CVE-2026-20846: GDI+ Denial of Service Vulnerability
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8868Patch KB5075999 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19822.20000 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7840Fixed in 10.0.26100.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32370Fixed in 10.0.26100.32313Patch KB5075942 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6649Patch KB5075941 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2149Patch KB5075897 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7840Fixed in 10.0.26200.7781Patch KB5077212 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6937Patch KB5075912 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23022Patch KB5075970 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25923Patch KB5075971 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4773Fixed in 10.0.20348.4711Patch KB5075943 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8389Patch KB5075904 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.1575Patch KB5077179
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20846?
CVE-2026-20846 has been classified as a moderate severity denial of service vulnerability.
How do I fix CVE-2026-20846?
To address CVE-2026-20846, ensure that all relevant Microsoft security updates for your affected product version are applied.
What products are affected by CVE-2026-20846?
CVE-2026-20846 affects various versions of Windows 10, Windows 11, and Windows Server products.
Can CVE-2026-20846 be exploited remotely?
Yes, CVE-2026-20846 can be exploited remotely by an unauthorized attacker to cause a denial of service.
Is there a workaround for CVE-2026-20846?
There are currently no known workarounds for CVE-2026-20846, and applying security updates is recommended.