Skip to content

CVE-2026-20854

CVE

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 13, 2026
Last Seen
January 13, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Two vulnerabilities have been identified in the Windows Local Security Authority Subsystem Service (LSASS). CVE-2026-20875 allows unauthorized attackers to cause a denial of service, while CVE-2026-20854 enables authorized attackers to execute code remotely. Both vulnerabilities pose significant ris...

On January 10, 2026, Microsoft released its Patch Tuesday updates, fixing 114 vulnerabilities, including three classified as zero-day flaws. These updates affect various Microsoft products and are crucial for maintaining system security against potential exploits.

In January 2026, Adobe released 11 security patches addressing vulnerabilities in its software. Microsoft also issued updates during the same Patch Tuesday. Users of Adobe products and Microsoft software are advised to apply these updates promptly to mitigate potential risks.

Public Exploits

Checking GitHub for proof-of-concept code…