{"schema_version":1,"title":"Microsoft Windows 11 23h2 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 40 vulnerabilities in Microsoft Windows 11 23h2: 0 in the last 7 days and 14 in the last 90 days, 7 of them critical and 6 exploited in the wild. The most recent, CVE-2026-68820, was published on 11 August 2026.","url":"https://junglewise.ai/threats/technologies/windows-11-23h2","json_url":"https://junglewise.ai/threats/technologies/windows-11-23h2.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/windows-11-23h2","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":21,"all_time":40,"critical":7,"exploited":6,"last_7_days":0,"last_30_days":0,"last_90_days":14,"last_365_days":35},"latest":[{"cve":"CVE-2026-68820","cvss":7,"epss":0.0033,"slug":"cve-2026-68820-microsoft-windows-ancillary-function-driver-for-winsock-use-after","title":"Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","severity":"critical","exploited":true,"published_at":"2026-08-11T17:19:06.357+00:00","url":"https://junglewise.ai/threats/cve-2026-68820-microsoft-windows-ancillary-function-driver-for-winsock-use-after"},{"cve":"CVE-2026-56173","cvss":7,"slug":"cve-2026-56173-microsoft-windows-webview-use-after-free-privilege-escalation","title":"Microsoft Windows WebView use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T18:18:23.31+00:00","url":"https://junglewise.ai/threats/cve-2026-56173-microsoft-windows-webview-use-after-free-privilege-escalation"},{"cve":"CVE-2026-50471","cvss":7.8,"slug":"cve-2026-50471-microsoft-windows-ntfs-heap-overflow","title":"Microsoft Windows NTFS heap overflow","severity":"high","exploited":false,"published_at":"2026-07-14T18:17:52.677+00:00","url":"https://junglewise.ai/threats/cve-2026-50471-microsoft-windows-ntfs-heap-overflow"},{"cve":"CVE-2026-58601","cvss":7.8,"slug":"cve-2026-58601-microsoft-windows-privilege-escalation-in-vhd-miniport-driver","title":"Microsoft Windows privilege escalation in VHD Miniport Driver","severity":"high","exploited":false,"published_at":"2026-07-14T17:17:12.657+00:00","url":"https://junglewise.ai/threats/cve-2026-58601-microsoft-windows-privilege-escalation-in-vhd-miniport-driver"},{"cve":"CVE-2026-49172","cvss":9.8,"slug":"cve-2026-49172-microsoft-windows-ftp-service-heap-overflow-remote-code-execution","title":"Microsoft Windows FTP Service heap overflow remote code execution","severity":"critical","exploited":false,"published_at":"2026-07-14T17:16:52.233+00:00","url":"https://junglewise.ai/threats/cve-2026-49172-microsoft-windows-ftp-service-heap-overflow-remote-code-execution"},{"cve":"CVE-2026-48572","cvss":7,"slug":"cve-2026-48572-microsoft-windows-app-installer-race-condition-privilege","title":"Microsoft Windows App Installer race condition privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T17:16:50.257+00:00","url":"https://junglewise.ai/threats/cve-2026-48572-microsoft-windows-app-installer-race-condition-privilege"},{"cve":"CVE-2026-48571","cvss":7,"slug":"cve-2026-48571-microsoft-windows-app-installer-use-after-free-privilege","title":"Microsoft Windows App Installer use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T17:16:50.023+00:00","url":"https://junglewise.ai/threats/cve-2026-48571-microsoft-windows-app-installer-use-after-free-privilege"},{"cve":"CVE-2026-44800","cvss":7.8,"slug":"cve-2026-44800-microsoft-windows-push-notifications-privilege-escalation","title":"Microsoft Windows Push Notifications privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T17:16:48.667+00:00","url":"https://junglewise.ai/threats/cve-2026-44800-microsoft-windows-push-notifications-privilege-escalation"},{"cve":"CVE-2026-42982","cvss":7.8,"slug":"cve-2026-42982-microsoft-windows-secure-kernel-mode-privilege-escalation","title":"Microsoft Windows Secure Kernel Mode privilege escalation","severity":"high","exploited":false,"published_at":"2026-07-14T17:16:48.33+00:00","url":"https://junglewise.ai/threats/cve-2026-42982-microsoft-windows-secure-kernel-mode-privilege-escalation"},{"cve":"CVE-2026-40378","cvss":7.5,"slug":"cve-2026-40378-microsoft-windows-lsass-denial-of-service-via-excessive-memory","title":"Microsoft Windows LSASS denial of service via excessive memory allocation","severity":"high","exploited":false,"published_at":"2026-07-14T17:16:47.257+00:00","url":"https://junglewise.ai/threats/cve-2026-40378-microsoft-windows-lsass-denial-of-service-via-excessive-memory"},{"cve":"CVE-2026-34348","cvss":6.5,"slug":"cve-2026-34348-microsoft-windows-event-logging-service-protection-mechanism","title":"Microsoft Windows Event Logging Service protection mechanism failure","severity":"medium","exploited":false,"published_at":"2026-07-14T17:16:46.56+00:00","url":"https://junglewise.ai/threats/cve-2026-34348-microsoft-windows-event-logging-service-protection-mechanism"},{"cve":"CVE-2026-34346","cvss":5.5,"slug":"cve-2026-34346-microsoft-windows-ancillary-function-driver-for-winsock","title":"Microsoft