Patch Tuesday Archive
Patch Tuesday January 2026
Total CVEs
124
Critical
17
Important
106
Exploited
2
Publicly Disclosed
1
All CVEs this month 124
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2026-20962 | Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability | Important | 4.4 |
Dynamic Root of Trust for Measurement (DRTM) | - | - | - |
| CVE-2026-21265 | Secure Boot Certificate Expiration Security Feature Bypass Vulnerability | Important | 6.4 |
Windows Secure Boot | - | Yes | - |
| CVE-2026-0386 | Windows Deployment Services Remote Code Execution Vulnerability | Important | 7.5 |
Windows Deployment Services | - | - | - |
| CVE-2026-20803 | Microsoft SQL Server Elevation of Privilege Vulnerability | Important | 7.2 |
SQL Server | - | - | - |
| CVE-2026-20965 | Windows Admin Center Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Admin Center | - | - | - |
| CVE-2026-20804 | Windows Hello Tampering Vulnerability | Important | 7.7 |
Windows Hello | - | - | - |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | Important | 5.5 |
Desktop Window Manager | Yes | - | - |
| CVE-2026-20808 | Windows File Explorer Elevation of Privilege Vulnerability | Important | 7 |
Printer Association Object | - | - | - |
| CVE-2026-20809 | Windows Kernel Memory Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel Memory | - | - | - |
| CVE-2026-20810 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-20811 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2026-20812 | LDAP Tampering Vulnerability | Important | 6.5 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2026-20814 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Important | 7 |
Graphics Kernel | - | - | - |
| CVE-2026-20815 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | Important | 7 |
Capability Access Management Service (camsvc) | - | - | - |
| CVE-2026-20816 | Windows Installer Elevation of Privilege Vulnerability | Important | 7 |
Windows Installer | - | - | - |
| CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Error Reporting | - | - | Yes |
| CVE-2026-20818 | Windows Kernel Information Disclosure Vulnerability | Important | 6.2 |
Windows Kernel | - | - | - |
| CVE-2026-20819 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | Important | 5.5 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2026-20820 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Common Log File System Driver | - | - | - |
| CVE-2026-20821 | Remote Procedure Call Information Disclosure Vulnerability | Important | 6.2 |
Windows Remote Procedure Call | - | - | - |
| CVE-2026-20822 | Windows Graphics Component Elevation of Privilege Vulnerability | Critical | 7.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2026-20823 | Windows File Explorer Information Disclosure Vulnerability | Important | 5.5 |
Windows File Explorer | - | - | - |
| CVE-2026-20824 | Windows Remote Assistance Security Feature Bypass Vulnerability | Important | 5.5 |
Windows Remote Assistance | - | - | - |
| CVE-2026-20825 | Windows Hyper-V Information Disclosure Vulnerability | Important | 4.4 |
Windows Hyper-V | - | - | - |
| CVE-2026-20826 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | Important | 7 |
Tablet Windows User Interface (TWINUI) Subsystem | - | - | - |
| CVE-2026-20827 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability | Important | 5.5 |
Tablet Windows User Interface (TWINUI) Subsystem | - | - | - |
| CVE-2026-20828 | Windows rndismp6.sys Information Disclosure Vulnerability | Important | 4.6 |
Windows Internet Connection Sharing (ICS) | - | - | - |
| CVE-2026-20829 | TPM Trustlet Information Disclosure Vulnerability | Important | 5.5 |
Windows TPM | - | - | - |
| CVE-2026-20832 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Procedure Call Interface Definition Language (IDL) | - | - | - |
| CVE-2026-20833 | Windows Kerberos Information Disclosure Vulnerability | Important | 5.5 |
Windows Kerberos | - | - | - |
| CVE-2026-20834 | Windows Spoofing Vulnerability | Important | 4.6 |
Windows Shell | - | - | - |
| CVE-2026-20835 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | Important | 5.5 |
Capability Access Management Service (camsvc) | - | - | - |
| CVE-2026-20836 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Important | 7 |
Graphics Kernel | - | - | - |
