How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
January 2026 Patch Tuesday: Microsoft fixed 112 vulnerabilities, 8 of them Critical. 1 was already being exploited. Released Tue 13 Jan 2026.
- 112vulnerabilities fixed
- 8Critical
- 1exploited before the fix
- 1publicly disclosed
- 2now on CISA KEV
By type: 55 elevation of privilege, 22 remote code execution, 22 information disclosure, 5 spoofing, 3 security feature bypass, 3 tampering, 2 denial of service.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Being exploited, already public, or on CISA’s list of vulnerabilities attackers are using. Whatever else waits for testing, these should not.
| CVE | What | Severity | CVSS | Why first |
|---|---|---|---|---|
CVE-2026-20963 | Microsoft SharePoint Remote Code Execution | Important | 9.8 | On CISA KEV federal deadline 21 Mar |
CVE-2026-21265 | Secure Boot Certificate Expiration Security Feature Bypass | Important | 6.4 | Publicly disclosed |
CVE-2026-20805 | Desktop Window Manager Information Disclosure | Important | 5.5 | Exploited On CISA KEV federal deadline 3 Feb |
Critical (8)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2026-20944 | Microsoft Word Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-20952 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-20953 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-20822 | Windows Graphics Component Elevation of Privilege | Elevation of Privilege | 7.8 |
CVE-2026-20955 | Microsoft Excel Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-20957 | Microsoft Excel Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-20854 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution | Remote Code Execution | 7.5 |
CVE-2026-20876 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege | Elevation of Privilege | 6.7 |
Added to CISA KEV in January 2026 (17)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) | Code Injection | 29 Jan | 1 Feb 2026 | |
CVE-2026-24858 | Fortinet Multiple Products | Authentication Bypass Using an Alternate Path or Channel | 27 Jan | 30 Jan 2026 | |
CVE-2018-14634 | Linux Kernel | Integer Overflow | 26 Jan | 16 Feb 2026 | |
CVE-2025-52691 | SmarterTools SmarterMail | Unrestricted Upload of File with Dangerous Type | 26 Jan | 16 Feb 2026 | Known |
CVE-2026-21509 | Microsoft Office | Security Feature Bypass | 26 Jan | 16 Feb 2026 | |
CVE-2026-23760 | SmarterTools SmarterMail | Authentication Bypass Using an Alternate Path or Channel | 26 Jan | 16 Feb 2026 | Known |
CVE-2026-24061 | GNU InetUtils | Argument Injection | 26 Jan | 16 Feb 2026 | |
CVE-2024-37079 | Broadcom VMware vCenter Server | Out-of-bounds Write | 23 Jan | 13 Feb 2026 | |
CVE-2025-31125 | Vite Vitejs | Improper Access Control | 22 Jan | 12 Feb 2026 | |
CVE-2025-34026 | Versa Concerto | Improper Authentication | 22 Jan | 12 Feb 2026 | |
CVE-2025-54313 | Prettier eslint-config-prettier | Embedded Malicious Code | 22 Jan | 12 Feb 2026 | |
CVE-2025-68645 | Synacor Zimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion | 22 Jan | 12 Feb 2026 | |
CVE-2026-20045 | Cisco Unified Communications Manager | Cisco Unified Communications Products Code Injection | 21 Jan | 11 Feb 2026 | |
CVE-2026-20805 | Microsoft Windows | Information Disclosure | 13 Jan | 3 Feb 2026 | |
CVE-2025-8110 | Gogs Gogs | Gogs Path Traversal | 12 Jan | 2 Feb 2026 | |
CVE-2009-0556 | Microsoft Office | PowerPoint Code Injection | 7 Jan | 28 Jan 2026 | |
CVE-2025-37164 | Hewlett Packard Enterprise (HPE) OneView | Code Injection | 7 Jan | 28 Jan 2026 |
All 112 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2026-20944 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 8.4 |
CVE-2026-20952 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-20953 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-20822 | Microsoft Graphics Component | Windows Graphics Component Elevation of Privilege | Critical | 7.8 |
CVE-2026-20955 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Critical | 7.8 |
CVE-2026-20957 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Critical | 7.8 |
CVE-2026-20854 | Windows Local Security Authority Subsystem Service (LSASS) | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution | Critical | 7.5 |
CVE-2026-20876 | Windows Virtualization-Based Security (VBS) Enclave | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege | Critical | 6.7 |
CVE-2026-20963 | Microsoft Office SharePoint | Microsoft SharePoint Remote Code Execution | Important | 9.8 |
CVE-2026-20868 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Remote Code Execution | Important | 8.8 |
CVE-2026-20947 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-20856 | Windows Server Update Service | Windows Server Update Service (WSUS) Remote Code Execution | Important | 8.1 |
CVE-2026-20931 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 8.0 |
CVE-2026-20809 | Windows Kernel Memory | Windows Kernel Memory Elevation of Privilege | Important | 7.8 |
CVE-2026-20810 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-20811 | Windows Win32K – ICOMP | Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-20816 | Windows Installer | Windows Installer Elevation of Privilege | Important | 7.8 |
CVE-2026-20817 | Windows Error Reporting | Windows Error Reporting Service Elevation of Privilege | Important | 7.8 |
