Listen to this Post

Microsoft has kicked off the January 2026 Patch Tuesday with an extensive set of security updates, addressing 114 vulnerabilities across Windows and related products. Among these, one flaw is actively exploited in the wild, while two zero-days have been publicly disclosed. This month’s updates also include eight Critical vulnerabilities, six of which allow remote code execution (RCE), and two that enable elevation of privilege.
The patches cover a wide spectrum of vulnerability types, including 57 elevation-of-privilege flaws, 22 remote code execution flaws, 22 information disclosure issues, 3 security feature bypasses, 2 denial-of-service vulnerabilities, and 5 spoofing weaknesses. Notably, this count focuses only on Microsoft’s updates released today and does not include recent patches for Microsoft Edge or Mariner.
In addition to security updates, non-security fixes were released for Windows 11 (KB5074109 & KB5073455) and Windows 10 (KB5073724). Organizations are advised to review these cumulative updates to maintain system stability and prevent operational disruption.
Zero-Day Vulnerabilities
January’s Patch Tuesday resolves three zero-day vulnerabilities: one actively exploited and two publicly disclosed.
Actively exploited zero-day (CVE-2026-20805): A Desktop Window Manager information disclosure vulnerability that can allow attackers to read sensitive memory addresses via the remote ALPC port. Microsoft attributed the discovery to MSTIC and MSRC but has not detailed the exploitation method.
Publicly disclosed zero-days (CVE-2026-21265): Windows Secure Boot certificates issued in 2011 are approaching expiration, potentially allowing threat actors to bypass Secure Boot on unpatched systems. The update renews certificates to maintain the Secure Boot trust chain.
In addition, Microsoft removed vulnerable Agere Soft Modem drivers (agrsm64.sys and agrsm.sys) that were previously exploited for privilege escalation.
Updates Beyond Microsoft
Several other vendors issued critical updates this January:
Adobe patched multiple vulnerabilities across its Creative Cloud and Substance 3D suite.
Cisco addressed a publicly exploited ISE flaw.
Fortinet fixed multiple RCE vulnerabilities.
D-Link confirmed an actively exploited vulnerability in end-of-life routers.
Google updated Android to fix a critical DD+ Codec flaw.
SAP patched a 9.9/10 severity code injection flaw in Solution Manager.
ServiceNow disclosed a critical privilege escalation in its AI platform.
Trend Micro fixed an Apex Central vulnerability allowing SYSTEM-level code execution.
Veeam released fixes for critical RCE vulnerabilities in Backup & Replication.
Comprehensive Microsoft Patch List
Microsoft’s January 2026 Patch Tuesday resolves vulnerabilities across Windows, Office, Hyper-V, SQL Server, Win32K, LSASS, NTFS, and more. Critical and important flaws include RCEs in Office Excel, Word, SharePoint, and LSASS, as well as elevation-of-privilege and information disclosure flaws in Windows Kernel, DWM, WinSock, Cloud Files Mini Filter Driver, and VBS Enclave. The updates also address spoofing, tampering, and security feature bypass issues across multiple Windows components.
What Undercode Say:
This month’s Patch Tuesday demonstrates Microsoft’s ongoing commitment to defending against both widely known and actively exploited threats. The Desktop Window Manager zero-day is particularly concerning because information disclosure flaws can serve as stepping stones for privilege escalation and lateral movement within networks. Organizations that delay patching risk exposure to sophisticated attacks.
The Secure Boot certificate expiration underscores a subtle but critical threat: foundational security features can silently degrade over time if updates are not applied. Renewing certificates is essential for maintaining system integrity and preventing attackers from bypassing core security mechanisms.
The removal of Agere Soft Modem drivers is a strong reminder that legacy components continue to present risk. Organizations relying on outdated drivers may be unknowingly vulnerable, even if modern patches are applied elsewhere.
From a broader perspective, the January updates highlight the increasing interconnectivity of software ecosystems. Vendors like Adobe, Cisco, and SAP are all addressing serious vulnerabilities, showing that enterprises need a holistic approach to patch management that extends beyond Microsoft.
Administrators should prioritize patches based on severity and exploitability, but they also need to account for the complexity of dependencies between operating systems, productivity software, and third-party components. Tools for automated patch deployment, vulnerability scanning, and certificate lifecycle management are becoming indispensable for reducing attack surfaces.
The trend toward actively exploited vulnerabilities in zero-days, coupled with publicly disclosed flaws like the Secure Boot issue, reflects the dual nature of modern cyber risk: attackers exploit both known weaknesses and subtle, systemic oversights. Enterprises must balance rapid patch application with thorough testing to avoid operational disruption, particularly in mission-critical environments.
Organizations should also review telemetry and threat intelligence data to identify exposure to zero-day exploits and anticipate emerging threats. Threat actors increasingly leverage advanced techniques that combine privilege escalation, information disclosure, and code execution to bypass conventional defenses.
Overall, January 2026’s Patch Tuesday reinforces a core principle of cybersecurity: proactive, comprehensive, and timely patching is essential. Ignoring updates—even seemingly minor ones—can provide attackers with entry points to compromise entire networks.
Fact Checker Results:
✅ Microsoft patched 114 vulnerabilities, including 1 actively exploited zero-day and 2 publicly disclosed zero-days.
✅ Secure Boot certificate expiration is a real and critical security concern for older systems.
❌ The claim that two zero-days were actively exploited is incorrect; only one was confirmed exploited.
Prediction:
🔮 We anticipate that cybercriminals will focus on unpatched Desktop Window Manager systems in the coming months, leveraging the information disclosure vulnerability for targeted attacks.
🔮 Enterprises ignoring Secure Boot certificate updates may face boot-level bypass attacks, particularly in legacy Windows environments.
🔮 The removal of legacy modem drivers may trigger discovery of other forgotten, vulnerable components, leading to new patch initiatives across enterprise networks.
If you want, I can also create a visual table summarizing all 114 vulnerabilities by severity and type, making it easier for IT teams to prioritize patching. This would be extremely useful for cybersecurity briefings.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