Windows Ancillary Function Driver for WinSock Information Disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T17:16:46.373+00:00","url":"https://junglewise.ai/threats/cve-2026-34346-microsoft-windows-ancillary-function-driver-for-winsock"},{"cve":"CVE-2026-34328","cvss":5.5,"slug":"cve-2026-34328-microsoft-windows-audio-service-information-disclosure","title":"Microsoft Windows Audio Service information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T17:16:46.22+00:00","url":"https://junglewise.ai/threats/cve-2026-34328-microsoft-windows-audio-service-information-disclosure"},{"cve":"CVE-2026-33842","cvss":5.5,"slug":"cve-2026-33842-microsoft-windows-file-explorer-information-disclosure","title":"Microsoft Windows File Explorer information disclosure","severity":"medium","exploited":false,"published_at":"2026-07-14T17:16:46.037+00:00","url":"https://junglewise.ai/threats/cve-2026-33842-microsoft-windows-file-explorer-information-disclosure"},{"cve":"CVE-2026-33841","cvss":7.8,"epss":0.0031,"slug":"cve-2026-33841-microsoft-windows-kernel-heap-buffer-overflow-privilege","title":"Microsoft Windows Kernel heap buffer overflow privilege escalation","severity":"high","exploited":false,"published_at":"2026-05-12T18:17:06.297+00:00","url":"https://junglewise.ai/threats/cve-2026-33841-microsoft-windows-kernel-heap-buffer-overflow-privilege"},{"cve":"CVE-2026-32152","cvss":7.8,"epss":0.0006,"slug":"cve-2026-32152-microsoft-windows-desktop-window-manager-use-after-free-privilege","title":"Microsoft Windows Desktop Window Manager use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-04-14T18:17:15.71+00:00","url":"https://junglewise.ai/threats/cve-2026-32152-microsoft-windows-desktop-window-manager-use-after-free-privilege"},{"cve":"CVE-2026-20938","cvss":7.8,"epss":0.0048,"slug":"cve-2026-20938-microsoft-windows-vbs-enclave-untrusted-pointer-dereference","title":"Microsoft Windows VBS Enclave untrusted pointer dereference","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:20.98+00:00","url":"https://junglewise.ai/threats/cve-2026-20938-microsoft-windows-vbs-enclave-untrusted-pointer-dereference"},{"cve":"CVE-2026-20935","cvss":6.2,"epss":0.0041,"slug":"cve-2026-20935-microsoft-windows-vbs-enclave-untrusted-pointer-dereference","title":"Microsoft Windows VBS Enclave untrusted pointer dereference","severity":"medium","exploited":false,"published_at":"2026-01-13T18:16:20.5+00:00","url":"https://junglewise.ai/threats/cve-2026-20935-microsoft-windows-vbs-enclave-untrusted-pointer-dereference"},{"cve":"CVE-2026-20920","cvss":7.8,"epss":0.0048,"slug":"cve-2026-20920-microsoft-windows-win32k-use-after-free-in-icomp","title":"Microsoft Windows Win32K use after free in ICOMP","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:18.303+00:00","url":"https://junglewise.ai/threats/cve-2026-20920-microsoft-windows-win32k-use-after-free-in-icomp"},{"cve":"CVE-2026-20876","cvss":6.7,"epss":0.0051,"slug":"cve-2026-20876-microsoft-windows-vbs-enclave-heap-buffer-overflow","title":"Microsoft Windows VBS Enclave heap buffer overflow","severity":"medium","exploited":false,"published_at":"2026-01-13T18:16:17.65+00:00","url":"https://junglewise.ai/threats/cve-2026-20876-microsoft-windows-vbs-enclave-heap-buffer-overflow"},{"cve":"CVE-2026-20871","cvss":7.8,"epss":0.0399,"slug":"cve-2026-20871-microsoft-desktop-window-manager-use-after-free-privilege","title":"Microsoft Desktop Window Manager use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:16.81+00:00","url":"https://junglewise.ai/threats/cve-2026-20871-microsoft-desktop-window-manager-use-after-free-privilege"},{"cve":"CVE-2026-20867","cvss":7.8,"epss":0.0029,"slug":"cve-2026-20867-microsoft-windows-management-services-race-condition-privilege","title":"Microsoft Windows Management Services race condition privilege escalation","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:16.13+00:00","url":"https://junglewise.ai/threats/cve-2026-20867-microsoft-windows-management-services-race-condition-privilege"},{"cve":"CVE-2026-20863","cvss":7,"epss":0.0038,"slug":"cve-2026-20863-microsoft-windows-win32k-double-free-privilege-escalation-in","title":"Microsoft Windows Win32K double free privilege escalation in ICOMP","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:15.467+00:00","url":"https://junglewise.ai/threats/cve-2026-20863-microsoft-windows-win32k-double-free-privilege-escalation-in"},{"cve":"CVE-2026-20862","cvss":5.5,"epss":0.0061,"slug":"cve-2026-20862-microsoft-windows-management-services-information-disclosure","title":"Microsoft Windows Management Services information