| CVE-2026-20837 | Windows Media Remote Code Execution Vulnerability | Important | 7.8 |
Windows Media | - | - | - |
| CVE-2026-20838 | Windows Kernel Information Disclosure Vulnerability | Important | 5.5 |
Windows Kernel | - | - | - |
| CVE-2026-20839 | Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability | Important | 5.5 |
Windows Client-Side Caching (CSC) Service | - | - | - |
| CVE-2026-20840 | Windows NTFS Remote Code Execution Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2026-20842 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Important | 7 |
Windows DWM | - | - | - |
| CVE-2026-20844 | Windows Clipboard Server Elevation of Privilege Vulnerability | Important | 7.4 |
Windows Clipboard Server | - | - | - |
| CVE-2026-20847 | Microsoft Windows File Explorer Spoofing Vulnerability | Important | 6.5 |
Windows Shell | - | - | - |
| CVE-2026-20851 | Capability Access Management Service (camsvc) Information Disclosure Vulnerability | Important | 6.2 |
Capability Access Management Service (camsvc) | - | - | - |
| CVE-2026-20852 | Windows Hello Tampering Vulnerability | Important | 7.7 |
Windows Hello | - | - | - |
| CVE-2026-20856 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Important | 8.1 |
Windows Server Update Service | - | - | - |
| CVE-2026-20857 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2026-20858 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20859 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Kernel-Mode Drivers | - | - | - |
| CVE-2026-20860 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-20864 | Windows Connected Devices Platform Service Elevation of Privilege Vulnerability | Important | 7.8 |
Connected Devices Platform Service (Cdpsvc) | - | - | - |
| CVE-2026-20865 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20869 | Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability | Important | 7 |
Windows Local Session Manager (LSM) | - | - | - |
| CVE-2026-20875 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | Important | 7.5 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2026-20876 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Critical | 6.7 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2026-20877 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20918 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20919 | Windows SMB Server Elevation of Privilege Vulnerability | Important | 7.5 |
Windows SMB Server | - | - | - |
| CVE-2026-20920 | Win32k Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2026-20921 | Windows SMB Server Elevation of Privilege Vulnerability | Important | 7.5 |
Windows SMB Server | - | - | - |
| CVE-2026-20922 | Windows NTFS Remote Code Execution Vulnerability | Important | 7.8 |
Windows NTFS | - | - | - |
| CVE-2026-20923 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20924 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | Important | 6.5 |
Windows NTLM | - | - | - |
| CVE-2026-20926 | Windows SMB Server Elevation of Privilege Vulnerability | Important | 7.5 |
Windows SMB Server | - | - | - |
| CVE-2026-20927 | Windows SMB Server Denial of Service Vulnerability | Important | 5.3 |
Windows SMB Server | - | - | - |
| CVE-2026-20932 | Windows File Explorer Information Disclosure Vulnerability | Important | 5.5 |
Windows File Explorer | - | - | - |
| CVE-2026-20934 | Windows SMB Server Elevation of Privilege Vulnerability | Important | 7.5 |
Windows SMB Server | - | - | - |
| CVE-2026-20938 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2026-20940 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Cloud Files Mini Filter Driver | - | - | - |
| CVE-2026-20943 | Microsoft Office Click-To-Run Remote Code Execution Vulnerability | Important | 7 |
Microsoft Office | - | - | - |
| CVE-2026-20944 | Microsoft Word Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office Word | - | - | - |
| CVE-2026-20946 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-20951 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-20953 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-20955 | Microsoft Excel Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-20956 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-20959 | Microsoft SharePoint Server Spoofing Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | Important | 9.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-20830 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | Important | 7 |
Capability Access Management Service (camsvc) | - | - | - |
| CVE-2026-21221 | Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability | Important | 7 |
Capability Access Management Service (camsvc) | - | - | - |
| CVE-2026-21224 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | Important | 7.8 |
Azure Connected Machine Agent | - | - | - |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-20843 | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2026-20848 | Windows SMB Server Elevation of Privilege Vulnerability | Important | 7.5 |
Windows SMB Server | - | - | - |
| CVE-2026-20849 | Windows Kerberos Elevation of Privilege Vulnerability | Important | 7.5 |
Windows Kerberos | - | - | - |
| CVE-2026-20853 | Windows WalletService Elevation of Privilege Vulnerability | Important | 7.4 |
Windows WalletService | - | - | - |
| CVE-2026-20854 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | Critical | 7.5 |
Windows Local Security Authority Subsystem Service (LSASS) | - | - | - |
| CVE-2026-21219 | Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability | Important | 7 |
Inbox COM Objects | - | - | - |
| CVE-2026-20861 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20862 | Windows Management Services Information Disclosure Vulnerability | Important | 5.5 |
Windows Management Services | - | - | - |
| CVE-2026-20863 | Win32k Elevation of Privilege Vulnerability | Important | 7 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2026-20866 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20867 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20868 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Important | 8.8 |
Windows Routing and Remote Access Service (RRAS) | - | - | - |
| CVE-2026-20870 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Win32K - ICOMP | - | - | - |
| CVE-2026-20871 | Desktop Windows Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Desktop Window Manager | - | - | Yes |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | Important | 6.5 |
Windows NTLM | - | - | - |
| CVE-2026-20873 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20874 | Windows Management Services Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Management Services | - | - | - |
| CVE-2026-20929 | Windows HTTP.sys Elevation of Privilege Vulnerability | Important | 7.5 |
Windows HTTP.sys | - | - | - |
| CVE-2026-20931 | Windows Telephony Service Elevation of Privilege Vulnerability | Important | 8 |
Windows Telephony Service | - | - | - |
| CVE-2026-20935 | Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability | Important | 6.2 |
Windows Virtualization-Based Security (VBS) Enclave | - | - | - |
| CVE-2026-20936 | Windows NDIS Information Disclosure Vulnerability | Important | 4.3 |
Windows NDIS | - | - | - |
| CVE-2026-20937 | Windows File Explorer Information Disclosure Vulnerability | Important | 5.5 |
Windows File Explorer | - | - | - |
| CVE-2026-20939 | Windows File Explorer Information Disclosure Vulnerability | Important | 5.5 |
Windows File Explorer | - | - | - |
| CVE-2026-20948 | Microsoft Word Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Word | - | - | - |
| CVE-2026-20949 | Microsoft Excel Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-20950 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-20952 | Microsoft Office Remote Code Execution Vulnerability | Critical | 8.4 |
Microsoft Office | - | - | - |
| CVE-2026-20957 | Microsoft Excel Remote Code Execution Vulnerability | Critical | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2026-20958 | Microsoft SharePoint Information Disclosure Vulnerability | Important | 5.4 |
Microsoft Office SharePoint | - | - | - |
| CVE-2026-20941 | Host Process for Windows Tasks Elevation of Privilege Vulnerability | Important | 7.8 |
Host Process for Windows Tasks | - | - | - |
| CVE-2026-21226 | Azure Core shared client library for Python Remote Code Execution Vulnerability | Important | 7.5 |
Azure Core shared client library for Python | - | - | - |
| CVE-2026-21223 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Unknown | 7.1 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2026-21520 | Copilot Studio Information Disclosure Vulnerability | Critical | 7.5 |
