Windows 11
4,136 CVEs tracked. 106 of them are in CISA KEV.
This hub aggregates every CVE we track for Windows 11, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Windows 11 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 67 |
| 2024-11 | 34 |
| 2024-12 | 48 |
| 2025-01 | 126 |
| 2025-02 | 35 |
| 2025-03 | 36 |
| 2025-04 | 67 |
| 2025-05 | 39 |
| 2025-06 | 40 |
| 2025-07 | 86 |
| 2025-08 | 58 |
| 2025-09 | 54 |
| 2025-10 | 121 |
| 2025-11 | 38 |
| 2025-12 | 37 |
| 2026-01 | 87 |
| 2026-02 | 28 |
| 2026-03 | 44 |
| 2026-04 | 123 |
| 2026-05 | 62 |
| 2026-06 | 114 |
| 2026-07 | 384 |
| 2026-08 | 203 |
| 2026-09 | 635 |
Severity
How the 4,136 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical101
- High2,975
- Medium1,045
- Low14
Latest CVEs
The 15 most recently published vulnerabilities affecting Windows 11.
- CVE-2026-85921Windows Secure Kernel Mode Elevation of Privilege Vulnerability8.2
- CVE-2026-83498Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability7.8
- CVE-2026-83501Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability5.5
- CVE-2026-84000Microsoft Graphics Component Remote Code Execution Vulnerability7.8
- CVE-2026-83997Windows Message Queuing Remote Code Execution Vulnerability8.1
- CVE-2026-83995Windows NTFS Elevation of Privilege Vulnerability7.8
- CVE-2026-83992Windows Imaging Component Remote Code Execution Vulnerability8.8
- CVE-2026-83989Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability7.5
- CVE-2026-83990Microsoft Graphics Component Elevation of Privilege Vulnerability7.8
- CVE-2026-83985Windows Biometric Service Elevation of Privilege Vulnerability7.8
- CVE-2026-83983Windows Biometric Service Elevation of Privilege Vulnerability7.8
- CVE-2026-83980Windows Biometric Service Elevation of Privilege Vulnerability7.8
- CVE-2026-83987Windows Biometric Service Elevation of Privilege Vulnerability7.8
- CVE-2026-83982Windows Biometric Service Elevation of Privilege Vulnerability7.8
- CVE-2026-83978Windows Biometric Service Elevation of Privilege Vulnerability7.8
Product grouping is registry-driven, with AI assist and human review. How it works