ThreatCluster

Multiple Vulnerabilities in TWINUI Subsystem Affect Windows Users

First seen 13 Jan 2026, 20:07 UTC Api.Msrc.Microsoft 49

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in the Tablet Windows User Interface (TWINUI) Subsystem. CVE-2026-20826 allows authorized attackers to elevate privileges locally through a race condition, while CVE-2026-20827 enables the disclosure of sensitive information to unauthorized actors. Both vulnerabilities impact users of the TWINUI Subsystem.