
Deserialization strikes again for a WDAC bypass in imgmgr.exe (cc Dr. Tim Baker at dotSec) https://www.dotsec.com/insecure-deserialisation-app-control-bypass/ Fixed by Microsoft as a "remote code execution" vulnerability (CVE-2026-25166) https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-25166
Post summary
Microsoft has released a patch for CVE-2026-25166, a deserialization-based RCE in imgmgr.exe; no proof‑of‑concept or active exploitation is reported.

