Windows 10 Microsoft Windows 10

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Windows 10.

Recent Microsoft Windows 10 Security Advisories

Advisory Title Published
CVE-2020-0569 CVE-2020-0569 Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. January 1, 2026
CVE-2021-42297 Windows 10 Update Assistant Elevation of Privilege Vulnerability November 16, 2021
CVE-2021-43211 Windows 10 Update Assistant Elevation of Privilege Vulnerability November 16, 2021
CVE-2021-36945 Windows 10 Update Assistant Elevation of Privilege Vulnerability August 10, 2021

By the Year

In 2026 there have been 1553 vulnerabilities in Microsoft Windows 10 with an average score of 7.3 out of ten. Last year, in 2025 Windows 10 had 638 security vulnerabilities published. That is, 915 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.08.




Year Vulnerabilities Average Score
2026 1553 7.30
2025 638 7.22
2024 528 7.35
2023 529 7.50
2022 525 7.42
2021 489 7.36
2020 834 7.32
2019 488 7.30
2018 261 7.23

It may take a day or so for new Windows 10 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Windows 10 Security Vulnerabilities

Sep 2026: Microsoft Graphics Component Remote Code Execution Vulnerability
CVE-2026-84000 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Windows Message Queuing Remote Code Execution Vulnerability
CVE-2026-83997 8.1 - High - September 08, 2026

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-83992 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-83995 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability
CVE-2026-83989 7.5 - High - September 08, 2026

Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.

Out-of-bounds Read

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83985 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83987 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83983 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83982 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83980 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83978 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83981 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83977 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83973 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-70145 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83972 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83968 7.8 - High - September 08, 2026

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83970 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83967 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83954 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83971 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows iSCSI Remote Code Execution Vulnerability
CVE-2026-69598 8.8 - High - September 08, 2026

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

Incorrect Calculation of Buffer Size

Sep 2026: Windows WebClient Service Elevation of Privilege Vulnerability
CVE-2026-72965 7.8 - High - September 08, 2026

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Windows Storage Port Driver Information Disclosure Vulnerability
CVE-2026-69381 4.6 - Medium - September 08, 2026

Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds Read

Sep 2026: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-69530 8.1 - High - September 08, 2026

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-83940 7 - High - September 08, 2026

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-81955 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows Hello Elevation of Privilege Vulnerability
CVE-2026-81354 8.2 - High - September 08, 2026

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-80096 8.8 - High - September 08, 2026

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

Out-of-bounds Read

Sep 2026: Windows Storage Information Disclosure Vulnerability
CVE-2026-78516 4.3 - Medium - September 08, 2026

Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.

Buffer Over-read

Sep 2026: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-78454 5.5 - Medium - September 08, 2026

Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78452 4.6 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds Read

Sep 2026: Xbox Information Disclosure Vulnerability
CVE-2026-78455 4.3 - Medium - September 08, 2026

Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds Read

Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78453 6.5 - Medium - September 08, 2026

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Integer underflow

Sep 2026: Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
CVE-2026-78451 6.8 - Medium - September 08, 2026

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

Untrusted Pointer Dereference

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78448 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78450 8.1 - High - September 08, 2026

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78447 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78449 8.1 - High - September 08, 2026

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Microsoft Failover Cluster Remote Code Execution Vulnerability
CVE-2026-78444 8.1 - High - September 08, 2026

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Untrusted Pointer Dereference

Sep 2026: Windows Distributed File System (DFS) Denial of Service Vulnerability
CVE-2026-78446 5.3 - Medium - September 08, 2026

Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.

Dangling pointer

Sep 2026: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-77905 7 - High - September 08, 2026

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Graphics Kernel Remote Code Execution Vulnerability
CVE-2026-73017 7.5 - High - September 08, 2026

Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Windows iSCSI Security Feature Bypass Vulnerability
CVE-2026-73025 9.8 - Critical - September 08, 2026

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

1390

Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73016 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73013 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft Failover Cluster Remote Code Execution Vulnerability
CVE-2026-73010 9.8 - Critical - September 08, 2026

Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73023 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-73009 9.8 - Critical - September 08, 2026

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73006 8.8 - High - September 08, 2026

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Stack Overflow

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Windows 10 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe