Microsoft
Windows 11
Microsoft desktop operating system for PCs.
2026-07 B (22631.7376)
- Release date
- July 14, 2026
- Security status
- 25 high-severity CVEs tracked in the last 90 days. Current version not affected.
Source
Vendor Release Information
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 2026-07 B (22631.7376) | 2026-07-14 | Release Notes |
| 2026-06 B (22631.7219) | 2026-06-09 | Release Notes |
| 2026-05 B (22631.7079) | 2026-05-12 | Release Notes |
| 2026-04 B (22631.6936) | 2026-04-14 | Release Notes |
| 2026-03 B (22631.6783) | 2026-03-10 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-58629 | HIGH (7.0) | 2026-07-14 | Current versionnot affected | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-58640 | HIGH (7.8) | 2026-07-14 | Current versionnot affected | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Affected versions
|
| CVE-2026-58601 | HIGH (7.8) | 2026-07-14 | Current versionnot affected | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-49172 | CRITICAL (9.8) | 2026-07-14 | Current versionnot affected | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-48572 | HIGH (7.0) | 2026-07-14 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-48571 | HIGH (7.0) | 2026-07-14 | Current versionnot affected | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-44800 | HIGH (7.8) | 2026-07-14 | Current versionnot affected | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-42982 | HIGH (7.8) | 2026-07-14 | Current versionnot affected | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-40378 | HIGH (7.5) | 2026-07-14 | Current versionnot affected | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. Affected versions
|
| CVE-2026-49160 | HIGH (7.5) | 2026-06-09 | Current versionnot affected | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. Affected versions
|
| CVE-2026-48583 | HIGH (7.8) | 2026-06-09 | Current versionnot affected | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-48578 | HIGH (7.9) | 2026-06-09 | Current versionnot affected | Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-48576 | HIGH (7.9) | 2026-06-09 | Current versionnot affected | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Affected versions
|
| CVE-2026-48575 | HIGH (7.9) | 2026-06-09 | Current versionnot affected | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Affected versions
|
| CVE-2026-48574 | HIGH (7.8) | 2026-06-09 | Current versionnot affected | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. Affected versions
|
| CVE-2026-48573 | HIGH (7.9) | 2026-06-09 | Current versionnot affected | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Affected versions
|
| CVE-2026-48570 | HIGH (7.9) | 2026-06-09 | Current versionnot affected | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Affected versions
|
| CVE-2026-48568 | HIGH (7.9) | 2026-06-09 | Current versionnot affected | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Affected versions
|
| CVE-2026-48563 | HIGH (7.5) | 2026-06-09 | Current versionnot affected | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-47656 | HIGH (7.9) | 2026-06-09 | Current versionnot affected | Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. Affected versions
|
| CVE-2026-47653 | HIGH (8.8) | 2026-06-09 | Current versionnot affected | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-47652 | HIGH (8.2) | 2026-06-09 | Current versionnot affected | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. Affected versions
|
| CVE-2026-47648 | HIGH (7.0) | 2026-06-09 | Current versionnot affected | Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. Affected versions
|
| CVE-2026-47291 | CRITICAL (9.8) | 2026-06-09 | Current versionnot affected | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. Affected versions
|
| CVE-2026-47289 | HIGH (8.8) | 2026-06-09 | Current versionnot affected | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Affected versions
|