CVE-2026-20847Medium· 6.5▾ SunlitExposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
1.3% → 1.4%
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
windows_10_1607 < 10.0.14393.8783windows_10_1809 < 10.0.17763.8276windows_10_21h2 < 10.0.19044.6809windows_10_22h2 < 10.0.19045.6809windows_11_23h2 < 10.0.22631.6491windows_11_24h2 < 10.0.26100.7623windows_11_25h2 < 10.0.26200.7623windows_server_2008 = r2windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.8783windows_server_2019 < 10.0.17763.8276windows_server_2022 < 10.0.20348.4648windows_server_2022_23h2 < 10.0.25398.2092windows_server_2025 < 10.0.26100.32230Upgrade past the affected range:
windows_10_1607 10.0.14393.8783windows_10_1809 10.0.17763.8276windows_10_21h2 10.0.19044.6809windows_10_22h2 10.0.19045.6809windows_11_23h2 10.0.22631.6491windows_11_24h2 10.0.26100.7623windows_11_25h2 10.0.26200.7623windows_server_2016 10.0.14393.8783windows_server_2019 10.0.17763.8276windows_server_2022 10.0.20348.4648windows_server_2022_23h2 10.0.25398.2092windows_server_2025 10.0.26100.32230Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20827Medium· 5.5Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
CVE-2026-20823Medium· 5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-20821Medium· 6.2Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.
CVE-2026-20805Medium· 5.5Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVE-2026-41087Medium· 5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-33842Medium· 5.5Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.