Microsoft’s January Patch Tuesday security updates addressed 114 vulnerabilities, including three zero-days reported as publicly known and/or exploited. Reported issues span multiple Windows and Microsoft product components, including Desktop Window Manager (DWM), legacy modem drivers, and core OS services, with a mix of information disclosure, elevation of privilege (EoP), security feature bypass, and remote code execution (RCE) flaws.
Technical highlights called out include CVE-2023-31096 (Windows Agere Soft Modem Driver EoP), CVE-2026-20805 (DWM information disclosure), and a Secure Boot certificate expiration security feature bypass (CVE-2026-21265). The update set also includes multiple Office/Excel/Word RCE vulnerabilities (e.g., CVE-2026-20952, CVE-2026-20953, CVE-2026-20955, CVE-2026-20957, CVE-2026-20944), Windows privilege-escalation issues (e.g., Windows Graphics Component and VBS Enclave EoP), and cloud/agent components such as Azure Connected Machine Agent (CVE-2026-21224) and Azure Core shared client library for Python (CVE-2026-21226).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The January 2026 security updates identify CVE-2026-20805 as exploited in the wild. Reporting indicates the flaw affects a wide range of Windows client and server versions, making it the most clearly active zero-day in the release.
On January 13, 2026, Microsoft released its January Patch Tuesday security updates addressing 114 vulnerabilities across Windows, Office, SharePoint, Azure components, Edge/WebView, and other products. Multiple sources describe the release as including three zero-day flaws.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
arcticwolf.com
Open sourcethezdi.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.