Windows DWM Zero-Day Exploited in the Wild to Bypass ASLR ProtectionsMicrosoft patched CVE-2026-20805, a Desktop Window Manager information disclosure flaw actively exploited to defeat memory protections. CISA added it to the KEV catalog, requiring federal agencies to patch by February 3, 2026.Radical Notion Team6 months ago