unknown0 (0.0%)
User Interaction
None648 (91.4%)
Unknown0 (0.0%)
Required61 (8.6%)
Privileges Required
Low516 (72.8%)
High18 (2.5%)
None175 (24.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (709 CVEs).

709 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Apr 14, 20264.393YESYES
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Apr 14, 20269.874NONO
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
Jun 9, 20267.569NONO
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
Jun 9, 20269.859NONO
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Jun 9, 20269.854NONO
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
May 12, 20269.845NONO
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
Jul 14, 20269.944NONO
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
Jul 14, 20269.844NONO
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Jul 14, 20269.843NONO
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
Jul 14, 20269.843NONO

Exploit Exposure

Signals from CVEs in this product scope (709 CVEs).

CISA KEV
1 CVE
0.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
0.3% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (709 CVEs).

Media Mentions

Signals from CVEs in this product scope (709 CVEs).

Top CNAs Publishing CVEs For Windows 11 26h1

Top CWEs

Versions

No cataloged versions.