Deploy the Windows cumulative first — for an exploited zero-day, not a high score. CVE-2026-20805 is a Desktop Window Manager information-disclosure flaw, exploited in the wild and CISA KEV-listed on 13 January, the release day. It scores only 5.5, so a severity-ordered queue would bury it — and that queue would be wrong. Evidence-lane emergency change.
An exploited information-disclosure bug is the unusual part. ZDI notes it is rare to see an information-disclosure flaw exploited in the wild; a DWM leak is most useful as the reconnaissance half of a privilege-escalation chain, so treat it as a stepping stone, not a curiosity.
Also public at release: a Secure Boot bypass and two legacy modem drivers. CVE-2026-21265 is a Secure Boot certificate-expiration security-feature bypass (6.4), and Microsoft removed two legacy soft-modem drivers (CVE-2023-31096, CVE-2024-55414) rather than patch them — publicly disclosed, not exploited.
The highest-impact non-exploited flaws are Office Preview-Pane RCEs. CVE-2026-20952 and CVE-2026-20953 are Critical Office remote code execution reachable through the Preview Pane (no file-open needed), scored 8.4 and rated Exploitation Less Likely. They are not exposed technology or core infrastructure, so they ship on the normal cycle — but the Preview-Pane vector is a real caveat.
No CVSS-9.8 unauthenticated RCE this month. ZDI and Tenable both confirm the release has no 9.8 critical RCE; the top scores are the pair of 8.4 Office bugs. This is a one-zero-day cycle decided by exploitation, not by a headline number.
Why now. CVE-2026-20805, a Desktop Window Manager information-disclosure flaw, was exploited in the wild before the patch shipped and CISA KEV-listed on release day. It scores only 5.5, which means an automated severity-ordered queue buries it beneath dozens of higher-CVSS items you are not being attacked through — that is the severity inversion this cumulative exists to correct. Exploitation, not score, forces the emergency change.
| Product | Package | Carries |
|---|---|---|
| Windows 11 25H2 / 24H2 | KB5074109 | CVE-2026-20805, CVE-2026-21265 |
| Windows 11 23H2 | KB5073455 | CVE-2026-20805, CVE-2026-21265 |
| Windows 10 22H2 (ESU) | KB5073724 | CVE-2026-20805, CVE-2026-21265 |
| Windows Server 2025 | KB5073379 | CVE-2026-20805, CVE-2026-21265 |
| Windows Server 2022 | KB5073457 | CVE-2026-20805 |
| Windows Server 2019 | KB5073723 | CVE-2026-20805 |
| Windows Server 2016 | KB5073722 | CVE-2026-20805 |
Also inside: The same cumulative carries CVE-2026-21265, a Secure Boot certificate-expiration security-feature bypass that was publicly disclosed at release. Microsoft also removed two legacy soft-modem drivers rather than patch them — CVE-2023-31096 (Agere) and CVE-2024-55414 (Motorola), both publicly-disclosed elevation-of-privilege issues; if you do not use dial-up soft-modem hardware, the driver removal has no functional impact.
Patching is not remediation. CVE-2026-20805 was exploited as a zero-day, so deployment and compromise assessment are two obligations and this unit discharges only the first. A DWM information leak is most valuable as the reconnaissance stage of a privilege-escalation chain, so review endpoints for follow-on elevation attempts in the exposure window rather than treating a 5.5 information-disclosure as low consequence.
Then. Deploy the per-product package for your build from the table and reboot. From January 2026 Windows Server 2025 has its own KB and build sequence (KB5073379 / 26100.32230) separate from the Windows 11 24H2 client, despite the shared 26100 base — do not assume the client KB covers the server.
There is no soft call on the tier: a single KEV-listed exploited flaw forces Act by evidence regardless of its 5.5 score. If you run a strict severity-ordered process, the judgement you must override is your own queue — this ships first because it is being used, not because it is severe.
The exploited DWM information-disclosure flaw is the reconnaissance half of an elevation-of-privilege chain, not a standalone leak.
Basis. Desktop Window Manager runs with elevated privilege and its leaks classically expose kernel addresses or handles used to defeat ASLR ahead of a local elevation. ZDI flags the rarity of an exploited information-disclosure bug, which fits a chain component being used in the wild rather than a data-theft primitive. This is inferred from the component and the exploitation pattern, not attested by an advisory.
What would lower this. No advisory names the paired elevation flaw or the intrusion set, so the chain reading is architectural inference. If the exploited use turns out to be pure information theft with no elevation follow-on, the reconnaissance framing weakens — but the deployment call (patch it now) does not change either way.
Why now. It is not now. CVE-2026-20952 and CVE-2026-20953 are Critical Office remote code execution flaws reachable through the Preview Pane, so no explicit file-open is required — but Office is neither exposed technology nor core infrastructure, the flaws are not exploited, and Microsoft rates them Exploitation Less Likely. The tree files them Track. The Preview-Pane vector is the one caveat: it lowers the interaction barrier, and it is called out here rather than hidden.
| Product | Package | Carries |
|---|---|---|
| Microsoft Office (Click-to-Run and MSI) | not established | resolve via vendor advisory before deployment |
Then. Patch Office on the normal cycle (Click-to-Run auto-updates; MSI via WSUS/SCCM). Do not let the Critical label pull it ahead of the exploited DWM zero-day — it is Critical because a rendered preview can execute code, not because anyone is reaching it unbidden today.
| Source | Admiralty | Used for |
|---|---|---|
| https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities | A1 | KEV read 2026-07-17 (catalogVersion 2026.07.16): CVE-2026-20805 added 2026-01-13, dueDate 2026-02-03, the only 13 January CVE in the catalog |
| https://www.thezdi.com/blog/2026/1/13/the-january-2026-security-update-review | B2 | Count (112/114), Critical (8); exploited DWM info-disclosure and its rarity; no 9.8; disclosed set |
| https://www.tenable.com/blog/microsofts-january-2026-patch-tuesday-addresses-1 | B2 | Count (113), Critical (8); no 9.8 confirmation; Office Preview-Pane RCEs 8.4 Exploitation Less Likely |
| https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2026-patch-t | B2 | Count (114), Critical (8, 6 RCE + 2 EoP); the three zero-days; per-version KB list |
| https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-january-2026/ | B2 | Count (114); exploited set; vulnerability-type breakdown |
| https://securityaffairs.com/186888/hacking/microsoft-patch-tuesday-security-up | B3 | Count (112/114); actively-exploited-zero-day framing; the second modem-driver CVE |
| https://support.microsoft.com/en-us/topic/january-13-2026-kb5074109-os-builds- | A2 | Windows 11 25H2/24H2 package KB5074109 and builds of record |