Back Isc.Sans.Edu January 2026 Microsoft Patch Tuesday Summary, (Tue, Jan 13th)
Today, Microsoft released patches for 113 vulnerabilities. One of these vulnerabilities affected the Edge browser and was patched upstream by Chromium.
Eight of the vulnerabilities are rated critical. One has been disclosed before today, and one is already being exploited. Five of the critical vulnerabilities affect Microsoft Office components.
Noteworthy Vulnerabilities
CVE-2026-20854 : A remote code execution vulnerability in LSASS. This brings back memories from hallmark Windows security events like the Blaster worm. However, in this case, the attacker must be authenticated. But the attacker does not need elevated privileges. Microsoft considers exploitation less likely.
CVE-2026-20805 : This is an information disclosure vulnerability in the Desktop Windows Manager, and it is already being exploited. The vulnerability can be used to identify the section address from a remote ALPC port.
CVE-2026-21265 : Secure boot may not recognize an expired certificate. This problem was already disclosed, but so far hasn't been exploited.
-- Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu Twitter |
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
