Microsoft Starts 2026 With a Bang: A Freshly Exploited Zero-Day
ID: 098abf5d-6caf-5db1-91ed-92af7965ab56
STIX ID: report--098abf5d-6caf-5db1-91ed-92af7965ab56
Feed Name: Dark Reading
Microsoft's January security update addresses 112 CVEs, notably an actively exploited Desktop Window Manager information-disclosure zero-day (CVE-2026-20805) and multiple high-severity RCE and elevation-of-privilege bugs (including NTFS RCEs CVE-2026-20840 and CVE-2026-20922, and several EoP flaws rated CVSS 7.8–8.4). The report warns leaked memory details and Preview Pane exploitation increase risk of privilege escalation and remote code execution, urging organizations to prioritize patching to prevent multi-stage compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
