Microsoft Windows

892 known vulnerabilities in Microsoft Windows, 36 critical, 177 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-85880 CVSS 7.8 high · actively exploited Microsoft Windows Heap-Based Buffer Overflow Vulnerability
  • CVE-2026-81963 CVSS 7.8 high · actively exploited Microsoft Windows Link Following Vulnerability
  • CVE-2026-68820 CVSS 7.0 high · actively exploited Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
  • CVE-2026-56155 CVSS 7.8 high · actively exploited Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
  • CVE-2026-33824 CVSS 9.8 critical · actively exploited Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
  • CVE-2026-32202 CVSS 4.3 medium · actively exploited Microsoft Windows Protection Mechanism Failure Vulnerability
  • CVE-2026-21533 CVSS 7.8 high · actively exploited Microsoft Windows Improper Privilege Management Vulnerability
  • CVE-2026-21525 CVSS 6.2 medium · actively exploited Microsoft Windows NULL Pointer Dereference Vulnerability
  • CVE-2026-21519 CVSS 7.8 high · actively exploited Microsoft Windows Type Confusion Vulnerability
  • CVE-2026-21513 CVSS 8.8 high · actively exploited Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Latest vulnerabilities

  • CVE-2026-85921 CVSS 8.2 high Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
  • CVE-2026-85880 CVSS 7.8 high · actively exploited Microsoft Windows Heap-Based Buffer Overflow Vulnerability
  • CVE-2026-85877 CVSS 8.8 high Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
  • CVE-2026-85360 CVSS 7.0 high Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
  • CVE-2026-84001 CVSS 7.5 high Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
  • CVE-2026-84000 CVSS 7.8 high Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
  • CVE-2026-83999 CVSS 7.0 high Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an…
  • CVE-2026-83998 CVSS 8.8 high Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
  • CVE-2026-83997 CVSS 8.1 high Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
  • CVE-2026-83996 CVSS 8.8 high Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83995 CVSS 7.8 high Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83992 CVSS 8.8 high Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
  • CVE-2026-83991 CVSS 5.5 medium Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering…
  • CVE-2026-83990 CVSS 7.8 high Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83989 CVSS 7.5 high Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
  • CVE-2026-83988 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83987 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83986 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83985 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83983 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83982 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83981 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83980 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83979 CVSS 7.8 high Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83978 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83977 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83976 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83975 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83974 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
  • CVE-2026-83973 CVSS 7.8 high Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.