
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20854 is a use-after-free vulnerability in the Windows Local Security Authority Subsystem Service (LSASS) that allows an authorized attacker to execute arbitrary code over a network. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects Windows 11 versions 24H2 (before 10.0.26100.7623), 25H2 (before 10.0.26200.7623), and Windows Server 2025 (before 10.0.26100.32230). It carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), meaning LSASS improperly accesses memory after it has been freed, potentially allowing an attacker to control the freed memory region and redirect code execution. Exploitation requires network access and low-level authenticated privileges (PR:L), but no user interaction, and has high attack complexity (AC:H), suggesting that specific race conditions or memory layout requirements must be met. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Microsoft MSRC, Feedly).
Successful exploitation results in complete system compromise, with high impact to confidentiality, integrity, and availability. Because LSASS is the critical Windows process responsible for authentication and security policy enforcement, a compromised LSASS instance could expose credential material, allow unauthorized modifications to security policies, and disrupt authentication services. The network-based attack vector means exploitation can be attempted remotely against any reachable affected system, increasing the risk of lateral movement within enterprise environments (Feedly).
Microsoft released patches on January 13, 2026, as part of the January 2026 Patch Tuesday update cycle. Administrators should update affected systems to the following minimum versions: Windows Server 2025 to build 10.0.26100.32230 or later, Windows 11 Version 24H2 to build 10.0.26100.7623 or later, and Windows 11 Version 25H2 to build 10.0.26200.7623 or later. As an interim measure, restricting network access to systems running LSASS on unpatched versions — particularly limiting exposure of authentication endpoints — can reduce the attack surface (Microsoft MSRC, Feedly).
The January 2026 Patch Tuesday release, which included CVE-2026-20854 among 114 fixed vulnerabilities, received broad coverage from security outlets including BleepingComputer, Talos Intelligence, Zero Day Initiative, Qualys, and CrowdStrike. Analysts noted the overall release as significant given the inclusion of three zero-day vulnerabilities, though CVE-2026-20854 itself was not highlighted as one of the most critical issues in the batch. Community sentiment focused primarily on the actively exploited zero-days in the same release rather than this specific LSASS flaw (BleepingComputer, Talos, ZDI).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."