ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20805
Local Information Disclosure in Microsoft Desktop Windows Manager (CVE-2026-20805)

CVE-2026-20805 is an information disclosure flaw (CWE-200) in Desktop Windows Manager (DWM) that exposes sensitive information to an unauthorized actor. An authorized attacker with local access and low privileges can trigger the flaw without user interaction and read sensitive data to which they should not have access. All supported Windows client versions from Windows 10 1607 through Windows 11 25H2 and Windows Server from 2012 through 2022 23H2 are affected, meaning essentially the entire installed Windows estate. The flaw was fixed in Microsoft's January 2026 Patch Tuesday release and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-13, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available.

Do: Deploy the January 2026 Microsoft security updates (Patch Tuesday) for every affected Windows 10/11 client and Windows Server release, prioritizing internet-facing and multi-user systems. Federal agencies must apply the updates per BOD 22-01 timelines following the KEV listing on 2026-01-13; other organizations should treat this as a priority patch given confirmed in-the-wild exploitation. After patching, review local account activity on Windows endpoints for signs of low-privileged information gathering, and note that patching is the primary mitigation since the flaw requires only local access.

5.55% KEV PoC
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • microsoft Windows 10 21H2
  • +9 more
masshundreds of millions of Windows client devices plus millions of Windows Server instances across all listed versions
CVE-2026-20868
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.81%
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • microsoft windows 10 21h2
  • +1 more
CVE-2026-20952
+2 in the same advisory: …20944 …20955
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
8.4
group max
<1%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
CVE-2026-20947
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute cod

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

NVD description · AI analysis pending
8.819%
  • microsoft sharepoint server
CVE-2026-20963
Deserialization RCE in Microsoft SharePoint Exploited in the Wild

CVE-2026-20963 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint that allows an unauthorized attacker to execute code remotely over the network. The flaw is triggered when SharePoint processes maliciously crafted serialized data without validating it, enabling an attacker to run arbitrary code in the context of the SharePoint service. Successful exploitation gives the attacker code execution on the affected SharePoint server, a foothold that typically supports further lateral movement and data access within the environment. Organizations running affected SharePoint deployments are in scope, though affected version ranges have not yet been published in the available data. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-18, confirming active exploitation, and its EPSS of 31.6% (98th percentile) indicates a high near-term probability of exploitation; no public proof-of-concept is known and CVSS scoring is not yet available.

Do: Inventory all SharePoint deployments, prioritize any internet-facing SharePoint Server instances, and apply Microsoft's security updates or vendor-specified mitigations as soon as they are available; federal agencies must follow BOD 22-01 (including cloud services) with its standard remediation timeline, and others should treat KEV inclusion as a patch-now signal despite the absence of a public PoC. Until patched, restrict network exposure of SharePoint and review server logs for signs of untrusted serialized data being processed leading to unexpected code execution.

9.833% KEV
  • Microsoft SharePoint
massOrder of millions of users across plausibly hundreds of thousands of SharePoint deployments (SharePoint Online and on-prem SharePoint Server)
Full article625 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Researchers said the information disclosure zero-day exposes sensitive information that attackers can use to undermine defenses and make other exploits more reliable.

Listen to this article

0:00

Learn more.

Microsoft
(Jeenah Moon/Getty Images)

Microsoft’s first security update of 2026 addressed 112 vulnerabilities affecting its products and underlying systems, including one actively exploited zero-day in Desktop Window Manager. 

The company’s latest Patch Tuesday update marks the second consecutive month with no critical vulnerabilities disclosed. The batch of patches also contains more than 110 CVEs for the second January in a row. 

The zero-day vulnerability — CVE-2026-20805 — is an information disclosure defect with a CVSS rating of 5.5 that can be exploited by an unauthorized attacker to expose sensitive information. The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog Tuesday.

Information disclosure vulnerabilities are sporadically exploited in the wild, but not often, according to Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative. “This shows how memory leaks can be as important as code execution bugs since they make the remote code executions reliable,” he wrote in a blog post.

Jack Bicer, director of vulnerability research at Action1, concurred, added that the memory exposed by exploitation of CVE-2026-20805 can undermine defenses and bolster additional exploits. 

“This vulnerability increases the risk of successful multi-stage attacks,” Bicer said in an email. “Leaked memory details can be combined with other vulnerabilities to achieve privilege escalation or data theft, potentially leading to broader system compromise, regulatory exposure and loss of trust.”

Microsoft did not say how many attacks are linked to the zero-day. Yet, exploitation requires an attacker to have local access on the targeted system, Satnam Narang, senior staff research engineer at Tenable, said in an email.

“While Desktop Window Manager is a frequent flyer on Patch Tuesday with 20 CVEs patched in this library since 2022, this is the first time we’ve seen an information disclosure bug in this component exploited in the wild,” he added. “Attackers have historically used it to climb the ladder of privileges.”

The most severe defects disclosed by Microsoft this month include CVE-2026-20947 and CVE-2026-20963 affecting Microsoft Office SharePoint, CVE-2026-20868 affecting Windows Routing and Remote Access Service, CVE-2026-20952 and CVE-2026-20955 affecting Microsoft Office, and CVE-2026-20944 affecting Microsoft Office Word. 

Microsoft also flagged eight vulnerabilities, each with a CVSS rating of 7.8, as more likely to be exploited this month. 

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-january-2026/