Microsoft Windows Information Disclosure Vulnerability

Release Date: 13th of January 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-20805 is a security vulnerability in Microsoft Windows’ Desktop Window Manager (DWM) where an attacker with local access can disclose sensitive information (memory data) that should be protected. This is classified as an information disclosure flaw, and it was confirmed to be actively exploited in the wild before a patch was issued.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2026-20805