logo

CVE-2026-20805: Microsoft Fixes Actively Exploited Windows Desktop Manager Zero-Day

ID: 040d6645-d974-5428-afb9-324552ad1d80

STIX ID: report--040d6645-d974-5428-afb9-324552ad1d80

Feed Name: SOC Prime Blog

Threat Score
70/100

Date Published: 2026-01-15

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Microsoft’s January 2026 Patch Tuesday fixes 112–114 vulnerabilities across Windows and related products and highlights an actively exploited zero-day, CVE-2026-20805, an information-disclosure flaw in the Windows Desktop Window Manager that can expose protected memory to a locally authenticated attacker; CISA added this CVE to its Known Exploited Vulnerabilities catalog and federal agencies are required to patch by February 3, 2026. The report urges immediate remediation and points to detection intelligence resources for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.