Microsoft January 2026 Patch Tuesday Addresses 3 Zero-Days and 114 Vulnerabilities
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
On January 10, 2026, Microsoft issued its Patch Tuesday update, addressing a total of 117 vulnerabilities, including three zero-days. The zero-day vulnerabilities include CVE-2026-21224, which affects the Azure Connected Machine Agent, and several critical vulnerabilities in Microsoft Office products, such as CVE-2026-20952 and CVE-2026-20953, both of which allow remote code execution.
These vulnerabilities can lead to significant security risks if not patched promptly. For instance, the vulnerabilities in Microsoft Office could allow attackers to execute arbitrary code, potentially compromising sensitive data. Organizations using Azure services should prioritize applying these patches to safeguard their environments.
Key Vulnerabilities Addressed
Among the 114 flaws, many are categorized as important, with several critical vulnerabilities that could lead to severe consequences if exploited. The vulnerabilities span various Microsoft products, including Windows, Microsoft Office, and Azure services, highlighting the need for comprehensive patch management.
- Windows Agere Soft Modem Driver – CVE-2023-31096: Elevation of Privilege Vulnerability.
- Azure Connected Machine Agent – CVE-2026-21224: Elevation of Privilege Vulnerability.
- Microsoft Office – CVE-2026-20952: Remote Code Execution Vulnerability.
- Microsoft Office – CVE-2026-20953: Remote Code Execution Vulnerability.
- Windows Local Security Authority Subsystem Service (LSASS) – CVE-2026-20854: Remote Code Execution Vulnerability.
Organizations must remain vigilant and ensure that their systems are updated regularly to protect against these vulnerabilities. The presence of multiple critical vulnerabilities in widely used applications like Microsoft Office underscores the importance of timely updates.
Key Takeaways
- Ensure all Microsoft products are updated to the latest versions to mitigate vulnerabilities.
- Review and apply the January 2026 Patch Tuesday updates as soon as possible.
- Monitor for any unusual activity in systems that use affected Microsoft products.
- Educate staff about the risks associated with unpatched vulnerabilities and the importance of updates.
- Implement a regular patch management schedule to stay ahead of vulnerabilities.
Key Terms & Concepts
- CVE: CVE stands for Common Vulnerabilities and Exposures, a list of publicly disclosed cybersecurity vulnerabilities.
- Zero-Day: A zero-day vulnerability is a flaw in software that is unknown to the vendor and can be exploited by attackers.
- Remote Code Execution: Remote Code Execution is a type of vulnerability that allows an attacker to execute arbitrary code on a target system.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.