Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Two vulnerabilities have been identified in Windows Routing and Remote Access Service (RRAS). CVE-2026-20868 allows unauthorized remote code execution via a heap-based buffer overflow, while CVE-2026-20843 enables authorized users to elevate their privileges locally due to improper access control.
Zscaler has implemented protective measures against nine vulnerabilities identified in the January 2026 Microsoft security bulletins. The company is collaborating with Microsoft through the MAPP program and will continue to monitor for any exploits related to these vulnerabilities.
On January 10, 2026, Microsoft released its Patch Tuesday updates, fixing 114 vulnerabilities, including three classified as zero-day flaws. These updates affect various Microsoft products and are crucial for maintaining system security against potential exploits.
In January 2026, Adobe released 11 security patches addressing vulnerabilities in its software. Microsoft also issued updates during the same Patch Tuesday. Users of Adobe products and Microsoft software are advised to apply these updates promptly to mitigate potential risks.