Microsoft Windows 11 23h2
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Windows 11 23h2.
By the Year
In 2026 there have been 1198 vulnerabilities in Microsoft Windows 11 23h2 with an average score of 7.3 out of ten. Last year, in 2025 Windows 11 23h2 had 663 security vulnerabilities published. That is, 535 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.08.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1198 | 7.29 |
| 2025 | 663 | 7.21 |
| 2024 | 541 | 7.34 |
| 2023 | 49 | 7.70 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 1 | 7.00 |
It may take a day or so for new Windows 11 23h2 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Windows 11 23h2 Security Vulnerabilities
Sep 2026: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-83498
7.8 - High
- September 08, 2026
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
Untrusted Pointer Dereference
Sep 2026: Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-83501
5.5 - Medium
- September 08, 2026
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Sep 2026: Microsoft Graphics Component Remote Code Execution Vulnerability
CVE-2026-84000
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
Heap-based Buffer Overflow
Sep 2026: Windows Message Queuing Remote Code Execution Vulnerability
CVE-2026-83997
8.1 - High
- September 08, 2026
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-83995
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-83992
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-83990
7.8 - High
- September 08, 2026
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Stack Overflow
Sep 2026: Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability
CVE-2026-83989
7.5 - High
- September 08, 2026
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
Out-of-bounds Read
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83985
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83987
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83983
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83982
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83980
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83978
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83981
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83977
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-70145
5.5 - Medium
- September 08, 2026
Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83973
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83968
7.8 - High
- September 08, 2026
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83972
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83970
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83954
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83967
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83971
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows iSCSI Remote Code Execution Vulnerability
CVE-2026-69598
8.8 - High
- September 08, 2026
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
Incorrect Calculation of Buffer Size
Sep 2026: Windows WebClient Service Elevation of Privilege Vulnerability
CVE-2026-72965
7.8 - High
- September 08, 2026
Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Storage Port Driver Information Disclosure Vulnerability
CVE-2026-69381
4.6 - Medium
- September 08, 2026
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds Read
Sep 2026: Windows Update Stack Elevation of Privilege Vulnerability
CVE-2026-81963
7.8 - High
- September 08, 2026
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
insecure temporary file
Sep 2026: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-83940
7 - High
- September 08, 2026
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-81955
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Hello Elevation of Privilege Vulnerability
CVE-2026-81354
8.2 - High
- September 08, 2026
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-80096
8.8 - High
- September 08, 2026
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Out-of-bounds Read
Sep 2026: Windows Storage Information Disclosure Vulnerability
CVE-2026-78516
4.3 - Medium
- September 08, 2026
Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.
Buffer Over-read
Sep 2026: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-78454
5.5 - Medium
- September 08, 2026
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Sep 2026: Xbox Information Disclosure Vulnerability
CVE-2026-78455
4.3 - Medium
- September 08, 2026
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds Read
Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78452
4.6 - Medium
- September 08, 2026
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.
Out-of-bounds Read
Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78453
6.5 - Medium
- September 08, 2026
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.
Integer underflow
Sep 2026: Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
CVE-2026-78451
6.8 - Medium
- September 08, 2026
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.
Untrusted Pointer Dereference
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78448
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78447
7.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
Heap-based Buffer Overflow
Sep 2026: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78449
8.1 - High
- September 08, 2026
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Windows Distributed File System (DFS) Denial of Service Vulnerability
CVE-2026-78446
5.3 - Medium
- September 08, 2026
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.
Dangling pointer
Sep 2026: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-77905
7 - High
- September 08, 2026
Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: Graphics Kernel Remote Code Execution Vulnerability
CVE-2026-73017
7.5 - High
- September 08, 2026
Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.
Heap-based Buffer Overflow
Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73016
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73013
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73023
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-73009
9.8 - Critical
- September 08, 2026
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Dangling pointer
Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73006
8.8 - High
- September 08, 2026
Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Stack Overflow
Sep 2026: Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-73012
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
Heap-based Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Windows 11 23h2 or by Microsoft? Click the Watch button to subscribe.