LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20805: Microsoft Windows Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 13, 2026
CVSS 5.5 · Medium⚠ Actively exploited (CISA KEV)
5.5
CVSS score
Medium
Severity
Active
CISA KEV
No
Ransomware use
Feb 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20805 to its Known Exploited Vulnerabilities catalog on Jan 13, 2026, with a federal patch deadline of Feb 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Microsoft Windows Desktop Window Manager contains an information disclosure vulnerability tracked as CVE-2026-20805. An authorized local attacker can obtain information that should otherwise remain protected. The issue affects Microsoft Windows systems and can expose sensitive data without requiring elevated privileges beyond standard user access.

How it works

The weakness is classified under CWE-200, information exposure. Desktop Window Manager handles window composition and related graphics operations on Windows. An authorized attacker running code locally can interact with this component in a way that causes it to return data it should not disclose to that process or user context.

Exploitation remains local and does not rely on network access or remote code execution. Specific mechanics of the disclosure must be confirmed against the vendor advisory, as public details are limited to the general class of information exposure in this component.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows installations that include the Desktop Window Manager. Inventory all Windows endpoints and servers through standard asset management or configuration management tools. Focus on systems running recent Windows versions where Desktop Window Manager is active by default.

How to remediate

Apply mitigations per the vendor instructions referenced in the advisory. This is the primary step for addressing the information disclosure in Desktop Window Manager.

If you can't patch immediately

Apply mitigations per vendor instructions while planning the update. Follow applicable BOD 22-01 guidance for any cloud services involved. If mitigations cannot be implemented, discontinue use of the affected product or component until a fix is available.

If your data may have been exposed

Information disclosure vulnerabilities can contribute to data exposure when exploited. Organizations should review access logs on potentially affected systems and consider running a free exposure scan of their email addresses against known breach data to check for related incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-200
CVSS base score5.5 (Medium)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
PublishedJan 13, 2026
Added to CISA KEVJan 13, 2026
Federal patch deadlineFeb 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities