Patch today
Exploited in the wild
Confirmed attacks are already happening. Emergency change window.
CVE-2026-21509Microsoft Office Security Feature Bypass VulnerabilityCVE-2026-20805Desktop Window Manager Information Disclosure VulnerabilityMicrosoft's January 2026 Patch Tuesday fixes 125 vulnerabilities across Windows, Microsoft Office and Azure - 17 rated Critical, 2 publicly disclosed before the patch shipped, 2 already exploited in the wild. Patch CVE-2026-21509 first.
Why this number differs from other roundups. Microsoft's January 2026 release document lists 315 entries. 176 are Azure Linux (Mariner) OS package updates and 14 are republished Chromium fixes for Edge - neither is a Microsoft product vulnerability. The 125 above is the real Patch Tuesday set. See the breakdown →
Ranked by exploitation reality, not score alone. This month's exploited flaw is rated Important - a severity-sorted list would bury it.
Patch today
Confirmed attacks are already happening. Emergency change window.
CVE-2026-21509Microsoft Office Security Feature Bypass VulnerabilityCVE-2026-20805Desktop Window Manager Information Disclosure VulnerabilityPatch this week
Details are already public. Working exploits typically follow within days.
CVE-2023-31096MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege VulnerabilityCVE-2026-21265Secure Boot Certificate Expiration Security Feature Bypass VulnerabilityPatch this cycle
No known exploitation yet, but network-reachable and high impact.
CVE-2026-20944Microsoft Word Remote Code Execution VulnerabilityCVE-2026-20952Microsoft Office Remote Code Execution VulnerabilityCVE-2026-20953Microsoft Office Remote Code Execution VulnerabilitySee all 17 Critical →Most roundups quote a single number. These are three unrelated release streams.
Microsoft channel only · 125 CVEs
| Critical | 17 |
|---|---|
| Important | 108 |
| Moderate | 0 |
| Low | 0 |
What an attacker gains if it works
| Elevation of Privilege | 61 |
|---|---|
| Information Disclosure | 26 |
| Remote Code Execution | 23 |
| Spoofing | 6 |
| Security Feature Bypass | 4 |
| Tampering | 3 |
| Denial of Service | 2 |
Where this month’s fixes concentrate - filter by any of them in the table below
Sorted by risk by default: exploited first, then publicly disclosed, then severity, then CVSS. Search by CVE, title, component or KB number.
| Title | Status | KB | |||||
|---|---|---|---|---|---|---|---|
| Important | CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | Bypass | 7.8 | Exploited | Microsoft Office | 5002713 |
| Important | CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | Info Disc. | 5.5 | Exploited | Desktop Window Manager | 5073379 +9 |
| Important | CVE-2023-31096 | MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability | EoP | 7.8 | DisclosedMore likely | Agere Windows Modem Driver | 5073379 +13 |
| Important | CVE-2026-21265 | Secure Boot Certificate Expiration Security Feature Bypass Vulnerability | Bypass | 6.4 | Disclosed | Windows Secure Boot | 5073379 +9 |
| Important | CVE-2026-20816 | Windows Installer Elevation of Privilege Vulnerability | EoP | 7.8 | More likely | Windows Installer | 5073379 +13 |
| Important | CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | EoP | 7.8 | More likely | Windows Error Reporting | 5073379 +5 |
| Important | CVE-2026-20820 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | EoP | 7.8 | More likely | Windows Common Log File System Driver | 5073379 +13 |
| Important | CVE-2026-20840 | Windows NTFS Remote Code Execution Vulnerability | RCE | 7.8 | More likely | Windows NTFS | 5073379 +13 |
| Important | CVE-2026-20843 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | EoP | 7.8 | More likely | Windows Routing and Remote Access Service (RRAS) | 5073379 +13 |
| Important | CVE-2026-20860 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | EoP | 7.8 | More likely | Windows Ancillary Function Driver for WinSock | 5073379 +13 |
| Important | CVE-2026-20871 | Desktop Window Manager Elevation of Privilege Vulnerability | EoP | 7.8 | More likely | Desktop Window Manager | 5073379 +5 |
| Important | CVE-2026-20922 | Windows NTFS Remote Code Execution Vulnerability | RCE | 7.8 | More likely | Windows NTFS | 5073379 +13 |
| Critical | CVE-2026-20944 | Microsoft Word Remote Code Execution Vulnerability | RCE | 8.4 | — | Microsoft Office Word | — |
| Critical | CVE-2026-20952 | Microsoft Office Remote Code Execution Vulnerability | RCE | 8.4 | — | Microsoft Office | 5002826 |
| Critical | CVE-2026-20953 | Microsoft Office Remote Code Execution Vulnerability | RCE | 8.4 | — | Microsoft Office | 5002826 |
| Critical | CVE-2026-20822 | Windows Graphics Component Elevation of Privilege Vulnerability | EoP | 7.8 | — | Microsoft Graphics Component | 5073379 +7 |
| Critical | CVE-2026-20955 | Microsoft Excel Remote Code Execution Vulnerability | RCE | 7.8 | — | Microsoft Office Excel | 5002824 |
| Critical | CVE-2026-20957 | Microsoft Excel Remote Code Execution Vulnerability | RCE | 7.8 | — | Microsoft Office Excel | 5002824 +1 |
| Critical | CVE-2026-20854 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | RCE | 7.5 | — | Windows Local Security Authority Subsystem Service (LSASS) | 5073379 +1 |
| Critical | CVE-2026-20876 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | EoP | 6.7 | — | Windows Virtualization-Based Security (VBS) Enclave | 5073379 +3 |
| Important | CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | RCE | 9.8 | — | Microsoft Office SharePoint | 5002822 +2 |
| Important | CVE-2026-20868 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | RCE | 8.8 | — | Windows Routing and Remote Access Service (RRAS) | 5073379 +13 |
| Important | CVE-2026-20856 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | RCE | 8.1 | — | Windows Server Update Service | 5073379 +9 |
| Important | CVE-2026-20960 | PowerApps Desktop Client Remote Code Execution Vulnerability | RCE | 8.0 | — | Microsoft Power Apps | — |
| Important | CVE-2026-20809 | Windows Kernel Memory Elevation of Privilege Vulnerability | EoP | 7.8 | — | Windows Kernel Memory | 5073379 +8 |
The same five steps every month, in the order that reduces risk fastest.
CVE-2026-21509 is rated Important and scores 7.8 - a CVSS-sorted list would bury the one flaw attackers are already using. Sort by exploited, then publicly disclosed, then severity.
Patch Management vs Vulnerability Management: What's the Difference? →This release means 27 distinct update packages to deploy. Pilot on ring 0 within 24 hours and widen to production by day seven - never push the whole set everywhere at once.
What is Ring-Based Patch Deployment? A Guide to Progressive Rollouts →The Patch Management Lifecycle: 6 Stages from Discovery to Verification →Check the Windows release health dashboard before promoting past ring 1, and have the rollback path written down before you need it. Kernel, networking and authentication fixes are the ones that historically break things.
12 Patch Management Best Practices for 2026 →14 Chromium fixes for Edge shipped alongside this release on their own updater, and Adobe, SAP and Oracle release in the same week. OS-only patching leaves most of your real attack surface untouched.
What is Third-Party Patch Management and Why OS Patching Isn't Enough →Confirm the patch is actually present on each endpoint rather than trusting that "deployment succeeded". Keep the resulting report - it is the artefact auditors ask for, and reconstructing it later is far more work than capturing it now.
Patch Management: The Complete Guide →Trinetri does steps two through five automatically - detecting the 27 KB articles across every endpoint, staging them in rings, verifying installed state and producing the compliance evidence. See patch management →
Every month back to October 2024, with the same breakdown and the full CVE list.
Patch Tuesday falls on the second Tuesday of every month, with updates going live at 10:00 a.m. Pacific Time. Microsoft introduced the practice in October 2003, following the Blaster worm, to cut distribution costs and give administrators a predictable cadence instead of patches arriving at random. The 10:00 a.m. timing is deliberate: it leaves a full working week to remediate before the weekend. Internally Microsoft calls it the "B" release; optional "C" and "D" preview releases follow later in the month. The next Patch Tuesday is September 8, 2026.
Microsoft fixed 125 vulnerabilities in January 2026, across Windows, Microsoft Office, Azure and Apps. 17 are rated Critical, 2 were publicly disclosed before the patch shipped, and 2 were already being exploited. Note that Microsoft's release document lists 315 entries in total, but 176 of those are Azure Linux package updates and 14 are republished Chromium fixes for Edge, which is why other sources sometimes quote a much larger number.
Exploit Wednesday is the day after Patch Tuesday. Attackers compare the newly released patches against the previous version to locate the flaw each one fixes, then build working exploits from that difference - often within 24 to 48 hours. It is the reason the deployment window matters as much as the patch itself: every hour a Critical remote code execution fix sits undeployed is an hour of measurable exposure.
A workable target for most organisations: actively exploited vulnerabilities within 24 hours, publicly disclosed ones within 72 hours, remaining Critical fixes within seven days, and everything else within the month. CISA's Known Exploited Vulnerabilities catalogue sets binding deadlines for US federal agencies and is a reasonable benchmark for everyone else. Stage the rollout in rings rather than deploying everywhere at once, so a regression is caught on a pilot group instead of in production.
An out-of-band update is a patch released outside the monthly cycle because the risk will not wait for the next Patch Tuesday. Microsoft issues them for actively exploited flaws with no mitigation - most famously during the WannaCry outbreak in 2017, when it took the unusual step of patching versions of Windows that were already out of support.
Yes. Adobe aligned its releases with Patch Tuesday in November 2012, and both SAP's Security Patch Day and Oracle's quarterly Critical Patch Updates are coordinated to the same week. Part of the reason is defensive: staggered releases let attackers reverse-engineer one vendor's patch to find the same underlying flaw in another's still-unpatched product. For IT teams it means the second Tuesday is rarely just a Microsoft problem.
Edge is built on Chromium, so most of its security fixes originate with the Chromium project and are republished by Microsoft under their own CVE identifiers. They ship on Chromium's cadence rather than the Patch Tuesday cycle, and they are delivered by Edge's own updater rather than Windows Update. Counting the 14 Edge entries alongside Microsoft product fixes would inflate the headline number and imply work for your Windows Update rings that does not exist.
Experience how Trinetri transforms endpoint chaos into clarity. Try the 30 minute demo session, our experts will walk you through how AI-powered automation, real-time visibility, and unified control can secure your entire hybrid environment, without the overhead.