Jan 2026: Windows Kernel Information Disclosure Vulnerability
CVE-2026-20838 Published on January 13, 2026
Windows Kernel Information Disclosure Vulnerability
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
Weakness Type
Generation of Error Message Containing Sensitive Information
The software generates an error message that includes sensitive information about its environment, users, or associated data.
Products Associated with CVE-2026-20838
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 11 version 22H3:- Version 10.0.22631.0 and below 10.0.22631.6491 is affected.
- Version 10.0.22631.0 and below 10.0.22631.6491 is affected.
- Version 10.0.26100.0 and below 10.0.26100.7623 is affected.
- Version 10.0.26200.0 and below 10.0.26200.7623 is affected.
- Version 10.0.20348.0 and below 10.0.20348.4648 is affected.
- Version 10.0.25398.0 and below 10.0.25398.2092 is affected.
- Version 10.0.26100.0 and below 10.0.26100.32230 is affected.
- Version 10.0.26100.0 and below 10.0.26100.32230 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.