CVE-2026-20848 Windows SMB Server Elevation of Privilege Vulnerability
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated FAQ information. This is an informational change only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 16, 2026
Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected […]
Published January 16, 2026
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Published January 16, 2026
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Published January 16, 2026
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Management Services allows an authorized attacker to elevate privileges locally.
Published January 16, 2026
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.