logo

Microsoft Patch Tuesday security updates for January 2026 fixed actively exploited zero-day

ID: eea8971c-72dd-5894-9ed5-8dd6759e4740

STIX ID: report--eea8971c-72dd-5894-9ed5-8dd6759e4740

Feed Name: Security Affairs

Threat Score
60/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Microsoft January 2026 Patch Tuesday:** Microsoft released fixes for 112 vulnerabilities across Windows, Office, Azure, Edge and other components (114 including third-party Chromium fixes), including eight critical issues and an actively exploited Desktop Window Manager information-leak zero-day (CVE-2026-20805). The bulletin also highlights publicly known flaws affecting legacy modem drivers and Secure Boot certificates, removal of vulnerable drivers in the cumulative update, and urges administrators to apply updates to avoid privilege escalation, boot/trust issues, and to reduce risk of chained exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.