Skip to main content
QUIETLYTIC
Advisory

Microsoft Patch Tuesday January 2026: 315 Vulnerabilities Fixed

Microsoft's January 13, 2026 Patch Tuesday fixed 315 vulnerabilities (29 critical, 151 important) — none are currently listed as actively exploited, per CISA…

Microsoft Patch Tuesday January 2026: 315 Vulnerabilities Fixed — Advisory research covering CVE-2026-24304, CVE-2025-68789, CVE-2025-68814, CVE-2025-68819, CVE-2025-68822, CVE-2025-68823, CVE-2025-71064, CVE-2025-71066, CVE-2025-71072, CVE-2025-71073, CVE-2025-71098, CVE-2026-24306, CVE-2026-21264, CVE-2026-24305, CVE-2026-24307, CVE-2026-20944, CVE-2026-20952, CVE-2026-20953, CVE-2026-21227, CVE-2026-22184, CVE-2026-20822, CVE-2026-20955, CVE-2026-20957, CVE-2026-20854, CVE-2026-21520, CVE-2026-21521, CVE-2026-21524, CVE-2026-20876, CVE-2026-24821, CVE-2026-20963, CVE-2025-69194, CVE-2026-20868, CVE-2026-20947, CVE-2025-15444, CVE-2025-68782, CVE-2025-62291, CVE-2026-20856, CVE-2026-20931, CVE-2026-20960, CVE-2025-61731, CVE-2025-68753, CVE-2025-68786, CVE-2025-68801, CVE-2025-68817, CVE-2025-71068, CVE-2025-71089, CVE-2025-71101, CVE-2025-71122, CVE-2025-71152, CVE-2025-71162, CVE-2026-22980, CVE-2023-31096, CVE-2024-55414, CVE-2026-20809, CVE-2026-20810, CVE-2026-20811, CVE-2026-20816, CVE-2026-20817, CVE-2026-20820, CVE-2026-20826, CVE-2026-20831, CVE-2026-20832, CVE-2026-20837, CVE-2026-20840, CVE-2026-20843, CVE-2026-20857, CVE-2026-20858, CVE-2026-20859, CVE-2026-20860, CVE-2026-20861, CVE-2026-20864, CVE-2026-20865, CVE-2026-20866, CVE-2026-20867, CVE-2026-20870, CVE-2026-20871, CVE-2026-20873, CVE-2026-20874, CVE-2026-20877, CVE-2026-20918, CVE-2026-20920, CVE-2026-20922, CVE-2026-20923, CVE-2026-20924, CVE-2026-20938, CVE-2026-20940, CVE-2026-20941, CVE-2026-20946, CVE-2026-20948, CVE-2026-20949, CVE-2026-20950, CVE-2026-20951, CVE-2026-20956, CVE-2026-21224, CVE-2026-21509, CVE-2026-20804, CVE-2026-20852, CVE-2025-69195, CVE-2025-61726, CVE-2026-0719, CVE-2026-0897, CVE-2026-21441, CVE-2026-23490, CVE-2026-0386, CVE-2026-20848, CVE-2026-20849, CVE-2026-20875, CVE-2026-20919, CVE-2026-20921, CVE-2026-20926, CVE-2026-20929, CVE-2026-20934, CVE-2026-20965, CVE-2026-21226, CVE-2026-20844, CVE-2026-20853, CVE-2026-20803, CVE-2025-68756, CVE-2025-68759, CVE-2025-68766, CVE-2025-68771, CVE-2025-68785, CVE-2025-68795, CVE-2025-68808, CVE-2025-71067, CVE-2025-71081, CVE-2025-71082, CVE-2025-71087, CVE-2025-71105, CVE-2025-71114, CVE-2025-71130, CVE-2025-71133, CVE-2025-71143, CVE-2026-22984, CVE-2025-68119, CVE-2025-68781, CVE-2025-71075, CVE-2026-20808, CVE-2026-20814, CVE-2026-20815, CVE-2026-20830, CVE-2026-20836, CVE-2026-20842, CVE-2026-20863, CVE-2026-20869, CVE-2026-20943, CVE-2026-21219, CVE-2026-21221, CVE-2026-20812, CVE-2026-20847
Severity
Critical
Confidence
High
Status
Active

