CVE-2026-20846
vulnerability analysis and mitigation

Overview

CVE-2026-20846 is a buffer over-read vulnerability in Windows GDI+ (Graphics Device Interface Plus) that allows an unauthenticated remote attacker to cause a denial of service (DoS) condition over a network. It was disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday security update release. Affected products span a wide range of Windows client and server versions, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2012/2016/2019/2022/2025, and their variants. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC).

Technical details

The root cause is classified as CWE-126 (Buffer Over-read), occurring within the Windows GDI+ subsystem. An attacker can exploit this flaw by sending specially crafted network requests that trigger the over-read condition in GDI+ processing logic, requiring no authentication, no privileges, and no user interaction. The attack vector is network-based with low complexity, making it straightforward to trigger remotely. No public proof-of-concept or detailed technical write-up has been identified at this time (Microsoft MSRC).

Impact

Successful exploitation results in a denial of service, degrading or completely disrupting the availability of affected Windows systems and any services dependent on GDI+ functionality. There is no impact on confidentiality or integrity — the vulnerability is limited to availability (CVSS A:HIGH, C:NONE, I:NONE). Because no authentication is required and the attack is network-accessible, a wide range of exposed Windows systems could be targeted, potentially affecting business continuity for organizations running unpatched endpoints or servers (Microsoft MSRC).

Mitigation and workarounds

Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected Windows versions. Organizations should apply the relevant cumulative updates to reach the following minimum build versions:

  • Windows 11 25H2: 10.0.26200.7781
  • Windows 11 24H2: 10.0.26100.7781
  • Windows 11 23H2: 10.0.22631.6649
  • Windows 10 22H2: 10.0.19045.6937
  • Windows 10 21H2: 10.0.19044.6937
  • Windows 10 1809: 10.0.17763.8389
  • Windows 10 1607: 10.0.14393.8868
  • Windows Server 2025: 10.0.26100.32313
  • Windows Server 2022: 10.0.20348.4711
  • Windows Server 2022 23H2: 10.0.25398.2149
  • Windows Server 2019: 10.0.17763.8389
  • Windows Server 2016: 10.0.14393.8868

Prioritize patching internet-exposed systems and servers running services that leverage GDI+ functionality. No configuration-based workaround has been published by Microsoft (Microsoft MSRC).

Community reactions

CVE-2026-20846 was covered as part of broader February 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Qualys, Rapid7, and Sophos, though it did not receive individual spotlight coverage given its DoS-only impact and lack of active exploitation. Qualys and Rapid7 included it in their monthly patch review analyses. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified (Qualys Blog, BleepingComputer).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management