Microsoft’s Security Update Guide lists a new vulnerability, tracked as CVE‑2026‑20868, that affects the Windows Routing and Remote Access Service (RRAS) and is described as a remote code execution (RCE) issue — an urgent operational problem for any organization that runs RRAS‑based VPN or...
Microsoft has recorded CVE-2026-20919 as an SMB Server elevation-of-privilege (EoP) vulnerability in its Security Update Guide, and the entry is part of the January 2026 Windows security roll-up that administrators should treat as actionable: the vendor lists the identifier against the SMB...