Copilot Studio | - | - | - |
| CVE-2026-24304 | Azure Resource Manager Elevation of Privilege Vulnerability | Critical | 8.8 |
Azure Resource Manager | - | - | - |
| CVE-2026-24306 | Azure Front Door Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Front Door (AFD) | - | - | - |
| CVE-2026-21524 | Azure Data Explorer Information Disclosure Vulnerability | Critical | 7.4 |
Azure Data Explorer | - | - | - |
| CVE-2026-24305 | Azure Entra ID Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Entra ID | - | - | - |
| CVE-2026-24307 | M365 Copilot Information Disclosure Vulnerability | Critical | 7.5 |
M365 Copilot | - | - | - |
| CVE-2026-21227 | Azure Logic Apps Elevation of Privilege Vulnerability | Critical | 9.8 |
Azure Logic Apps | - | - | - |
| CVE-2026-21521 | Word Copilot Information Disclosure Vulnerability | Critical | 7.4 |
Copilot | - | - | - |
| CVE-2026-21264 | Microsoft Account Spoofing Vulnerability | Critical | 6.1 |
Microsoft Account | - | - | - |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | Important | 7.8 |
Microsoft Office | Yes | - | - |
| CVE-2026-20831 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Important | 7 |
Windows Ancillary Function Driver for WinSock | - | - | - |
| CVE-2026-20960 | PowerApps Desktop Client Remote Code Execution Vulnerability | Important | 8 |
Microsoft Power Apps | - | - | - |
Threat Categories 8
| Threat Category | CVEs | Critical |
|---|---|---|
| Elevation of Privilege | 59 | 6 |
| Information Disclosure | 26 | 4 |
| Remote Code Execution | 23 | 6 |
| Spoofing | 6 | 1 |
| Security Feature Bypass | 4 | - |
| Tampering | 3 | - |
| Denial of Service | 2 | - |
| Unknown | 1 | - |
Affected Products 68
| Product | CVEs | Exploited |
|---|---|---|
| Windows Management Services | 12 | - |
| Microsoft Office Excel | 6 | - |
| Windows SMB Server | 6 | - |
| Capability Access Management Service (camsvc) | 5 | - |
| Microsoft Office SharePoint | 5 | - |
| Microsoft Office | 4 | 1 |
| Windows File Explorer | 4 | - |
| Windows Virtualization-Based Security (VBS) Enclave | 4 | - |
| Windows Win32K - ICOMP | 4 | - |
| Windows Ancillary Function Driver for WinSock | 3 | - |
| Desktop Window Manager | 2 | 1 |
| Graphics Kernel | 2 | - |
| Microsoft Office Word | 2 | - |
| Tablet Windows User Interface (TWINUI) Subsystem | 2 | - |
| Windows Cloud Files Mini Filter Driver | 2 | - |
| Windows Hello | 2 | - |
| Windows Kerberos | 2 | - |
| Windows Kernel | 2 | - |
| Windows Local Security Authority Subsystem Service (LSASS) | 2 | - |
| Windows NTFS | 2 | - |
| Windows NTLM | 2 | - |
| Windows Routing and Remote Access Service (RRAS) | 2 | - |
| Windows Shell | 2 | - |
| Azure Connected Machine Agent | 1 | - |
| Azure Core shared client library for Python | 1 | - |
| Azure Data Explorer | 1 | - |
| Azure Entra ID | 1 | - |
| Azure Front Door (AFD) | 1 | - |
| Azure Logic Apps | 1 | - |
| Azure Resource Manager | 1 | - |
| Connected Devices Platform Service (Cdpsvc) | 1 | - |
| Copilot | 1 | - |
| Copilot Studio | 1 | - |
| Dynamic Root of Trust for Measurement (DRTM) | 1 | - |
| Host Process for Windows Tasks | 1 | - |
| Inbox COM Objects | 1 | - |
| M365 Copilot | 1 | - |
| Microsoft Account | 1 | - |
| Microsoft Edge (Chromium-based) | 1 | - |
| Microsoft Graphics Component | 1 | - |
| Microsoft Power Apps | 1 | - |
| Printer Association Object | 1 | - |
| SQL Server | 1 | - |
| Windows Admin Center | 1 | - |
| Windows Client-Side Caching (CSC) Service | 1 | - |
| Windows Clipboard Server | 1 | - |
| Windows Common Log File System Driver | 1 | - |
| Windows DWM | 1 | - |
| Windows Deployment Services | 1 | - |
| Windows Error Reporting | 1 | - |
| Windows HTTP.sys | 1 | - |
| Windows Hyper-V | 1 | - |
| Windows Installer | 1 | - |
| Windows Internet Connection Sharing (ICS) | 1 | - |
| Windows Kernel Memory | 1 | - |
| Windows Kernel-Mode Drivers | 1 | - |
| Windows LDAP - Lightweight Directory Access Protocol | 1 | - |
| Windows Local Session Manager (LSM) | 1 | - |
| Windows Media | 1 | - |
| Windows NDIS | 1 | - |
| Windows Remote Assistance | 1 | - |
| Windows Remote Procedure Call | 1 | - |
| Windows Remote Procedure Call Interface Definition Language (IDL) | 1 | - |
| Windows Secure Boot | 1 | - |
| Windows Server Update Service | 1 | - |
| Windows TPM | 1 | - |
| Windows Telephony Service | 1 | - |
| Windows WalletService | 1 | - |