logo

Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero-day

ID: db097dd3-381e-5015-8909-bc9eca5f07b1

STIX ID: report--db097dd3-381e-5015-8909-bc9eca5f07b1

Feed Name: CyberScoop

Threat Score
55/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Microsoft’s January 2026 Patch Tuesday fixed 112 vulnerabilities, including an actively exploited information-disclosure zero-day (CVE-2026-20805) in Desktop Window Manager that requires local access; the flaw (CVSS 5.5) is listed in CISA’s known exploited vulnerabilities catalog and experts warn leaked memory can enable privilege escalation and multi-stage attacks. Several other high-severity flaws across Office, SharePoint, and Windows components were also fixed, and Microsoft flagged multiple vulnerabilities more likely to be exploited this month.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.