ThreatCluster

Multiple Vulnerabilities in Windows LSASS Affecting Security

First seen 13 Jan 2026, 20:07 UTC Api.Msrc.Microsoft 35

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in the Windows Local Security Authority Subsystem Service (LSASS). CVE-2026-20875 allows unauthorized attackers to cause a denial of service, while CVE-2026-20854 enables authorized attackers to execute code remotely. Both vulnerabilities pose significant risks to systems utilizing LSASS.