
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20856 is an improper input validation vulnerability in Windows Server Update Service (WSUS) that allows an unauthenticated remote attacker to execute arbitrary code over a network. Disclosed on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday, it affects a broad range of Microsoft products including Windows Server 2012/2012 R2/2016/2019/2022/2025 and Windows 10/11 versions (1607, 1809, 21H2, 22H2, 23H2, 24H2, 25H2). It carries a CVSS v3.1 base score of 8.1 (High) (Microsoft MSRC, Feedly).
The vulnerability is classified as CWE-20 (Improper Input Validation) in the Windows Server Update Service component. The attack vector is network-based with high attack complexity, requiring no privileges or user interaction, suggesting the exploitation likely involves a machine-in-the-middle (MitM) position to intercept and manipulate WSUS communications between clients and the update server. Because WSUS typically communicates over HTTP (unencrypted) in many default configurations, an attacker positioned on the network path can inject malicious data that bypasses input validation and triggers code execution. A public proof-of-concept exploit was published on GitHub within one day of patch release (Microsoft MSRC, Feedly).
Successful exploitation results in complete system compromise with high confidentiality, integrity, and availability impacts on the affected host. Of particular concern is the supply chain risk: if WSUS infrastructure is compromised, attackers could distribute malware enterprise-wide to all systems relying on WSUS for updates, enabling mass lateral movement across an entire organization. Compromised systems could be leveraged for data exfiltration, ransomware deployment, or persistent backdoor installation (Feedly).
%SystemRoot%\WID\, %ProgramFiles%\Update Services\); new scheduled tasks or services created by the WSUS service account.WsusService.exe or w3wp.exe (IIS worker process), such as cmd.exe, powershell.exe, certutil.exe, or network utilities like curl or wget.Microsoft released patches on January 13, 2026. Organizations should apply the following minimum build versions: Windows Server 2016 / Windows 10 1607 (10.0.14393.8783), Windows Server 2019 / Windows 10 1809 (10.0.17763.8276), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2025 (10.0.26100.32230). Prioritize patching WSUS infrastructure servers before client systems. As a workaround where immediate patching is not possible, configure WSUS to use HTTPS (SSL/TLS) to prevent MitM interception of update traffic, and implement network segmentation to restrict WSUS communication to authorized hosts only (Microsoft MSRC, Feedly).
The vulnerability was covered as part of Microsoft's January 2026 Patch Tuesday, which addressed 114 flaws including 3 zero-days, drawing significant attention from the security community. BleepingComputer, GBHackers, CyberSecurityNews, and Sophos all covered the January 2026 Patch Tuesday release, highlighting the WSUS RCE as a notable finding given the supply chain risk it poses. Expel's security team flagged the vulnerability in their Patch Tuesday analysis, and Flare.io published post-patch intelligence noting the rapid PoC publication as a key risk factor. The rapid availability of a public PoC within 24 hours of patch release was widely noted as a significant concern for enterprise defenders relying on WSUS (BleepingComputer, Sophos, Flare.io).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."