CVE-2026-20820 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-20826 | Tablet Windows User Interface (TWINUI) Subsystem | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure | Important | 7.8 |
CVE-2026-20831 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-20832 | Windows Remote Procedure Call Interface Definition Language (IDL) | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege | Important | 7.8 |
CVE-2026-20837 | Windows Media | Windows Media Remote Code Execution | Important | 7.8 |
CVE-2026-20840 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-20843 | Windows Routing and Remote Access Service (RRAS) | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege | Important | 7.8 |
CVE-2026-20857 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-20858 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20859 | Windows Kernel-Mode Drivers | Windows Kernel-Mode Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-20860 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-20861 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20864 | Connected Devices Platform Service (Cdpsvc) | Windows Connected Devices Platform Service Elevation of Privilege | Important | 7.8 |
CVE-2026-20865 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20866 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20867 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20870 | Windows Win32K – ICOMP | Windows Win32 Kernel Subsystem Elevation of Privilege | Important | 7.8 |
CVE-2026-20871 | Desktop Window Manager | Desktop Window Manager Elevation of Privilege | Important | 7.8 |
CVE-2026-20873 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20874 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20877 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20918 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20920 | Windows Win32K – ICOMP | Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-20922 | Windows NTFS | Windows NTFS Remote Code Execution | Important | 7.8 |
CVE-2026-20923 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20924 | Windows Management Services | Windows Management Services Elevation of Privilege | Important | 7.8 |
CVE-2026-20938 | Windows Virtualization-Based Security (VBS) Enclave | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege | Important | 7.8 |
CVE-2026-20940 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-20941 | Host Process for Windows Tasks | Host Process for Windows Tasks Elevation of Privilege | Important | 7.8 |
CVE-2026-20946 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-20948 | Microsoft Office Word | Microsoft Word Remote Code Execution | Important | 7.8 |
CVE-2026-20949 | Microsoft Office Excel | Microsoft Excel Security Feature Bypass | Important | 7.8 |
CVE-2026-20950 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-20951 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 7.8 |
CVE-2026-20956 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-21224 | Azure Connected Machine Agent | Azure Connected Machine Agent Elevation of Privilege | Important | 7.8 |
CVE-2026-20804 | Windows Hello | Windows Hello Tampering | Important | 7.7 |
CVE-2026-20852 | Windows Hello | Windows Hello Tampering | Important | 7.7 |
CVE-2026-0386 | Windows Deployment Services | Windows Deployment Services Remote Code Execution | Important | 7.5 |
CVE-2026-20848 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.5 |
CVE-2026-20849 | Windows Kerberos | Windows Kerberos Elevation of Privilege | Important | 7.5 |
CVE-2026-20875 | Windows Local Security Authority Subsystem Service (LSASS) | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service | Important | 7.5 |
CVE-2026-20919 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.5 |
CVE-2026-20921 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.5 |
CVE-2026-20926 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.5 |
CVE-2026-20929 | Windows HTTP.sys | Windows HTTP.sys Elevation of Privilege | Important | 7.5 |
CVE-2026-20934 | Windows SMB Server | Windows SMB Server Elevation of Privilege | Important | 7.5 |
CVE-2026-20965 | Windows Admin Center | Windows Admin Center Elevation of Privilege | Important | 7.5 |
CVE-2026-21226 | Azure Core shared client library for Python | Azure Core shared client library for Python Remote Code Execution | Important | 7.5 |
CVE-2026-20844 | Windows Clipboard Server | Windows Clipboard Server Elevation of Privilege | Important | 7.4 |
CVE-2026-20853 | Windows WalletService | Windows WalletService Elevation of Privilege | Important | 7.4 |
CVE-2026-20803 | SQL Server | Microsoft SQL Server Elevation of Privilege | Important | 7.2 |
CVE-2026-20808 | Printer Association Object | Windows File Explorer Elevation of Privilege | Important | 7.0 |
CVE-2026-20814 | Windows Graphics Kernel | DirectX Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-20815 | Capability Access Management Service (camsvc) | Capability Access Management Service (camsvc) Elevation of Privilege | Important | 7.0 |
CVE-2026-20830 | Capability Access Management Service (camsvc) | Capability Access Management Service (camsvc) Elevation of Privilege | Important | 7.0 |
CVE-2026-20836 | Windows Graphics Kernel | DirectX Graphics Kernel Elevation of Privilege | Important | 7.0 |
