Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: January 2026

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

January 2026 Patch Tuesday: Microsoft fixed 112 vulnerabilities, 8 of them Critical. 1 was already being exploited. Released Tue 13 Jan 2026.

  • 112vulnerabilities fixed
  • 8Critical
  • 1exploited before the fix
  • 1publicly disclosed
  • 2now on CISA KEV

By type: 55 elevation of privilege, 22 remote code execution, 22 information disclosure, 5 spoofing, 3 security feature bypass, 3 tampering, 2 denial of service.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.

CVEWhatSeverityCVSSWhy first
CVE-2026-20963Microsoft SharePoint Remote Code ExecutionImportant9.8On CISA KEV federal deadline 21 Mar
CVE-2026-21265Secure Boot Certificate Expiration Security Feature BypassImportant6.4Publicly disclosed
CVE-2026-20805Desktop Window Manager Information DisclosureImportant5.5Exploited On CISA KEV federal deadline 3 Feb

Critical (8)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2026-20944Microsoft Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-20952Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-20953Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-20822Windows Graphics Component Elevation of PrivilegeElevation of Privilege7.8
CVE-2026-20955Microsoft Excel Remote Code ExecutionRemote Code Execution7.8
CVE-2026-20957Microsoft Excel Remote Code ExecutionRemote Code Execution7.8
CVE-2026-20854Windows Local Security Authority Subsystem Service (LSASS) Remote Code ExecutionRemote Code Execution7.5
CVE-2026-20876Windows Virtualization-Based Security (VBS) Enclave Elevation of PrivilegeElevation of Privilege6.7

Added to CISA KEV in January 2026 (17)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2026-1281Ivanti Endpoint Manager Mobile (EPMM)Code Injection29 Jan1 Feb 2026
CVE-2026-24858Fortinet Multiple ProductsAuthentication Bypass Using an Alternate Path or Channel27 Jan30 Jan 2026
CVE-2018-14634Linux KernelInteger Overflow26 Jan16 Feb 2026
CVE-2025-52691SmarterTools SmarterMailUnrestricted Upload of File with Dangerous Type26 Jan16 Feb 2026Known
CVE-2026-21509Microsoft OfficeSecurity Feature Bypass26 Jan16 Feb 2026
CVE-2026-23760SmarterTools SmarterMailAuthentication Bypass Using an Alternate Path or Channel26 Jan16 Feb 2026Known
CVE-2026-24061GNU InetUtilsArgument Injection26 Jan16 Feb 2026
CVE-2024-37079Broadcom VMware vCenter ServerOut-of-bounds Write23 Jan13 Feb 2026
CVE-2025-31125Vite VitejsImproper Access Control22 Jan12 Feb 2026
CVE-2025-34026Versa ConcertoImproper Authentication22 Jan12 Feb 2026
CVE-2025-54313Prettier eslint-config-prettierEmbedded Malicious Code22 Jan12 Feb 2026
CVE-2025-68645Synacor Zimbra Collaboration Suite (ZCS)Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion22 Jan12 Feb 2026
CVE-2026-20045Cisco Unified Communications ManagerCisco Unified Communications Products Code Injection21 Jan11 Feb 2026
CVE-2026-20805Microsoft WindowsInformation Disclosure13 Jan3 Feb 2026
CVE-2025-8110Gogs GogsGogs Path Traversal12 Jan2 Feb 2026
CVE-2009-0556Microsoft OfficePowerPoint Code Injection7 Jan28 Jan 2026
CVE-2025-37164Hewlett Packard Enterprise (HPE) OneViewCode Injection7 Jan28 Jan 2026

