CVE•Published 2026-01-13•1 article on news•6 live references•NVD data
CVE-2026-20860
Vulnerability data via CVEDB (Shodan)
CVSS v3.1
7.8
HIGH
EPSS percentile
94
Exploit Prediction Scoring System · top 6% of all CVEs
Description
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Timeline
Published 2026-01-13
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-20860Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · OS
os:"Windows 10 1607"Hosts Shodan identified as running Windows 10 1607.
More intel sources (5)
Shodan report
vuln:CVE-2026-20860Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-20860Censys host search filtered to this CVE id.
grep.app
CVE-2026-20860Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-20860GitHub code search for direct mentions.
Google dork
"CVE-2026-20860" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-208608 repos
Threekiii/Awesome-POCJava
一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.
Threekiii/CVEunknown
一个 CVE 漏洞预警知识库,无 exp/poc,部分包含修复方案。A knowledge base of CVE security vulnerability, no PoCs/exploits.
Xuchen-Li/cv-arxiv-dailyPython
Automatically update arXiv papers about SOT & VLT, Multi-modal Learning, LLM and Video Understanding using Github Actions.
XuzhaoLi/ro-arxiv-dailyPython
Automatically Update Arxiv Papers about Path Planning, LLM and Autonomous Driving using Github Actions since 2024.2.
J1ezds/Vulnerability-Wiki-pageHTML
这是一个每天同步Vulnerability-Wiki中docs-base中内容的项目
AndrewAltimit/exploitsPython
Security research and exploit development: vulnerability analysis, exploit chain implementation, post-exploitation tradecraft, and defensive assessment tooling. Covers browser engi…
Ritacloud23/Netflix-Clone-Azure-AKS-DevSecOps-DeploymentJavaScript
joaomagfreitas/starsunknown
Complete list of repositories I've starred