CVE-2026-20842 | Windows DWM | Microsoft DWM Core Library Elevation of Privilege | Important | 7.0 |
CVE-2026-20863 | Windows Win32K – ICOMP | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-20869 | Windows Local Session Manager (LSM) | Windows Local Session Manager (LSM) Elevation of Privilege | Important | 7.0 |
CVE-2026-20943 | Microsoft Office | Microsoft Office Click-To-Run Remote Code Execution | Important | 7.0 |
CVE-2026-21219 | Inbox COM Objects | Inbox COM Objects (Global Memory) Remote Code Execution | Important | 7.0 |
CVE-2026-21221 | Capability Access Management Service (camsvc) | Capability Access Management Service (camsvc) Elevation of Privilege | Important | 7.0 |
CVE-2026-20812 | Windows LDAP – Lightweight Directory Access Protocol | LDAP Tampering | Important | 6.5 |
CVE-2026-20847 | Windows Shell | Microsoft Windows File Explorer Spoofing | Important | 6.5 |
CVE-2026-20872 | Windows NTLM | NTLM Hash Disclosure Spoofing | Important | 6.5 |
CVE-2026-20925 | Windows NTLM | NTLM Hash Disclosure Spoofing | Important | 6.5 |
CVE-2026-21265 | Windows Secure Boot | Secure Boot Certificate Expiration Security Feature Bypass | Important | 6.4 |
CVE-2026-20818 | Windows Kernel | Windows Kernel Information Disclosure | Important | 6.2 |
CVE-2026-20821 | Windows Remote Procedure Call | Remote Procedure Call Information Disclosure | Important | 6.2 |
CVE-2026-20851 | Capability Access Management Service (camsvc) | Capability Access Management Service (camsvc) Information Disclosure | Important | 6.2 |
CVE-2026-20935 | Windows Virtualization-Based Security (VBS) Enclave | Windows Virtualization-Based Security (VBS) Information Disclosure | Important | 6.2 |
CVE-2026-20805 | Desktop Window Manager | Desktop Window Manager Information Disclosure | Important | 5.5 |
CVE-2026-20819 | Windows Virtualization-Based Security (VBS) Enclave | Windows Virtualization-Based Security (VBS) Information Disclosure | Important | 5.5 |
CVE-2026-20823 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-20824 | Windows Remote Assistance | Windows Remote Assistance Security Feature Bypass | Important | 5.5 |
CVE-2026-20827 | Tablet Windows User Interface (TWINUI) Subsystem | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure | Important | 5.5 |
CVE-2026-20829 | Windows TPM | TPM Trustlet Information Disclosure | Important | 5.5 |
CVE-2026-20833 | Windows Kerberos | Windows Kerberos Information Disclosure | Important | 5.5 |
CVE-2026-20835 | Capability Access Management Service (camsvc) | Capability Access Management Service (camsvc) Information Disclosure | Important | 5.5 |
CVE-2026-20838 | Windows Kernel | Windows Kernel Information Disclosure | Important | 5.5 |
CVE-2026-20839 | Windows Client-Side Caching (CSC) Service | Windows Client-Side Caching (CSC) Service Information Disclosure | Important | 5.5 |
CVE-2026-20862 | Windows Management Services | Windows Management Services Information Disclosure | Important | 5.5 |
CVE-2026-20932 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-20937 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-20939 | Windows File Explorer | Windows File Explorer Information Disclosure | Important | 5.5 |
CVE-2026-20958 | Microsoft Office SharePoint | Microsoft SharePoint Information Disclosure | Important | 5.4 |
CVE-2026-20927 | Windows SMB Server | Windows SMB Server Denial of Service | Important | 5.3 |
CVE-2026-20828 | Windows Internet Connection Sharing (ICS) | Windows rndismp6.sys Information Disclosure | Important | 4.6 |
CVE-2026-20834 | Windows Shell | Windows Spoofing | Important | 4.6 |
CVE-2026-20959 | Microsoft Office SharePoint | Microsoft SharePoint Server Spoofing | Important | 4.6 |
CVE-2026-20825 | Windows Hyper-V | Windows Hyper-V Information Disclosure | Important | 4.4 |
CVE-2026-20962 | Dynamic Root of Trust for Measurement (DRTM) | Dynamic Root of Trust for Measurement (DRTM) Information Disclosure | Important | 4.4 |
CVE-2026-20936 | Windows NDIS | Windows NDIS Information Disclosure | Important | 4.3 |
Published later in the month (12)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 22 Jan | CVE-2026-24304 | Azure Resource Manager Elevation of Privilege | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-24306 | Azure Front Door Elevation of Privilege | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-21264 | Microsoft Account Spoofing | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-24305 | Azure Entra ID Elevation of Privilege | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-24307 | M365 Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-21227 | Azure Logic Apps Elevation of Privilege | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-21520 | Copilot Studio Information Disclosure | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-21521 | Word Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 22 Jan | CVE-2026-21524 | Azure Data Explorer Information Disclosure | Critical | Fixed by Microsoft |
| 16 Jan | CVE-2026-20960 | PowerApps Desktop Client Remote Code Execution | Important | Update |
| 26 Jan | CVE-2026-21509 | Microsoft Office Security Feature Bypass | Important | Update |
| 16 Jan | CVE-2026-21223 | Microsoft Edge (Chromium-based) Security Feature Bypass | Important | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 6 hours ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.