All 112 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2026-20944Microsoft Office WordMicrosoft Word Remote Code ExecutionCritical8.4
CVE-2026-20952Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-20953Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-20822Microsoft Graphics ComponentWindows Graphics Component Elevation of PrivilegeCritical7.8
CVE-2026-20955Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionCritical7.8
CVE-2026-20957Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionCritical7.8
CVE-2026-20854Windows Local Security Authority Subsystem Service (LSASS)Windows Local Security Authority Subsystem Service (LSASS) Remote Code ExecutionCritical7.5
CVE-2026-20876Windows Virtualization-Based Security (VBS) EnclaveWindows Virtualization-Based Security (VBS) Enclave Elevation of PrivilegeCritical6.7
CVE-2026-20963Microsoft Office SharePointMicrosoft SharePoint Remote Code ExecutionImportant9.8
CVE-2026-20868Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Remote Code ExecutionImportant8.8
CVE-2026-20947Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.8
CVE-2026-20856Windows Server Update ServiceWindows Server Update Service (WSUS) Remote Code ExecutionImportant8.1
CVE-2026-20931Windows Telephony ServiceWindows Telephony Service Elevation of PrivilegeImportant8.0
CVE-2026-20809Windows Kernel MemoryWindows Kernel Memory Elevation of PrivilegeImportant7.8
CVE-2026-20810Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-20811Windows Win32K – ICOMPWin32k Elevation of PrivilegeImportant7.8
CVE-2026-20816Windows InstallerWindows Installer Elevation of PrivilegeImportant7.8
CVE-2026-20817Windows Error ReportingWindows Error Reporting Service Elevation of PrivilegeImportant7.8
CVE-2026-20820Windows Common Log File System DriverWindows Common Log File System Driver Elevation of PrivilegeImportant7.8
CVE-2026-20826Tablet Windows User Interface (TWINUI) SubsystemTablet Windows User Interface (TWINUI) Subsystem Information DisclosureImportant7.8
CVE-2026-20831Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-20832Windows Remote Procedure Call Interface Definition Language (IDL)Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of PrivilegeImportant7.8
CVE-2026-20837Windows MediaWindows Media Remote Code ExecutionImportant7.8
CVE-2026-20840Windows NTFSWindows NTFS Remote Code ExecutionImportant7.8
CVE-2026-20843Windows Routing and Remote Access Service (RRAS)Windows Routing and Remote Access Service (RRAS) Elevation of PrivilegeImportant7.8
CVE-2026-20857Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2026-20858Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20859Windows Kernel-Mode DriversWindows Kernel-Mode Driver Elevation of PrivilegeImportant7.8
CVE-2026-20860Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-20861Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20864Connected Devices Platform Service (Cdpsvc)Windows Connected Devices Platform Service Elevation of PrivilegeImportant7.8
CVE-2026-20865Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20866Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20867Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20870Windows Win32K – ICOMPWindows Win32 Kernel Subsystem Elevation of PrivilegeImportant7.8
CVE-2026-20871Desktop Window ManagerDesktop Window Manager Elevation of PrivilegeImportant7.8
CVE-2026-20873Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20874Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20877Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20918Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20920Windows Win32K – ICOMPWin32k Elevation of PrivilegeImportant7.8
CVE-2026-20922Windows NTFSWindows NTFS Remote Code ExecutionImportant7.8
CVE-2026-20923Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20924Windows Management ServicesWindows Management Services Elevation of PrivilegeImportant7.8
CVE-2026-20938Windows Virtualization-Based Security (VBS) EnclaveWindows Virtualization-Based Security (VBS) Enclave Elevation of PrivilegeImportant7.8
CVE-2026-20940Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2026-20941Host Process for Windows TasksHost Process for Windows Tasks Elevation of PrivilegeImportant7.8
CVE-2026-20946Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-20948Microsoft Office WordMicrosoft Word Remote Code ExecutionImportant7.8
CVE-2026-20949Microsoft Office ExcelMicrosoft Excel Security Feature BypassImportant7.8
CVE-2026-20950Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-20951Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant7.8
CVE-2026-20956Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-21224Azure Connected Machine AgentAzure Connected Machine Agent Elevation of PrivilegeImportant7.8
CVE-2026-20804Windows HelloWindows Hello TamperingImportant7.7
CVE-2026-20852Windows HelloWindows Hello TamperingImportant7.7
CVE-2026-0386Windows Deployment ServicesWindows Deployment Services Remote Code ExecutionImportant7.5
CVE-2026-20848Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.5
CVE-2026-20849Windows KerberosWindows Kerberos Elevation of PrivilegeImportant7.5
CVE-2026-20875Windows Local Security Authority Subsystem Service (LSASS)Windows Local Security Authority Subsystem Service (LSASS) Denial of ServiceImportant7.5
CVE-2026-20919Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.5
CVE-2026-20921Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.5
CVE-2026-20926Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.5
CVE-2026-20929Windows HTTP.sysWindows HTTP.sys Elevation of PrivilegeImportant7.5
CVE-2026-20934Windows SMB ServerWindows SMB Server Elevation of PrivilegeImportant7.5
CVE-2026-20965Windows Admin CenterWindows Admin Center Elevation of PrivilegeImportant7.5
CVE-2026-21226Azure Core shared client library for PythonAzure Core shared client library for Python Remote Code ExecutionImportant7.5
CVE-2026-20844Windows Clipboard ServerWindows Clipboard Server Elevation of PrivilegeImportant7.4
CVE-2026-20853Windows WalletServiceWindows WalletService Elevation of PrivilegeImportant7.4
CVE-2026-20803SQL ServerMicrosoft SQL Server Elevation of PrivilegeImportant7.2
CVE-2026-20808Printer Association ObjectWindows File Explorer Elevation of PrivilegeImportant7.0
CVE-2026-20814Windows Graphics KernelDirectX Graphics Kernel Elevation of PrivilegeImportant7.0
CVE-2026-20815Capability Access Management Service (camsvc)Capability Access Management Service (camsvc) Elevation of PrivilegeImportant7.0
CVE-2026-20830Capability Access Management Service (camsvc)Capability Access Management Service (camsvc) Elevation of PrivilegeImportant7.0
CVE-2026-20836Windows Graphics KernelDirectX Graphics Kernel Elevation of PrivilegeImportant7.0
CVE-2026-20842Windows DWMMicrosoft DWM Core Library Elevation of PrivilegeImportant7.0
CVE-2026-20863Windows Win32K – ICOMPWin32k Elevation of PrivilegeImportant7.0
CVE-2026-20869Windows Local Session Manager (LSM)Windows Local Session Manager (LSM) Elevation of PrivilegeImportant7.0
CVE-2026-20943Microsoft OfficeMicrosoft Office Click-To-Run Remote Code ExecutionImportant7.0
CVE-2026-21219Inbox COM ObjectsInbox COM Objects (Global Memory) Remote Code ExecutionImportant7.0
CVE-2026-21221Capability Access Management Service (camsvc)Capability Access Management Service (camsvc) Elevation of PrivilegeImportant7.0
CVE-2026-20812Windows LDAP – Lightweight Directory Access ProtocolLDAP TamperingImportant6.5
CVE-2026-20847Windows ShellMicrosoft Windows File Explorer SpoofingImportant6.5
CVE-2026-20872Windows NTLMNTLM Hash Disclosure SpoofingImportant6.5
CVE-2026-20925Windows NTLMNTLM Hash Disclosure SpoofingImportant6.5
CVE-2026-21265Windows Secure BootSecure Boot Certificate Expiration Security Feature BypassImportant6.4
CVE-2026-20818Windows KernelWindows Kernel Information DisclosureImportant6.2
CVE-2026-20821Windows Remote Procedure CallRemote Procedure Call Information DisclosureImportant6.2
CVE-2026-20851Capability Access Management Service (camsvc)Capability Access Management Service (camsvc) Information DisclosureImportant6.2
CVE-2026-20935Windows Virtualization-Based Security (VBS) EnclaveWindows Virtualization-Based Security (VBS) Information DisclosureImportant6.2
CVE-2026-20805Desktop Window ManagerDesktop Window Manager Information DisclosureImportant5.5
CVE-2026-20819Windows Virtualization-Based Security (VBS) EnclaveWindows Virtualization-Based Security (VBS) Information DisclosureImportant5.5
CVE-2026-20823Windows File ExplorerWindows File Explorer Information DisclosureImportant5.5
CVE-2026-20824Windows Remote AssistanceWindows Remote Assistance Security Feature BypassImportant5.5
CVE-2026-20827Tablet Windows User Interface (TWINUI) SubsystemTablet Windows User Interface (TWINUI) Subsystem Information DisclosureImportant5.5
CVE-2026-20829Windows TPMTPM Trustlet Information DisclosureImportant5.5
CVE-2026-20833Windows KerberosWindows Kerberos Information DisclosureImportant5.5
CVE-2026-20835Capability Access Management Service (camsvc)Capability Access Management Service (camsvc) Information DisclosureImportant5.5
CVE-2026-20838Windows KernelWindows Kernel Information DisclosureImportant5.5
CVE-2026-20839Windows Client-Side Caching (CSC) ServiceWindows Client-Side Caching (CSC) Service Information DisclosureImportant5.5
CVE-2026-20862Windows Management ServicesWindows Management Services Information DisclosureImportant5.5
CVE-2026-20932Windows File ExplorerWindows File Explorer Information DisclosureImportant5.5
CVE-2026-20937Windows File ExplorerWindows File Explorer Information DisclosureImportant5.5
CVE-2026-20939Windows File ExplorerWindows File Explorer Information DisclosureImportant5.5
CVE-2026-20958Microsoft Office SharePointMicrosoft SharePoint Information DisclosureImportant5.4
CVE-2026-20927Windows SMB ServerWindows SMB Server Denial of ServiceImportant5.3
CVE-2026-20828Windows Internet Connection Sharing (ICS)Windows rndismp6.sys Information DisclosureImportant4.6
CVE-2026-20834Windows ShellWindows SpoofingImportant4.6
CVE-2026-20959Microsoft Office SharePointMicrosoft SharePoint Server SpoofingImportant4.6
CVE-2026-20825Windows Hyper-VWindows Hyper-V Information DisclosureImportant4.4
CVE-2026-20962Dynamic Root of Trust for Measurement (DRTM)Dynamic Root of Trust for Measurement (DRTM) Information DisclosureImportant4.4
CVE-2026-20936Windows NDISWindows NDIS Information DisclosureImportant4.3

