CVE-2026-20822General(microsoft / windows_10_1607)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2016windows_server_2019windows_server_2022

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 102-0202-03
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-031
Patch1
Full discourse2 posts
  • Kaan@wkaandemir
    General

    Güvenlik Rehberi'ne taze güncelleme! 🔥 Artık repo OWASP Top 10 2025'le sınırlı değil; her ay yeni açıklar, tehditler ve pratik çözümlerle genişleyecek. Bu ay: OWASP notlarını detaylandırdım + şu açıkları ekledim: • Windows DWM info leak (CVE-2026-20805) • Windows Graphics EoP (CVE-2026-20822) • Linux mlx5e UAF (CVE-2026-23000) • Cisco CM RCE (CVE-2026-20045) • Apache Tika XXE (CVE-2025-66516) Yeni dokümanlar, checklist'ler ve önerilerle daha güçlü.

    Post summary

    The post announces the addition of several CVEs to the security guide, providing brief type classifications but no PoC, exploit code, patch info, or active exploitation details.

    11061500
    1.8K followersView on X
  • CVEDatabase.com@cvedatabase
    Patch

    RCE + EoP in Microsoft Stack 💥 Patch update includes CVE-2026-20944 (Word RCE) and CVE-2026-20822 (Graphics EoP) — both critical for enterprise environments. See details & CVSS scores: 👉 https://cvedatabase.com/cve/CVE-2026-20944 👉 https://cvedatabase.com/cve/CVE-2026-20822 #InfoSec #VulnerabilityManagement

    Post summary

    A patch update addresses two critical Microsoft CVEs—CVE-2026-20944 (Word RCE) and CVE-2026-20822 (Graphics EoP)—with CVSS scores linked for reference.

    0000058
    1 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more