CVE-2026-20848 Windows SMB Server Elevation of Privilege Vulnerability
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated FAQ information. This is an informational change only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 16, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 16, 2026
Microsoft Edge Elevation Service exposes a privileged COM interface that inadequately validates the privileges of the calling process. A standard (non‑administrator) local user can invoke the IElevatorEdge interface method LaunchUpdateCmdElevatedAndWait, causing the service to execute privileged update commands as LocalSystem. This allows a non‑administrator to enable or disable Windows Virtualization‑Based Security (VBS) by modifying protected […]
Published January 16, 2026
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Published January 16, 2026
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Published January 16, 2026
Concurrent execution using shared resource with improper synchronization (‘race condition’) in Windows Management Services allows an authorized attacker to elevate privileges locally.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.