EXPOSURES › CVE-2026-20805
CVE-2026-20805
HIGH ⌖ ON CISA KEV · EXPLOITEDAuthorized attackers can disclose information on Windows systems due to an unpatched vulnerability.
An unpatched information disclosure vulnerability in Microsoft Windows Desktop Windows Manager allows authorized attackers to access sensitive information locally. This poses a high risk to DIB organizations as it compromises the integrity and confidentiality of data.
Shame score — Authorized attackers can disclose sensitive information locally, leading to potential data breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |