CVE-2026-20846 | Microsoft Windows up to Server 2025 GDI+ buffer over-read
A vulnerability described as critical has been identified in Microsoft Windows. The affected element is an unknown function of the component GDI+. The manipulation results in buffer over-read.
This vulnerability is reported as CVE-2026-20846. The attack can be launched remotely. No exploit exists.
It is advisable to implement a patch to correct this issue.