Microsoft Patch Tuesday addresses 112 defects, including one actively exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20805 | Local Information Disclosure in Microsoft Desktop Windows Manager (CVE-2026-20805) CVE-2026-20805 is an information disclosure flaw (CWE-200) in Desktop Windows Manager (DWM) that exposes sensitive information to an unauthorized actor. An authorized attacker with local access and low privileges can trigger the flaw without user interaction and read sensitive data to which they should not have access. All supported Windows client versions from Windows 10 1607 through Windows 11 25H2 and Windows Server from 2012 through 2022 23H2 are affected, meaning essentially the entire installed Windows estate. The flaw was fixed in Microsoft's January 2026 Patch Tuesday release and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-13, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available. Do: Deploy the January 2026 Microsoft security updates (Patch Tuesday) for every affected Windows 10/11 client and Windows Server release, prioritizing internet-facing and multi-user systems. Federal agencies must apply the updates per BOD 22-01 timelines following the KEV listing on 2026-01-13; other organizations should treat this as a priority patch given confirmed in-the-wild exploitation. After patching, review local account activity on Windows endpoints for signs of low-privileged information gathering, and note that patching is the primary mitigation since the flaw requires only local access. | 5.5 | 5% | KEV PoC |
| masshundreds of millions of Windows client devices plus millions of Windows Server instances across all listed versions | |
| CVE-2026-20868 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2026-20952 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 8.4 group max | <1% |
| — | ||
| CVE-2026-20947 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute cod Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 19% |
| — | ||
| CVE-2026-20963 | Deserialization RCE in Microsoft SharePoint Exploited in the Wild CVE-2026-20963 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint that allows an unauthorized attacker to execute code remotely over the network. The flaw is triggered when SharePoint processes maliciously crafted serialized data without validating it, enabling an attacker to run arbitrary code in the context of the SharePoint service. Successful exploitation gives the attacker code execution on the affected SharePoint server, a foothold that typically supports further lateral movement and data access within the environment. Organizations running affected SharePoint deployments are in scope, though affected version ranges have not yet been published in the available data. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-18, confirming active exploitation, and its EPSS of 31.6% (98th percentile) indicates a high near-term probability of exploitation; no public proof-of-concept is known and CVSS scoring is not yet available. Do: Inventory all SharePoint deployments, prioritize any internet-facing SharePoint Server instances, and apply Microsoft's security updates or vendor-specified mitigations as soon as they are available; federal agencies must follow BOD 22-01 (including cloud services) with its standard remediation timeline, and others should treat KEV inclusion as a patch-now signal despite the absence of a public PoC. Until patched, restrict network exposure of SharePoint and review server logs for signs of untrusted serialized data being processed leading to unexpected code execution. | 9.8 | 33% | KEV |
| massOrder of millions of users across plausibly hundreds of thousands of SharePoint deployments (SharePoint Online and on-prem SharePoint Server) |
Full article625 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Researchers said the information disclosure zero-day exposes sensitive information that attackers can use to undermine defenses and make other exploits more reliable.
Listen to this article
0:00
Learn more.
Microsoft’s first security update of 2026 addressed 112 vulnerabilities affecting its products and underlying systems, including one actively exploited zero-day in Desktop Window Manager.
The company’s latest Patch Tuesday update marks the second consecutive month with no critical vulnerabilities disclosed. The batch of patches also contains more than 110 CVEs for the second January in a row.
The zero-day vulnerability — CVE-2026-20805 — is an information disclosure defect with a CVSS rating of 5.5 that can be exploited by an unauthorized attacker to expose sensitive information. The Cybersecurity and Infrastructure Security Agency added the defect to its known exploited vulnerabilities catalog Tuesday.
Information disclosure vulnerabilities are sporadically exploited in the wild, but not often, according to Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative. “This shows how memory leaks can be as important as code execution bugs since they make the remote code executions reliable,” he wrote in a blog post.
Jack Bicer, director of vulnerability research at Action1, concurred, added that the memory exposed by exploitation of CVE-2026-20805 can undermine defenses and bolster additional exploits.
“This vulnerability increases the risk of successful multi-stage attacks,” Bicer said in an email. “Leaked memory details can be combined with other vulnerabilities to achieve privilege escalation or data theft, potentially leading to broader system compromise, regulatory exposure and loss of trust.”
Microsoft did not say how many attacks are linked to the zero-day. Yet, exploitation requires an attacker to have local access on the targeted system, Satnam Narang, senior staff research engineer at Tenable, said in an email.
“While Desktop Window Manager is a frequent flyer on Patch Tuesday with 20 CVEs patched in this library since 2022, this is the first time we’ve seen an information disclosure bug in this component exploited in the wild,” he added. “Attackers have historically used it to climb the ladder of privileges.”
The most severe defects disclosed by Microsoft this month include CVE-2026-20947 and CVE-2026-20963 affecting Microsoft Office SharePoint, CVE-2026-20868 affecting Windows Routing and Remote Access Service, CVE-2026-20952 and CVE-2026-20955 affecting Microsoft Office, and CVE-2026-20944 affecting Microsoft Office Word.
Microsoft also flagged eight vulnerabilities, each with a CVSS rating of 7.8, as more likely to be exploited this month.
The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-january-2026/