Published later in the month (12)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
22 JanCVE-2026-24304Azure Resource Manager Elevation of PrivilegeCriticalFixed by Microsoft
22 JanCVE-2026-24306Azure Front Door Elevation of PrivilegeCriticalFixed by Microsoft
22 JanCVE-2026-21264Microsoft Account SpoofingCriticalFixed by Microsoft
22 JanCVE-2026-24305Azure Entra ID Elevation of PrivilegeCriticalFixed by Microsoft
22 JanCVE-2026-24307M365 Copilot Information DisclosureCriticalFixed by Microsoft
22 JanCVE-2026-21227Azure Logic Apps Elevation of PrivilegeCriticalFixed by Microsoft
22 JanCVE-2026-21520Copilot Studio Information DisclosureCriticalFixed by Microsoft
22 JanCVE-2026-21521Word Copilot Information DisclosureCriticalFixed by Microsoft
22 JanCVE-2026-21524Azure Data Explorer Information DisclosureCriticalFixed by Microsoft
16 JanCVE-2026-20960PowerApps Desktop Client Remote Code ExecutionImportantUpdate
26 JanCVE-2026-21509Microsoft Office Security Feature BypassImportantUpdate
16 JanCVE-2026-21223Microsoft Edge (Chromium-based) Security Feature BypassImportantUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 6 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools