Microsoft shipped its January Patch Tuesday security updates for Windows 10 (including ESU/LTSC) and Windows 11, addressing a large set of vulnerabilities and rolling in additional platform hardening changes. Windows 10’s KB5073724 (ESU) updates systems to build 19045.6809 (and LTSC 2021 to 19044.6809) and includes security/bug fixes plus a phased update to handle expiring Secure Boot certificates; it also removes legacy Agere modem drivers (agrsm64.sys, agrsm.sys, smserl64.sys, smserial.sys), which can break dependent modem hardware. Windows 11 cumulative updates KB5074109 (25H2/24H2) and KB5073455 (23H2) are mandatory and include fixes for issues such as WSL mirrored networking failures (“No route to host”) impacting VPN access and RemoteApp connection failures in Azure Virtual Desktop environments.
Third-party analysis of the same Patch Tuesday release reported 112 vulnerabilities (with 8 marked critical) and at least one vulnerability observed exploited in the wild: CVE-2026-20805. The critical issues highlighted include multiple remote code execution vulnerabilities across Windows components and Office applications (including LSASS, Word, Excel, and Office), plus elevation of privilege flaws such as CVE-2026-20822 (Windows Graphics Component, use-after-free leading to potential SYSTEM privileges) and CVE-2026-20854 (LSASS RCE over the network without requiring elevated privileges). Organizations should prioritize rapid deployment of the January Windows updates, with particular attention to exploited-in-the-wild items and critical RCE/EoP paths.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Following the KEV addition, CISA required U.S. federal civilian agencies to remediate CVE-2026-20805 by February 3, 2026. The deadline reflected the vulnerability's active exploitation status.
After Microsoft disclosed the active exploitation of CVE-2026-20805, CISA added the flaw to its Known Exploited Vulnerabilities catalog. The listing made the issue a priority for defenders and federal agencies.
The January 2026 updates started a phased deployment of refreshed Secure Boot certificates to address the upcoming expiration of older certificates. Microsoft also changed rollout behavior to use device targeting data for staged deployment.
As part of the January 2026 Windows updates, Microsoft removed legacy Agere modem drivers and related files tied to an elevation-of-privilege issue, with some reports also noting Motorola soft modem driver removal. Microsoft warned this could break dependent legacy modem hardware.
Microsoft released Windows 10 extended security update KB5073724 for Windows 10 and Enterprise LTSC systems enrolled in the ESU program. The update included January 2026 security fixes, removed specific Agere modem driver files, addressed the WinSqlite DLL issue, and began phased Secure Boot certificate updates.
Microsoft released mandatory Windows 11 cumulative updates KB5074109 and KB5073455 for versions 25H2/24H2 and 23H2. The updates delivered the January 2026 security fixes, removed certain legacy modem drivers, fixed networking and power issues, and changed Secure Boot certificate rollout behavior to phased device targeting.
Alongside the Patch Tuesday release, Microsoft identified eight additional vulnerabilities as more likely to be exploited. These included issues across Windows components such as Installer, Error Reporting, CLFS, NTFS, RRAS, WinSock ancillary driver, and DWM.
The January 2026 updates fixed CVE-2026-20805, an information disclosure flaw in Desktop Window Manager that Microsoft said was being exploited in the wild. The bug can leak memory address information, potentially helping attackers bypass mitigations and chain follow-on attacks.
On January 13, 2026, Microsoft released its January Patch Tuesday updates, addressing 112 Microsoft vulnerabilities across Windows, Office, SharePoint, RRAS, and other products; some reports count 114 when including non-Microsoft or Chromium-related CVEs. The release included eight critical flaws and a large number of elevation-of-privilege and remote code execution issues.
Microsoft had warned since June 2025 that multiple Secure Boot certificates issued in 2011 would expire in 2026. The company said systems that do not receive updated certificates could face Secure Boot failures or weakened protections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
arcticwolf.com
Open sourcetechrepublic.com
Open sourcescworld.com
Open sourcesocradar.io
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.