Microsoft Patch Tuesday security updates for January 2026 fixed actively exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-31096 | An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). An issue was discovered in Broadcom) LSI PCI-SV92EX Soft Modem Kernel Driver through 2.2.100.1 (aka AGRSM64.sys). There is Local Privilege Escalation to SYSTEM via a Stack Overflow in RTLCopyMemory (IOCTL 0x1b2150). An attacker can exploit this to elevate privileges from a medium-integrity process to SYSTEM. This can also be used to bypass kernel-level protections such as AV or PPL, because exploit code runs with high-integrity privileges and can be used in coordinated BYOVD (bring your own vulnerable driver) ransomware campaigns. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2024-55414 | A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via spec A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code. NVD description · AI analysis pending | 9.8 | 1% | — | — | ||
| CVE-2026-20805 | Local Information Disclosure in Microsoft Desktop Windows Manager (CVE-2026-20805) CVE-2026-20805 is an information disclosure flaw (CWE-200) in Desktop Windows Manager (DWM) that exposes sensitive information to an unauthorized actor. An authorized attacker with local access and low privileges can trigger the flaw without user interaction and read sensitive data to which they should not have access. All supported Windows client versions from Windows 10 1607 through Windows 11 25H2 and Windows Server from 2012 through 2022 23H2 are affected, meaning essentially the entire installed Windows estate. The flaw was fixed in Microsoft's January 2026 Patch Tuesday release and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-13, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available. Do: Deploy the January 2026 Microsoft security updates (Patch Tuesday) for every affected Windows 10/11 client and Windows Server release, prioritizing internet-facing and multi-user systems. Federal agencies must apply the updates per BOD 22-01 timelines following the KEV listing on 2026-01-13; other organizations should treat this as a priority patch given confirmed in-the-wild exploitation. After patching, review local account activity on Windows endpoints for signs of low-privileged information gathering, and note that patching is the primary mitigation since the flaw requires only local access. | 5.5 | 5% | KEV PoC |
| masshundreds of millions of Windows client devices plus millions of Windows Server instances across all listed versions | |
| CVE-2026-21265 | Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates. NVD description · AI analysis pending | 6.4 | 1% |
| — |
Full article481 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday addressed 112 security flaws across Windows, Office, Azure, Edge, and more, including eight critical vulnerabilities, kicking off the new year with a major patch update.
Microsoft Patch Tuesday security updates for January 2026 release 112 CVEs affecting Windows, Office, Azure, Edge, SharePoint, SQL Server, SMB, and Windows management services. Including third-party Chromium fixes, the total rises to 114 vulnerabilities. Eight flaws are rated Critical, while the rest are Important. Large January releases are common, as vendors often delay patches during the holidays to avoid disruptions.
One of these flaws, tracked as CVE-2026-20805 (CVSS score of 5.5), is actively exploited in attacks in the wild, while two others are labeled as publicly known at release. CVE-2026-20805 is a Windows Desktop Window Manager flaw that lets attackers leak small pieces of memory information. While it does not directly run malicious code, the leaked data can help attackers bypass security protections and make more serious exploits work.
“Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.” reads the advisory. “The type of information that could be disclosed if an attacker successfully exploited this vulnerability is a section address from a remote ALPC port which is user-mode memory.”
This weakness shows how even limited information leaks can play a key role in full system compromise.
Microsoft did not share details about the attacks exploiting this vulnerability.
The following vulnerabilities are labeled as publicly known at release:
- CVE-2023-31096 (CVSS score of 7.8) – This flaw affects outdated Agere Soft Modem drivers included with Windows. The vulnerability allows attackers to gain higher system privileges by exploiting these drivers. If abused, it could let a local attacker take deeper control of a device. To eliminate the risk, Microsoft removed the vulnerable agrsm64.sys and agrsm.sys drivers in the January 2026 cumulative update.
- CVE-2026-21265 (CVSS score of 6.4) – affects Windows Secure Boot and relates to expiring security certificates. If administrators do not update these certificates, systems may stop trusting new boot loaders and could fail to receive future security updates. While attackers are unlikely to exploit this issue directly, ignoring it can leave devices unpatched or unable to boot securely. Microsoft disclosed this issue months ago, which is why it is listed as publicly known.
- CVE-2024-55414 (CVSS score of 6.4) – CVE-2024-55414 affects Motorola Soft Modem drivers included with Windows and allows attackers to gain elevated system privileges. The flaw exists in the smserl64.sys and smserial.sys drivers, which Microsoft removed in the January cumulative update. Systems that still rely on this legacy hardware may face compatibility issues, and Microsoft advises removing any remaining dependencies to reduce security risk.
The full list of CVEs addressed by Microsoft Patch Tuesday security updates for January 2026 is available here.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Patch Tuesday)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/186888/hacking/microsoft-patch-tuesday-security-updates-for-january-2026-fixed-actively-exploited-zero-day.html