Microsoft Addresses 114 Windows Vulnerabilities in January 2026 Patch
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
On January 10, 2026, Microsoft issued a significant security update addressing 114 vulnerabilities in Windows, marking it as the third-largest January Patch Tuesday update. Among these, eight vulnerabilities are rated as Critical, and 106 are deemed Important. Notably, CVE-2026-20805, an information disclosure flaw in Desktop Window Manager, is currently being exploited in the wild, allowing attackers to disclose sensitive information.
The vulnerabilities include a total of 58 classified as privilege escalation, 22 for information disclosure, 21 for remote code execution, and five for spoofing. The Microsoft Threat Intelligence Center (MTIC) and Microsoft Security Response Center (MSRC) identified CVE-2026-20805, which has a CVSS score of 5.5. This flaw allows an attacker to access user-mode memory, potentially compromising sensitive data.
In addition to the Windows vulnerabilities, Microsoft also addressed two security flaws in its Edge browser, including CVE-2025-65046 and CVE-2026-0628. The latter has a CVSS score of 8.8 and involves insufficient policy enforcement in Chromium’s WebView tag.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20805 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the latest fixes by February 3, 2026. This underscores the urgency for organizations to address this vulnerability to prevent potential exploitation.
Another significant vulnerability is CVE-2026-21265, which concerns Secure Boot Certificate Expiration, potentially allowing attackers to undermine security mechanisms essential for preventing malware during the boot process. Microsoft has warned that Secure Boot certificates will expire starting June 2026, urging users to update their certificates to avoid disruptions.
The update also removes Agere Soft Modem drivers due to a local privilege escalation flaw (CVE-2023-31096) that could grant SYSTEM permissions to attackers. This follows previous actions by Microsoft to address similar vulnerabilities in Agere Modem drivers.
Implications for Users and Organizations
Given the number of vulnerabilities addressed, users and organizations should prioritize applying these patches to safeguard their systems. The presence of actively exploited vulnerabilities highlights the importance of maintaining up-to-date security measures. Organizations should also review their security settings, especially concerning Secure Boot certificates, to ensure continued protection against potential threats.
Monitoring for updates from Microsoft and other vendors is essential, as vulnerabilities can lead to severe consequences if left unaddressed. Users should remain vigilant and proactive in their cybersecurity practices to mitigate risks associated with these vulnerabilities.
Key Takeaways
- Apply the January 2026 security update from Microsoft to protect against newly discovered vulnerabilities.
- Review and update Secure Boot certificates before the June 2026 expiration to ensure devices boot securely.
- Monitor for updates related to CVE-2026-20805 and other actively exploited vulnerabilities to stay informed.
- Remove any outdated or vulnerable drivers, such as Agere Soft Modem drivers, to reduce security risks.
- Regularly check security settings and configurations to enhance overall system protection.
Key Terms & Concepts
- CVE: CVE stands for Common Vulnerabilities and Exposures, a system for identifying and cataloging vulnerabilities in software.
- DWM: DWM refers to Desktop Window Manager, a Windows service responsible for managing visual effects and rendering on the desktop.
- CISA: CISA stands for the Cybersecurity and Infrastructure Security Agency, a U.S. government agency focused on protecting the nation’s critical infrastructure.
- CVSS: CVSS stands for Common Vulnerability Scoring System, a standardized method for rating the severity of security vulnerabilities.
- Secure Boot: Secure Boot is a security standard that ensures only trusted software is loaded during the boot process to prevent malware.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.