Full CVE Roster

All 150 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 3 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability 9.9 critical
CVE-2025-68789 hwmon: (ibmpex) fix use-after-free in high/low store 9.8 critical
CVE-2025-68814 io_uring: fix filename leak in __io_openat_prep() 9.8 critical
CVE-2025-68819 media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() 9.8 critical
CVE-2025-68822 Input: alps - fix use-after-free bugs caused by dev3_register_work 9.8 critical
CVE-2025-68823 ublk: fix deadlock when reading partition table 9.8 critical
CVE-2025-71064 net: hns3: using the num_tqps in the vf driver to apply for resources 9.8 critical
CVE-2025-71066 net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change 9.8 critical
CVE-2025-71072 shmem: fix recovery on rename failures 9.8 critical
CVE-2025-71073 Input: lkkbd - disable pending work before freeing device 9.8 critical
CVE-2025-71098 ip6_gre: make ip6gre_header() robust 9.8 critical
CVE-2026-24306 Azure Front Door Elevation of Privilege Vulnerability 9.8 critical
CVE-2026-21264 Microsoft Account Spoofing Vulnerability 9.3 critical
CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability 9.3 critical
CVE-2026-24307 M365 Copilot Information Disclosure Vulnerability 9.3 critical
CVE-2026-20944 Microsoft Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-20952 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-20953 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-21227 Azure Logic Apps Elevation of Privilege Vulnerability 8.2 critical
CVE-2026-22184 zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname() 7.8 critical
CVE-2026-20822 Windows Graphics Component Elevation of Privilege Vulnerability 7.8 critical
CVE-2026-20955 Microsoft Excel Remote Code Execution Vulnerability 7.8 critical
CVE-2026-20957 Microsoft Excel Remote Code Execution Vulnerability 7.8 critical
CVE-2026-20854 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability 7.5 critical
CVE-2026-21520 Copilot Studio Information Disclosure Vulnerability 7.5 critical
CVE-2026-21521 Word Copilot Information Disclosure Vulnerability 7.4 critical
CVE-2026-21524 Azure Data Explorer Information Disclosure Vulnerability 7.4 critical
CVE-2026-20876 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability 6.7 critical
CVE-2026-24821 A heap-based buffer over-read that might affect a system that compiles untrusted Lua code in turanszkij/WickedEngine. — critical
CVE-2026-20963 Microsoft SharePoint Remote Code Execution Vulnerability 9.8 high Yes
CVE-2025-69194 Wget2: arbitrary file write via metalink path traversal in gnu wget2 8.8 high
CVE-2026-20868 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.8 high
CVE-2026-20947 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 high
CVE-2025-15444 Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium 8.6 high
CVE-2025-68782 scsi: target: Reset t_task_cdb pointer in error case 8.6 high
CVE-2025-62291 In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow. 8.1 high
CVE-2026-20856 Windows Server Update Service (WSUS) Remote Code Execution Vulnerability 8.1 high
CVE-2026-20931 Windows Telephony Service Elevation of Privilege Vulnerability 8.0 high Yes
CVE-2026-20960 PowerApps Desktop Client Remote Code Execution Vulnerability 8.0 high
CVE-2025-61731 Arbitrary file write using cgo pkg-config directive in cmd/go 7.8 high
CVE-2025-68753 ALSA: firewire-motu: add bounds check in put_user loop for DSP events 7.8 high
CVE-2025-68786 ksmbd: skip lock-range check on equal size to avoid size==0 underflow 7.8 high
CVE-2025-68801 mlxsw: spectrum_router: Fix neighbour use-after-free 7.8 high
CVE-2025-68817 ksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency 7.8 high
CVE-2025-71068 svcrdma: bound check rq_pages index in inline path 7.8 high
CVE-2025-71089 iommu: disable SVA when CONFIG_X86 is set 7.8 high
CVE-2025-71101 platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing 7.8 high
CVE-2025-71122 iommufd/selftest: Check for overflow in IOMMU_TEST_OP_ADD_RESERVED 7.8 high
CVE-2025-71152 net: dsa: properly keep track of conduit reference 7.8 high
CVE-2025-71162 dmaengine: tegra-adma: Fix use-after-free 7.8 high
CVE-2026-22980 nfsd: provide locking for v4_end_grace 7.8 high
CVE-2023-31096 MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2024-55414 Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20809 Windows Kernel Memory Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20810 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20811 Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20816 Windows Installer Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20817 Windows Error Reporting Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20820 Windows Common Log File System Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20826 Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability 7.8 high
CVE-2026-20831 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20832 Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20837 Windows Media Remote Code Execution Vulnerability 7.8 high
CVE-2026-20840 Windows NTFS Remote Code Execution Vulnerability 7.8 high
CVE-2026-20843 Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20857 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20858 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20859 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20860 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20861 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20864 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20865 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20866 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20867 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20870 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20871 Desktop Window Manager Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20873 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20874 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20877 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20918 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20920 Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20922 Windows NTFS Remote Code Execution Vulnerability 7.8 high