disclosure","severity":"medium","exploited":false,"published_at":"2026-01-13T18:16:15.3+00:00","url":"https://junglewise.ai/threats/cve-2026-20862-microsoft-windows-management-services-information-disclosure"},{"cve":"CVE-2026-20861","cvss":7.8,"epss":0.0029,"slug":"cve-2026-20861-microsoft-windows-management-services-privilege-escalation","title":"Microsoft Windows Management Services privilege escalation","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:15.137+00:00","url":"https://junglewise.ai/threats/cve-2026-20861-microsoft-windows-management-services-privilege-escalation"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":13},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":1,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":977,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":168,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"}],"technology":{"hub":true,"name":"Microsoft Windows 11 23h2","slug":"windows-11-23h2","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":["windows-11-version-23h2"],"homepage":"https://www.microsoft.com/windows/windows-11","description":"A specific version of the Windows 11 operating system released in late 2023.","url":"https://junglewise.ai/threats/technologies/windows-11-23h2"},"most_severe":[{"cve":"CVE-2024-21412","cvss":8.1,"slug":"cve-2024-21412-microsoft-windows-internet-shortcut-files-security-feature-bypass","title":"Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2024-02-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-21412-microsoft-windows-internet-shortcut-files-security-feature-bypass"},{"cve":"CVE-2025-30400","cvss":7.8,"slug":"cve-2025-30400-microsoft-windows-dwm-core-library-use-after-free-vulnerability","title":"Microsoft Windows DWM Core Library Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2025-05-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-30400-microsoft-windows-dwm-core-library-use-after-free-vulnerability"},{"cve":"CVE-2025-21335","cvss":7.8,"slug":"cve-2025-21335-microsoft-windows-hyper-v-nt-kernel-integration-vsp-use-after","title":"Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2025-01-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-21335-microsoft-windows-hyper-v-nt-kernel-integration-vsp-use-after"},{"cve":"CVE-2025-21333","cvss":7.8,"slug":"cve-2025-21333-microsoft-windows-hyper-v-nt-kernel-integration-vsp-heap-based","title":"Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2025-01-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-21333-microsoft-windows-hyper-v-nt-kernel-integration-vsp-heap-based"},{"cve":"CVE-2024-38080","cvss":7.8,"slug":"cve-2024-38080-microsoft-windows-hyper-v-privilege-escalation-vulnerability","title":"Microsoft Windows Hyper-V Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2024-07-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38080-microsoft-windows-hyper-v-privilege-escalation-vulnerability"},{"cve":"CVE-2026-68820","cvss":7,"epss":0.0033,"slug":"cve-2026-68820-microsoft-windows-ancillary-function-driver-for-winsock-use-after","title":"Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.","severity":"critical","exploited":true,"published_at":"2026-08-11T17:19:06.357+00:00","url":"https://junglewise.ai/threats/cve-2026-68820-microsoft-windows-ancillary-function-driver-for-winsock-use-after"},{"cve":"CVE-2026-49172","cvss":9.8,"slug":"cve-2026-49172-microsoft-windows-ftp-service-heap-overflow-remote-code-execution","title":"Microsoft Windows FTP Service heap overflow remote code execution","severity":"critical","exploited":false,"published_at":"2026-07-14T17:16:52.233+00:00","url":"https://junglewise.ai/threats/cve-2026-49172-microsoft-windows-ftp-service-heap-overflow-remote-code-execution"},{"cve":"CVE-2026-20871","cvss":7.8,"epss":0.0399,"slug":"cve-2026-20871-microsoft-desktop-window-manager-use-after-free-privilege","title":"Microsoft Desktop Window Manager use after free privilege escalation","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:16.81+00:00","url":"https://junglewise.ai/threats/cve-2026-20871-microsoft-desktop-window-manager-use-after-free-privilege"},{"cve":"CVE-2026-20811","cvss":7.8,"epss":0.0049,"slug":"cve-2026-20811-microsoft-windows-win32k-type-confusion-privilege-escalation","title":"Microsoft Windows Win32K type confusion privilege escalation","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:07.727+00:00","url":"https://junglewise.ai/threats/cve-2026-20811-microsoft-windows-win32k-type-confusion-privilege-escalation"},{"cve":"CVE-2026-20938","cvss":7.8,"epss":0.0048,"slug":"cve-2026-20938-microsoft-windows-vbs-enclave-untrusted-pointer-dereference","title":"Microsoft Windows VBS Enclave untrusted pointer dereference","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:20.98+00:00","url":"https://junglewise.ai/threats/cve-2026-20938-microsoft-windows-vbs-enclave-untrusted-pointer-dereference"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}