CVE-2026-20805Medium· 5.5▾ Midnight⚠ Exploited in the wild0dayPoC availableExposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 30.3 · likelihood 1 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Feb 3, 2026
Last analysed / modified upstream
5.0%
6 GitHub repos
5.0% → 5.2%
Added to the CISA catalog on Jan 13, 2026. Federal remediation due Feb 3, 2026. View catalog ↗
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
windows_10_1607 < 10.0.14393.8783windows_10_1809 < 10.0.17763.8276windows_10_21h2 < 10.0.19044.6809windows_10_22h2 < 10.0.19045.6809windows_11_23h2 < 10.0.22631.6491windows_11_24h2 < 10.0.26100.7623windows_11_25h2 < 10.0.26200.7623windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.8783windows_server_2019 < 10.0.17763.8276windows_server_2022 < 10.0.20348.4648windows_server_2022_23h2 < 10.0.25398.2092windows_server_2025 < 10.0.26100.7623Upgrade past the affected range:
windows_10_1607 10.0.14393.8783windows_10_1809 10.0.17763.8276windows_10_21h2 10.0.19044.6809windows_10_22h2 10.0.19045.6809windows_11_23h2 10.0.22631.6491windows_11_24h2 10.0.26100.7623windows_11_25h2 10.0.26200.7623windows_server_2016 10.0.14393.8783windows_server_2019 10.0.17763.8276windows_server_2022 10.0.20348.4648windows_server_2022_23h2 10.0.25398.2092windows_server_2025 10.0.26100.7623Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-33824Critical· 9.8Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-32202Medium· 4.3Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2018-8174High· 7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…
CVE-2026-20847Medium· 6.5Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
CVE-2026-20827Medium· 5.5Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.