logo

Microsoft Patch Tuesday January 2026: Actively Exploited Zero Day, 8 High-Risk Flaws

ID: 2ae77618-905e-5e38-9043-dcc5a3379aa3

STIX ID: report--2ae77618-905e-5e38-9043-dcc5a3379aa3

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Microsoft's Patch Tuesday for January 2026 addresses 112 Microsoft CVEs (and three non-Microsoft CVEs), including an actively exploited zero-day information disclosure in Desktop Window Manager (CVE-2026-20805) that was added to CISA’s KEV catalog, eight additional “exploitation more likely” high-risk flaws (several allowing local privilege escalation or local code execution), and three highest-rated 8.8-severity vulnerabilities in SharePoint and RRAS that Microsoft judged at lower risk of attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.