logo

Microsoft Starts 2026 With a Bang: A Freshly Exploited Zero-Day

ID: 098abf5d-6caf-5db1-91ed-92af7965ab56

STIX ID: report--098abf5d-6caf-5db1-91ed-92af7965ab56

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft's January security update addresses 112 CVEs, notably an actively exploited Desktop Window Manager information-disclosure zero-day (CVE-2026-20805) and multiple high-severity RCE and elevation-of-privilege bugs (including NTFS RCEs CVE-2026-20840 and CVE-2026-20922, and several EoP flaws rated CVSS 7.8–8.4). The report warns leaked memory details and Preview Pane exploitation increase risk of privilege escalation and remote code execution, urging organizations to prioritize patching to prevent multi-stage compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.