Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20806