January 2026 Patch Tuesday forecast: And so it continues
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-14174 | Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet. Do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations. | 8.8 | 22% | KEV |
| massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users) | |
| CVE-2025-43529 | Use-After-Free in Apple WebKit (Safari, iOS, macOS) Allows Arbitrary Code Execution CVE-2025-43529 is a use-after-free (CWE-416) flaw in Apple's WebKit browser engine, fixed via improved memory management. It is triggered when a device processes maliciously crafted web content, and successful exploitation can lead to arbitrary code execution with network reachability and no privileges required (CVSS 3.1: 8.8, user interaction needed). It affects a broad range of Apple products: Safari, iPhone OS/iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, with fixes delivered in Safari 26.2, iOS/iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Apple reports the issue was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-15 (a companion CVE-2025-14174 was issued for the same report). No public proof-of-concept is known, and EPSS assigns an 8.9% probability of exploitation within 30 days (95th percentile). Do: Update affected devices to Safari 26.2, iOS/iPadOS 26.2 (or iOS/iPadOS 18.7.3 on devices that remain on the iOS 18 branch), macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2, prioritizing mobile users and high-risk targeted individuals. Federal agencies must remediate per CISA BOD 22-01 requirements since the CVE is in the KEV catalog (added 2025-12-15); also review the related CVE-2025-14174 addressed by the same updates. Check device fleet inventory for WebKit-exposed Apple hardware that cannot reach the fixed versions and confirm patches have been applied. | 8.8 | 9% | KEV |
| masswell over 1 billion Apple devices/users across iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro running pre-26.2 (or pre-18.7.3 legacy) software |
Full article630 words · extracted from helpnetsecurity.com · click to collapse
Welcome to a new year of my Patch Tuesday forecast blog where I provide a summary of Microsoft and other vendor’s security patch activity (and reported issues) for the month, talk about some of the latest trends, processes, and evolution of patch management, and finally yes, provide a forecast of what security patches are expected to release next week on Patch Tuesday.

Microsoft reported several issues you should be aware of with respect to the December Patch Tuesday releases. To start, in their Known Issues report they announced that ‘Message Queuing (MSMQ) might fail with the December 2025 Windows security update’. This was due to some recent security changes related to MSMQ. Symptoms include MSMQ queues becoming inactive and IIS sites failing with “Insufficient resources to perform operation” errors. They have since released out-of band KB5074976 to address the issues which impacted Windows 10 21H2 and 22H2.
Microsoft offers KIR or registry fix for Windows 11 issue
The next known issue was actually reported in KB5072033 for Windows 11 24H2 and 25H2. Listed as ‘RemoteApp sessions might fail to start on Azure Virtual Desktop’, this has turned into a significant issue for customers with large numbers of Azure hosted systems. Microsoft provides two workaround options as the attempt to resolve this issue. The first workaround is to manually add a registry key to the system as explained in the KB and the second is to use the Known Issue Rollback (KIR) which can be deployed via group policy as also explained in the KB.
And the final issue is the failure of VPM network access to systems in the Windows Subsystem for Linux (WSL) environment. This effectively isolates critical company resources from use. This has been an ongoing issue and Microsoft has yet to provide a solution, but maybe this Patch Tuesday?
Apple patches two actively exploited WebKit zero-days
Apple provided security updates for many of their products on December 12. If you were holding off deployment with the holidays so near, you’ll want to include them in your patch routine this month because there were two zero-day vulnerabilities identified. Apple stated with regards to CVE-2025-14174 and CVE-2025-43529, both in Webkit, Apple’s open source Web browser engine, that “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26.”
January 2026 Patch Tuesday forecast
- We didn’t have a set of preview patches in late December, so you never know what to expect for the season opener. The usual Windows 10 ESU, Windows 11, and Server updates are expected to be light on CVEs due to downtime over the holidays. Last month we saw an Exchange Server update, so perhaps a SQL server update and .NET framework will be released.
- Adobe provided a small security update for Acrobat and Reader last month with just 4 CVEs and little else. We should see a large subset of Adobe Creative Cloud Apps with updates next Tuesday but probably not Acrobat and Reader again.
- It should be quiet from Apple next week but make sure you have the December 12 updates already deployed or in queue to address those zero-day vulnerabilities.
- Google released Chrome beta 144.0.7559.59 for Windows, Mac and Linux yesterday, so expect that version on Patch Tuesday.
- Mozilla has been releasing their updates on Patch Tuesday of late, so expect the latest security fixes for Firefox, Firefox ESR, and Thunderbird to be released.
I hope everyone had a nice break and is ready to jump back into the chaos we call patch management. With the growing popularity of AI, we could see significant changes coming to our community this year. But regardless of what happens, the need for the patch process will continue.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/01/09/january-2026-patch-tuesday-forecast/