CVE-2026-20923 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20924 Windows Management Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20938 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20940 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20941 Host Process for Windows Tasks Elevation of Privilege Vulnerability 7.8 high
CVE-2026-20946 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-20948 Microsoft Word Remote Code Execution Vulnerability 7.8 high
CVE-2026-20949 Microsoft Excel Security Feature Bypass Vulnerability 7.8 high
CVE-2026-20950 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-20951 Microsoft SharePoint Server Remote Code Execution Vulnerability 7.8 high
CVE-2026-20956 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-21224 Azure Connected Machine Agent Elevation of Privilege Vulnerability 7.8 high
CVE-2026-21509 Microsoft Office Security Feature Bypass Vulnerability 7.8 high Yes
CVE-2026-20804 Windows Hello Tampering Vulnerability 7.7 high
CVE-2026-20852 Windows Hello Tampering Vulnerability 7.7 high
CVE-2025-69195 Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls 7.6 high
CVE-2025-61726 Memory exhaustion in query parameter parsing in net/url 7.5 high
CVE-2026-0719 Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication 7.5 high
CVE-2026-0897 Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata 7.5 high
CVE-2026-21441 urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) 7.5 high
CVE-2026-23490 pyasn1 has a DoS vulnerability in decoder 7.5 high
CVE-2026-0386 Windows Deployment Services Remote Code Execution Vulnerability 7.5 high
CVE-2026-20848 Windows SMB Server Elevation of Privilege Vulnerability 7.5 high
CVE-2026-20849 Windows Kerberos Elevation of Privilege Vulnerability 7.5 high
CVE-2026-20875 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability 7.5 high
CVE-2026-20919 Windows SMB Server Elevation of Privilege Vulnerability 7.5 high
CVE-2026-20921 Windows SMB Server Elevation of Privilege Vulnerability 7.5 high
CVE-2026-20926 Windows SMB Server Elevation of Privilege Vulnerability 7.5 high
CVE-2026-20929 Windows HTTP.sys Elevation of Privilege Vulnerability 7.5 high
CVE-2026-20934 Windows SMB Server Elevation of Privilege Vulnerability 7.5 high
CVE-2026-20965 Windows Admin Center Elevation of Privilege Vulnerability 7.5 high
CVE-2026-21226 Azure Core shared client library for Python Remote Code Execution Vulnerability 7.5 high
CVE-2026-20844 Windows Clipboard Server Elevation of Privilege Vulnerability 7.4 high
CVE-2026-20853 Windows WalletService Elevation of Privilege Vulnerability 7.4 high
CVE-2026-20803 Microsoft SQL Server Elevation of Privilege Vulnerability 7.2 high
CVE-2025-68756 block: Use RCU in blk_mq_[un]quiesce_tagset() instead of set->tag_list_lock 7.1 high
CVE-2025-68759 wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring() 7.1 high
CVE-2025-68766 irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc() 7.1 high
CVE-2025-68771 ocfs2: fix kernel BUG in ocfs2_find_victim_chain 7.1 high
CVE-2025-68785 net: openvswitch: fix middle attribute validation in push_nsh() action 7.1 high
CVE-2025-68795 ethtool: Avoid overflowing userspace buffer on stats query 7.1 high
CVE-2025-68808 media: vidtv: initialize local pointers upon transfer of memory ownership 7.1 high
CVE-2025-71067 ntfs: set dummy blocksize to read boot_block when mounting 7.1 high
CVE-2025-71081 ASoC: stm32: sai: fix OF node leak on probe 7.1 high
CVE-2025-71082 Bluetooth: btusb: revert use of devm_kzalloc in btusb 7.1 high
CVE-2025-71087 iavf: fix off-by-one issues in iavf_config_rss_reg() 7.1 high
CVE-2025-71105 f2fs: use global inline_xattr_slab instead of per-sb slab cache 7.1 high
CVE-2025-71114 via_wdt: fix critical boot hang due to unnamed resource allocation 7.1 high
CVE-2025-71130 drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer 7.1 high
CVE-2025-71133 RDMA/irdma: avoid invalid read in irdma_net_event 7.1 high
CVE-2025-71143 clk: samsung: exynos-clkout: Assign .num before accessing .hws 7.1 high
CVE-2026-22984 libceph: prevent potential out-of-bounds reads in handle_auth_done() 7.1 high
CVE-2025-68119 Unexpected code execution when invoking toolchain in cmd/go 7.0 high
CVE-2025-68781 usb: phy: fsl-usb: Fix use-after-free in delayed work during device removal 7.0 high
CVE-2025-71075 scsi: aic94xx: fix use-after-free in device removal path 7.0 high
CVE-2026-20808 Windows File Explorer Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20814 DirectX Graphics Kernel Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20815 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20830 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20836 DirectX Graphics Kernel Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20842 Microsoft DWM Core Library Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20863 Win32k Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20869 Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20943 Microsoft Office Click-To-Run Remote Code Execution Vulnerability 7.0 high
CVE-2026-21219 Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability 7.0 high
CVE-2026-21221 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability 7.0 high
CVE-2026-20812 LDAP Tampering Vulnerability 6.5 high
CVE-2026-20847 Microsoft Windows File Explorer Spoofing Vulnerability 6.5 high

Microsoft’s January 13, 2026 Patch Tuesday release covers 315 CVEs: 29 rated critical, 151 rated important, and 113 rated moderate. Of these, none are currently listed as actively exploited.

Severity Breakdown

Severity Count
Critical 29
Important 151
Moderate 113
Actively exploited (CISA KEV) 0

Highest-Severity Vulnerabilities

Top 20 of 315 total, by CVSS/severity:

CVE Title CVSS
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability 9.9
CVE-2025-68789 hwmon: (ibmpex) fix use-after-free in high/low store 9.8
CVE-2025-68814 io_uring: fix filename leak in __io_openat_prep() 9.8
CVE-2025-68819 media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() 9.8
CVE-2025-68822 Input: alps - fix use-after-free bugs caused by dev3_register_work 9.8
CVE-2025-68823 ublk: fix deadlock when reading partition table 9.8
CVE-2025-71064 net: hns3: using the num_tqps in the vf driver to apply for resources 9.8
CVE-2025-71066 net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change 9.8
CVE-2025-71072 shmem: fix recovery on rename failures 9.8
CVE-2025-71073 Input: lkkbd - disable pending work before freeing device 9.8
CVE-2025-71098 ip6_gre: make ip6gre_header() robust 9.8
CVE-2026-24306 Azure Front Door Elevation of Privilege Vulnerability 9.8
CVE-2026-20963 Microsoft SharePoint Remote Code Execution Vulnerability 9.8
CVE-2026-21264 Microsoft Account Spoofing Vulnerability 9.3
CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability 9.3
CVE-2026-24307 M365 Copilot Information Disclosure Vulnerability 9.3
CVE-2025-69194 Wget2: arbitrary file write via metalink path traversal in gnu wget2 8.8
CVE-2026-20868 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 8.8
CVE-2026-20947 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8
CVE-2025-15444 Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium 8.6

CVSS scores are sourced directly from Microsoft’s CVRF data as of January 13, 2026; exploitation status is cross-checked against CISA’s KEV catalog. Later re-scoring by NVD can shift a CVE’s score after this report was generated.

Why This Matters

No vulnerabilities in this release are yet listed in CISA’s Known Exploited Vulnerabilities catalog, but that can change quickly once a patch is public and attackers reverse-engineer it. Organizations should prioritize the critical- and important-rated CVEs above, especially any with public proof-of-concept exploits.

Frequently Asked Questions

How many vulnerabilities did Microsoft patch in January 2026? 315 CVEs, per Microsoft’s January 13, 2026 Patch Tuesday release.

Were any January 2026 Patch Tuesday vulnerabilities actively exploited? Not as of January 13, 2026, per CISA’s Known Exploited Vulnerabilities (KEV) catalog — this can change as exploitation is discovered after release.


Data sourced from Microsoft Security Response Center (MSRC) CVRF v3.0 and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated January 13, 2026. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Microsoft Security Response Center (MSRC)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools