Windows 11 23h2 Microsoft Windows 11 23h2

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Windows 11 23h2.

By the Year

In 2026 there have been 1198 vulnerabilities in Microsoft Windows 11 23h2 with an average score of 7.3 out of ten. Last year, in 2025 Windows 11 23h2 had 663 security vulnerabilities published. That is, 535 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.08.




Year Vulnerabilities Average Score
2026 1198 7.29
2025 663 7.21
2024 541 7.34
2023 49 7.70
2022 0 0.00
2021 0 0.00
2020 1 7.00

It may take a day or so for new Windows 11 23h2 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Windows 11 23h2 Security Vulnerabilities

Sep 2026: Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-83498 7.8 - High - September 08, 2026

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Untrusted Pointer Dereference

Sep 2026: Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-83501 5.5 - Medium - September 08, 2026

Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Microsoft Graphics Component Remote Code Execution Vulnerability
CVE-2026-84000 7.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Windows Message Queuing Remote Code Execution Vulnerability
CVE-2026-83997 8.1 - High - September 08, 2026

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-83995 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-83992 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-83990 7.8 - High - September 08, 2026

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Stack Overflow

Sep 2026: Windows Services for NFS ONCRPC XDR Driver Denial of Service Vulnerability
CVE-2026-83989 7.5 - High - September 08, 2026

Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.

Out-of-bounds Read

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83985 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83987 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83983 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83982 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83980 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83978 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83981 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83977 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft Windows Search Component Information Disclosure Vulnerability
CVE-2026-70145 5.5 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83973 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83968 7.8 - High - September 08, 2026

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83972 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83970 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83954 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83967 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-83971 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows iSCSI Remote Code Execution Vulnerability
CVE-2026-69598 8.8 - High - September 08, 2026

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

Incorrect Calculation of Buffer Size

Sep 2026: Windows WebClient Service Elevation of Privilege Vulnerability
CVE-2026-72965 7.8 - High - September 08, 2026

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Windows Storage Port Driver Information Disclosure Vulnerability
CVE-2026-69381 4.6 - Medium - September 08, 2026

Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds Read

Sep 2026: Windows Update Stack Elevation of Privilege Vulnerability
CVE-2026-81963 7.8 - High - September 08, 2026

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

insecure temporary file

Sep 2026: Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-83940 7 - High - September 08, 2026

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-81955 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows Hello Elevation of Privilege Vulnerability
CVE-2026-81354 8.2 - High - September 08, 2026

Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2026-80096 8.8 - High - September 08, 2026

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

Out-of-bounds Read

Sep 2026: Windows Storage Information Disclosure Vulnerability
CVE-2026-78516 4.3 - Medium - September 08, 2026

Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.

Buffer Over-read

Sep 2026: Windows CD-ROM Driver Information Disclosure Vulnerability
CVE-2026-78454 5.5 - Medium - September 08, 2026

Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.

Out-of-bounds Read

Sep 2026: Xbox Information Disclosure Vulnerability
CVE-2026-78455 4.3 - Medium - September 08, 2026

Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds Read

Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78452 4.6 - Medium - September 08, 2026

Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.

Out-of-bounds Read

Sep 2026: Microsoft Windows SCSI Class System File Information Disclosure Vulnerability
CVE-2026-78453 6.5 - Medium - September 08, 2026

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Integer underflow

Sep 2026: Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
CVE-2026-78451 6.8 - Medium - September 08, 2026

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

Untrusted Pointer Dereference

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78448 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Biometric Service Elevation of Privilege Vulnerability
CVE-2026-78447 7.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based Buffer Overflow

Sep 2026: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-78449 8.1 - High - September 08, 2026

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Windows Distributed File System (DFS) Denial of Service Vulnerability
CVE-2026-78446 5.3 - Medium - September 08, 2026

Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.

Dangling pointer

Sep 2026: Windows Management Instrumentation Elevation of Privilege Vulnerability
CVE-2026-77905 7 - High - September 08, 2026

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: Graphics Kernel Remote Code Execution Vulnerability
CVE-2026-73017 7.5 - High - September 08, 2026

Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73016 8.8 - High - September 08, 2026

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73013 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows Imaging Component Remote Code Execution Vulnerability
CVE-2026-73023 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-73009 9.8 - Critical - September 08, 2026

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Dangling pointer

Sep 2026: DirectWrite Remote Code Execution Vulnerability
CVE-2026-73006 8.8 - High - September 08, 2026

Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Stack Overflow

Sep 2026: Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-73012 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.

Heap-based Buffer Overflow

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Windows 11 23h2 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe