ai-security EN

January 2026 Microsoft Patch Tuesday Summary, (Tue, Jan 13th)

January 2026 Microsoft Patch Tuesday Summary

Published
2026-01-13. Last Updated
2026-01-13 19:05:41 UTC

by Johannes Ullrich (Version: 1)

0 comment(s)

Today, Microsoft released patches for 113 vulnerabilities. One of these vulnerabilities affected the Edge browser and was patched upstream by Chromium.

Eight of the vulnerabilities are rated critical. One has been disclosed before today, and one is already being exploited. Five of the critical vulnerabilities affect Microsoft Office components.

Noteworthy Vulnerabilities

CVE-2026-20854
A remote code execution vulnerability in LSASS. This brings back memories from hallmark Windows security events like the Blaster worm. However, in this case, the attacker must be authenticated. But the attacker does not need elevated privileges. Microsoft considers exploitation less likely.

CVE-2026-20805 : This is an information disclosure vulnerability in the Desktop Windows Manager, and it is already being exploited. The vulnerability can be used to identify the section address from a remote ALPC port.

CVE-2026-21265 : Secure boot may not recognize an expired certificate. This problem was already disclosed, but so far hasn’t been exploited.

Description
CVEDisclosedExploitedExploitability (old versions)current versionSeverityCVSS Base (AVG)CVSS Temporal (AVG)
Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-21224NoNo--Important7.86.8
Azure Core shared client library for Python Remote Code Execution Vulnerability
CVE-2026-21226NoNo--Important7.56.5
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-20815NoNo--Important7.06.1
CVE-2026-20830NoNo--Important7.06.1
CVE-2026-21221NoNo--Important7.06.1
Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20835NoNo--Important5.54.8
CVE-2026-20851NoNo--Important6.25.4
Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag
CVE-2026-0628NoNo---
Desktop Window Manager Information Disclosure Vulnerability
CVE-2026-20805NoYes--Important5.54.8
Desktop Windows Manager Elevation of Privilege Vulnerability
CVE-2026-20871NoNo--Important7.86.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-20814NoNo--Important7.06.1
CVE-2026-20836NoNo--Important7.06.1
Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability
CVE-2026-20962NoNo--Important4.43.9
Host Process for Windows Tasks Elevation of Privilege Vulnerability
CVE-2026-20941NoNo--Important7.86.8
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2026-21219NoNo--Important7.06.1
LDAPTampering Vulnerability
CVE-2026-20812NoNo--Important6.55.7
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-20842NoNo--Important7.06.1
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20946NoNo--Important7.86.8
CVE-2026-20955NoNo--Critical7.86.8
CVE-2026-20956NoNo--Important7.86.8
CVE-2026-20950NoNo--Important7.86.8
CVE-2026-20957NoNo--Critical7.86.8
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2026-20949NoNo--Important7.86.8
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
CVE-2026-20943NoNo--Important7.06.1
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-20953NoNo--Critical8.47.3
CVE-2026-20952NoNo--Critical8.47.3
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-20803NoNo--Important7.26.3
Microsoft SharePoint Information Disclosure Vulnerability
CVE-2026-20958NoNo--Important5.44.7
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2026-20963NoNo--Important8.87.7
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-20951NoNo--Important7.86.8
CVE-2026-20947NoNo--Important8.87.7
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-20959NoNo--Important4.64.0
Microsoft Windows File Explorer Spoofing Vulnerability
CVE-2026-20847NoNo--Important6.55.7
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-20944NoNo--Critical8.47.3
CVE-2026-20948NoNo--Important7.86.8
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2026-20925NoNo--Important6.55.7
CVE-2026-20872NoNo--Important6.55.7
Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-20821NoNo--Important6.25.4
Secure Boot Certificate Expiration Security Feature Bypass Vulnerability
CVE-2026-21265YesNo--Important6.45.6
TPM Trustlet Information Disclosure Vulnerability
CVE-2026-20829NoNo--Important5.54.8
Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
CVE-2026-20826NoNo--Important7.86.8
CVE-2026-20827NoNo--Important5.54.8
Win32k Elevation of Privilege Vulnerability
CVE-2026-20811NoNo--Important7.86.8
CVE-2026-20920NoNo--Important7.86.8
CVE-2026-20863NoNo--Important7.06.1
Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-20965NoNo--Important7.56.5
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20810NoNo--Important7.86.8
CVE-2026-20831NoNo--Important7.86.8
CVE-2026-20860NoNo--Important7.86.8
Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability
CVE-2026-20839NoNo--Important5.54.8
Windows Clipboard Server Elevation of Privilege Vulnerability
CVE-2026-20844NoNo--Important7.46.4
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-20857NoNo--Important7.86.8
CVE-2026-20940NoNo--Important7.86.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-20820NoNo--Important7.86.8
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-20864NoNo--Important7.86.8
Windows Deployment Services Remote Code Execution Vulnerability
CVE-2026-0386NoNo--Important7.56.5
Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2026-20817NoNo--Important7.86.8
Windows File Explorer Elevation of Privilege Vulnerability
CVE-2026-20808NoNo--Important7.06.1
Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20823NoNo--Important5.54.8
CVE-2026-20932NoNo--Important5.54.8
CVE-2026-20937NoNo--Important5.54.8
CVE-2026-20939NoNo--Important5.54.8
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-20822NoNo--Critical7.86.8
Windows HTTP.sys Elevation of Privilege Vulnerability
CVE-2026-20929NoNo--Important7.56.5
Windows Hello Tampering Vulnerability
CVE-2026-20804NoNo--Important7.76.7
CVE-2026-20852NoNo--Important7.76.7
Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-20825NoNo--Important4.43.9
Windows Installer Elevation of Privilege Vulnerability
CVE-2026-20816NoNo--Important7.86.8
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2026-20849NoNo--Important7.56.5
Windows Kerberos Information Disclosure Vulnerability
CVE-2026-20833NoNo--Important5.54.8
Windows Kernel Information Disclosure Vulnerability
CVE-2026-20818NoNo--Important6.25.4
CVE-2026-20838NoNo--Important5.54.8
Windows Kernel Memory Elevation of Privilege Vulnerability
CVE-2026-20809NoNo--Important7.86.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-20859NoNo--Important7.86.8
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2026-20875NoNo--Important7.56.5
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
CVE-2026-20854NoNo--Critical7.56.5
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
CVE-2026-20869NoNo--Important7.06.1
Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20858NoNo--Important7.86.9
CVE-2026-20865NoNo--Important7.86.8
CVE-2026-20877NoNo--Important7.86.8
CVE-2026-20918NoNo--Important7.86.8
CVE-2026-20923NoNo--Important7.86.8
CVE-2026-20924NoNo--Important7.86.8
CVE-2026-20861NoNo--Important7.86.8
CVE-2026-20866NoNo--Important7.86.8
CVE-2026-20867NoNo--Important7.86.8
CVE-2026-20873NoNo--Important7.86.8
CVE-2026-20874NoNo--Important7.86.8
Windows Management Services Information Disclosure Vulnerability
CVE-2026-20862NoNo--Important5.54.8
Windows Media Remote Code Execution Vulnerability
CVE-2026-20837NoNo--Important7.86.8
Windows NDIS Information Disclosure Vulnerability
CVE-2026-20936NoNo--Important4.33.8
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-20840NoNo--Important7.86.8
CVE-2026-20922NoNo--Important7.86.8
Windows Remote Assistance Security Feature Bypass Vulnerability
CVE-2026-20824NoNo--Important5.54.8
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
CVE-2026-20832NoNo--Important7.86.8
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2026-20843NoNo--Important7.86.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-20868NoNo--Important8.87.7
Windows SMB Server Denial of Service Vulnerability
CVE-2026-20927NoNo--Important5.34.6
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20919NoNo--Important7.56.5
CVE-2026-20921NoNo--Important7.56.5
CVE-2026-20926NoNo--Important7.56.5
CVE-2026-20934NoNo--Important7.56.5
CVE-2026-20848NoNo--Important7.56.5
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2026-20856NoNo--Important8.17.1
Windows Spoofing Vulnerability
CVE-2026-20834NoNo--Important4.64.0
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-20931NoNo--Important8.07.0
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20876NoNo--Critical6.75.8
CVE-2026-20938NoNo--Important7.86.8
Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-20819NoNo--Important5.54.8
CVE-2026-20935NoNo--Important6.25.4
Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-20853NoNo--Important7.46.4
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2026-20870NoNo--Important7.86.8
Windows rndismp6.sys Information Disclosure Vulnerability
CVE-2026-20828NoNo--Important4.64.0

Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu

Twitter |

Keywords: microsoft patch Tuesday

0 comment(s)

My next class:

Application Security: Securing Web Apps, APIs, and MicroservicesOrlandoMar 29th - Apr 3rd 2026

Comments

Login here to join the discussion.

Top of page

×

modal content

Diary Archives