Windows 11 26h1
Vendor:
First CVE: Mar 10, 2026 · Active for under a year
709
Total CVEs
More Total CVEs than 100% of tracked products
709.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows 11 26h1 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2026
4 months ago
Most Recent CVE
Jul 16, 2026
12 days ago
CVE Severity & Scoring
Windows 11 26h1709 CVEs
20%
76%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local541 (76.3%)
Network131 (18.5%)
Unknown0 (0.0%)
Physical23 (3.2%)
Adjacent Network14 (2.0%)
Attack Complexity
Low560 (79.0%)
High149 (21.0%)
Unknown0 (0.0%)
User Interaction
None648 (91.4%)
Unknown0 (0.0%)
Required61 (8.6%)
Privileges Required
Low516 (72.8%)
High18 (2.5%)
None175 (24.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (709 CVEs).
709 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32202MEDIUM Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | Apr 14, 2026 | 4.3 | 93 | YES | YES |
CVE-2026-33824CRITICAL Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | Apr 14, 2026 | 9.8 | 74 | NO | NO |
CVE-2026-49160HIGH Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | Jun 9, 2026 | 7.5 | 69 | NO | NO |
CVE-2026-47291CRITICAL Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 | 9.8 | 59 | NO | NO |
CVE-2026-45657CRITICAL Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | Jun 9, 2026 | 9.8 | 54 | NO | NO |
CVE-2026-41096CRITICAL Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | May 12, 2026 | 9.8 | 45 | NO | NO |
CVE-2026-57092CRITICAL Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 9.9 | 44 | NO | NO |
CVE-2026-56190CRITICAL Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 | 9.8 | 44 | NO | NO |
CVE-2026-50694CRITICAL Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-49172CRITICAL Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 | 9.8 | 43 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (709 CVEs).
CISA KEV
1 CVE
0.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
0.3% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (709 CVEs).
Media Mentions
Signals from CVEs in this product scope (709 CVEs).
Top CNAs Publishing CVEs For Windows 11 26h1
Top CWEs
Versions
No cataloged versions.