CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

windows_11_26h1

39 known vulnerabilities · sorted by CVSS score

CVE-2026-24283
HIGH8.8

Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

microsoft / windows_11_24h2+7
Local
Published Mar 10, 2026
Page 1 of 2
CVE-2026-25177
HIGH8.8

Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

microsoft / windows_10_1607+24
Network
Published Mar 10, 2026
CVE-2026-23669
HIGH8.8

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

microsoft / windows_10_1607+24
Network
Published Mar 10, 2026
CVE-2026-25188
HIGH8.8

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

microsoft / windows_10_1607+24
Adjacent
Published Mar 10, 2026
CVE-2026-25173
HIGH8.0

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

microsoft / windows_10_1607+24
Network
Published Mar 10, 2026
CVE-2026-24289
HIGH7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-24292
HIGH7.8

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1809+19
Local
Published Mar 10, 2026
CVE-2026-24291
HIGH7.8

Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-26132
HIGH7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_21h2+16
Local
Published Mar 10, 2026
CVE-2026-25176
HIGH7.8

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-24294
HIGH7.8

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-24293
HIGH7.8

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_21h2+16
Local
Published Mar 10, 2026
CVE-2026-24290
HIGH7.8

Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1809+19
Local
Published Mar 10, 2026
CVE-2026-25190
HIGH7.8

Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-25166
HIGH7.8

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

microsoft / windows_10_1607+21
Local
Published Mar 10, 2026
CVE-2026-24287
HIGH7.8

External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1809+19
Local
Published Mar 10, 2026
CVE-2026-23672
HIGH7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-26128
HIGH7.8

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-25174
HIGH7.8

Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026
CVE-2026-25187
HIGH7.8

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

microsoft / windows_10_1607+24
Local
Published Mar 10, 2026