TLP:CLEAR
Microsoft January 2026 Threat & Deployment BriefExploited Zero-Day, Secure Boot Bypass, Severity Inversion

Patch the Windows client and server cumulative first — it carries CVE-2026-20805, a Desktop Window Manager information-disclosure zero-day exploited in the wild and KEV-listed on release day. No CVSS-9.8 in this cycle.

Deploy first
Windows client and server monthly security update
Act units
1
Hunt required
1 unit(s) — exploited pre-fix
Release
Microsoft 2026-01-13
CVEs
112–114 (by counter)
KEV read
2026-07-17
Report
ITS-EXV-2026-0113

Deploy the Windows cumulative first — for an exploited zero-day, not a high score. CVE-2026-20805 is a Desktop Window Manager information-disclosure flaw, exploited in the wild and CISA KEV-listed on 13 January, the release day. It scores only 5.5, so a severity-ordered queue would bury it — and that queue would be wrong. Evidence-lane emergency change.

An exploited information-disclosure bug is the unusual part. ZDI notes it is rare to see an information-disclosure flaw exploited in the wild; a DWM leak is most useful as the reconnaissance half of a privilege-escalation chain, so treat it as a stepping stone, not a curiosity.

Also public at release: a Secure Boot bypass and two legacy modem drivers. CVE-2026-21265 is a Secure Boot certificate-expiration security-feature bypass (6.4), and Microsoft removed two legacy soft-modem drivers (CVE-2023-31096, CVE-2024-55414) rather than patch them — publicly disclosed, not exploited.

The highest-impact non-exploited flaws are Office Preview-Pane RCEs. CVE-2026-20952 and CVE-2026-20953 are Critical Office remote code execution reachable through the Preview Pane (no file-open needed), scored 8.4 and rated Exploitation Less Likely. They are not exposed technology or core infrastructure, so they ship on the normal cycle — but the Preview-Pane vector is a real caveat.

No CVSS-9.8 unauthenticated RCE this month. ZDI and Tenable both confirm the release has no 9.8 critical RCE; the top scores are the pair of 8.4 Office bugs. This is a one-zero-day cycle decided by exploitation, not by a headline number.

The worklist

1

Windows client and server monthly security update

Per-product servicing — see table
ACT · under attack
emergency change, ≤72h

Why now. CVE-2026-20805, a Desktop Window Manager information-disclosure flaw, was exploited in the wild before the patch shipped and CISA KEV-listed on release day. It scores only 5.5, which means an automated severity-ordered queue buries it beneath dozens of higher-CVSS items you are not being attacked through — that is the severity inversion this cumulative exists to correct. Exploitation, not score, forces the emergency change.

ProductPackageCarries
Windows 11 25H2 / 24H2KB5074109CVE-2026-20805, CVE-2026-21265
Windows 11 23H2KB5073455CVE-2026-20805, CVE-2026-21265
Windows 10 22H2 (ESU)KB5073724CVE-2026-20805, CVE-2026-21265
Windows Server 2025KB5073379CVE-2026-20805, CVE-2026-21265
Windows Server 2022KB5073457CVE-2026-20805
Windows Server 2019KB5073723CVE-2026-20805
Windows Server 2016KB5073722CVE-2026-20805

Also inside: The same cumulative carries CVE-2026-21265, a Secure Boot certificate-expiration security-feature bypass that was publicly disclosed at release. Microsoft also removed two legacy soft-modem drivers rather than patch them — CVE-2023-31096 (Agere) and CVE-2024-55414 (Motorola), both publicly-disclosed elevation-of-privilege issues; if you do not use dial-up soft-modem hardware, the driver removal has no functional impact.

Patching is not remediation. CVE-2026-20805 was exploited as a zero-day, so deployment and compromise assessment are two obligations and this unit discharges only the first. A DWM information leak is most valuable as the reconnaissance stage of a privilege-escalation chain, so review endpoints for follow-on elevation attempts in the exposure window rather than treating a 5.5 information-disclosure as low consequence.

Then. Deploy the per-product package for your build from the table and reboot. From January 2026 Windows Server 2025 has its own KB and build sequence (KB5073379 / 26100.32230) separate from the Windows 11 24H2 client, despite the shared 26100 base — do not assume the client KB covers the server.

The soft call in this unit

There is no soft call on the tier: a single KEV-listed exploited flaw forces Act by evidence regardless of its 5.5 score. If you run a strict severity-ordered process, the judgement you must override is your own queue — this ships first because it is being used, not because it is severe.

The cut — why the top unit cannot slip

Confidence: moderate — analytic judgement, not vendor-attested

The exploited DWM information-disclosure flaw is the reconnaissance half of an elevation-of-privilege chain, not a standalone leak.

Basis. Desktop Window Manager runs with elevated privilege and its leaks classically expose kernel addresses or handles used to defeat ASLR ahead of a local elevation. ZDI flags the rarity of an exploited information-disclosure bug, which fits a chain component being used in the wild rather than a data-theft primitive. This is inferred from the component and the exploitation pattern, not attested by an advisory.

What would lower this. No advisory names the paired elevation flaw or the intrusion set, so the chain reading is architectural inference. If the exploited use turns out to be pure information theft with no elevation follow-on, the reconnaissance framing weakens — but the deployment call (patch it now) does not change either way.

What is not urgent — and why

1

Microsoft Office (Click-to-Run and MSI)

Per-product servicing — see table
TRACK
normal cycle

Why now. It is not now. CVE-2026-20952 and CVE-2026-20953 are Critical Office remote code execution flaws reachable through the Preview Pane, so no explicit file-open is required — but Office is neither exposed technology nor core infrastructure, the flaws are not exploited, and Microsoft rates them Exploitation Less Likely. The tree files them Track. The Preview-Pane vector is the one caveat: it lowers the interaction barrier, and it is called out here rather than hidden.

ProductPackageCarries
Microsoft Office (Click-to-Run and MSI)not establishedresolve via vendor advisory before deployment

Then. Patch Office on the normal cycle (Click-to-Run auto-updates; MSI via WSUS/SCCM). Do not let the Critical label pull it ahead of the exploited DWM zero-day — it is Critical because a rendered preview can execute code, not because anyone is reaching it unbidden today.

Method, sources, caveats

Sources

SourceAdmiraltyUsed for
https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilitiesA1KEV read 2026-07-17 (catalogVersion 2026.07.16): CVE-2026-20805 added 2026-01-13, dueDate 2026-02-03, the only 13 January CVE in the catalog
https://www.thezdi.com/blog/2026/1/13/the-january-2026-security-update-reviewB2Count (112/114), Critical (8); exploited DWM info-disclosure and its rarity; no 9.8; disclosed set
https://www.tenable.com/blog/microsofts-january-2026-patch-tuesday-addresses-1B2Count (113), Critical (8); no 9.8 confirmation; Office Preview-Pane RCEs 8.4 Exploitation Less Likely
https://www.bleepingcomputer.com/news/microsoft/microsoft-january-2026-patch-tB2Count (114), Critical (8, 6 RCE + 2 EoP); the three zero-days; per-version KB list
https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-january-2026/B2Count (114); exploited set; vulnerability-type breakdown
https://securityaffairs.com/186888/hacking/microsoft-patch-tuesday-security-upB3Count (112/114); actively-exploited-zero-day framing; the second modem-driver CVE
https://support.microsoft.com/en-us/topic/january-13-2026-kb5074109-os-builds-A2Windows 11 25H2/24H2 package KB5074109 and builds of record