U.S. CISA adds a flaw in Microsoft Windows to its Known Exploited Vulnerabilities catalog
ID: 13f31fcc-7102-54d6-9f32-c22ac34ad3fc
STIX ID: report--13f31fcc-7102-54d6-9f32-c22ac34ad3fc
Feed Name: Security Affairs
Threat Score
CISA added CVE-2026-20805 — a Microsoft Windows Desktop Window Manager information-leak vulnerability — to its Known Exploited Vulnerabilities catalog after Microsoft’s January 2026 Patch Tuesday; the flaw (reported with a high CVSS score) is actively exploited in the wild, can leak user-mode memory useful for bypassing protections, and federal agencies were ordered to remediate by February 3, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
