CVE-2026-20804Patch(microsoft / windows_10_1607)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 2 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2016windows_server_2019windows_server_2022

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-13: 102-1302-14
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-132
Patch2
2026-02-141
Patch1
Full discourse3 posts
  • WinBuzzer@WBuzzer
    Patch

    https://winbuzzer.com/2026/02/14/microsoft-blocks-credential-autofill-windows-hello-flaw-cve-2026-20804-xcxwbn/ Microsoft Blocks Credential Autofill to Fix Windows Hello Flaw #Microsoft #Windows11 #February2026PatchTuesday #Cybersecurity #Authentication #WindowsHello #Biometrics #RemoteDesktop https://t.co/72pprJO3Oq

    Post summary

    Microsoft released a mitigation that blocks credential autofill to address a Windows Hello flaw (CVE‑2026‑20804); no exploit code, PoC, or active exploitation details are disclosed.

    0000086
    37.4K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔒 Windows sign-in now blocks untrusted autofill input, closing a Windows Hello privilege gap. Your password manager stays in its lane. #WindowsForum #PatchTuesday #WindowsSecurity https://windowsforum.com/threads/windows-credential-autofill-hardened-trusted-local-input-only-cve-2026-20804.401202/?utm_source=rss&utm_medium=rss

    Post summary

    The tweet announces a Windows update that blocks untrusted autofill input, addressing a Windows Hello privilege gap as part of Patch Tuesday.

    0000032
    992 followersView on X
  • WindowsForum@windowsforum
    Patch

    🔒 Windows just nixed autofill for sign-in dialogs; only trusted, locally sourced input gets through. Bye-bye credential auto-fill. #WindowsForum #PatchTuesday https://windowsforum.com/threads/windows-credential-autofill-blocked-by-jan-2026-security-update-cve-2026-20804.401181/?utm_source=rss&utm_medium=rss

    Post summary

    Microsoft released a Patch Tuesday security update that disables credential autofill for sign‑in dialogs to mitigate CVE‑2026‑20804.

    0000081
    992 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more