
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20836 is a race condition vulnerability in the Windows Graphics Kernel that allows a low-privileged, authenticated local attacker to elevate privileges. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday release. Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2016, 2019, 2022 (including 23H2 edition), and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization — Race Condition). The flaw exists in the Windows Graphics Kernel subsystem, where concurrent access to a shared resource is not properly synchronized, creating a time-of-check to time-of-use (TOCTOU) window that an attacker can exploit. Exploitation requires local access and low-level privileges, but no user interaction, and the attack complexity is rated High due to the timing requirements inherent in race condition exploitation. No public proof-of-concept code has been observed at the time of disclosure (Microsoft MSRC, Feedly).
Successful exploitation allows a low-privileged local attacker to escalate privileges to SYSTEM level on the affected Windows host, resulting in high confidentiality, integrity, and availability impacts. An attacker who achieves SYSTEM-level access can install malware, exfiltrate sensitive data, disable security controls, and potentially use the compromised host as a pivot point for lateral movement within the network. The broad scope of affected Windows versions — from Windows 10 1607 through Windows Server 2025 — means the potential attack surface is extensive across enterprise environments (Feedly).
Microsoft released patches for all affected Windows versions on January 13, 2026, as part of the January 2026 Patch Tuesday update. Organizations should apply the following minimum patched versions: Windows 10 1607 → 10.0.14393.8783; Windows 10 1809 → 10.0.17763.8276; Windows 10 21H2 → 10.0.19044.6809; Windows 10 22H2 → 10.0.19045.6809; Windows 11 23H2 → 10.0.22631.6491; Windows 11 24H2 → 10.0.26100.7623; Windows 11 25H2 → 10.0.26200.7623; Windows Server 2016 → 10.0.14393.8783; Windows Server 2019 → 10.0.17763.8276; Windows Server 2022 → 10.0.20348.4648; Windows Server 2022 23H2 → 10.0.25398.2092; Windows Server 2025 → 10.0.26100.32230. As a defense-in-depth measure, organizations should enforce the principle of least privilege and restrict local logon access to minimize the pool of potential attackers (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Cybersecurity News, Zero Day Initiative (ZDI), SANS ISC, and Sophos, all noting it among the 114 CVEs addressed that month. Commentary focused primarily on the three zero-days patched in the same release rather than this specific vulnerability, given its lack of public PoC and in-the-wild exploitation. Security vendors such as Qualys and Lansweeper flagged the CVE in their patch Tuesday analyses for enterprise tracking purposes (BleepingComputer, ZDI, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."