CVE-2026-20849 Windows Kerberos Elevation of Privilege Vulnerability
Published January 16, 2026
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
Published January 16, 2026
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
Published January 16, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 16, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 16, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 15, 2026
Updated acknowledgment. This is an informational change only.
Published January 15, 2026
Updated the build numbers. This is an informational update only.
Published January 15, 2026
Improper link resolution before file access (‘link following’) in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.
Published January 14, 2026
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
Published January 14, 2026
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Published January 14, 2026
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.