Patch Day month
January 2026 vulnerabilities
A server-rendered hunting trail for January 2026: 310 returned patch records across 1 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
310all patches
30critical
2exploitation detected
3in CISA KEV
139tracked here
Microsoft 310
Page 2 of 2 · records 201–310 of 310
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-20839 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Client-Side Caching (CSC) Service Information Disclosure Vulnerability
and 10 more
KB5073455KB5073457KB5073695KB5073696KB5073698KB5073699KB5073722KB5073723KB5073724KB5074109CVE-2026-20840 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant4%More likelyKB5073379KB5073450Windows NTFS Remote Code Execution Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20842 ↗2026-01-13Windows Server 2022Important0%KB5073379KB5073450Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-20843 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5073379KB5073450Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20844 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Clipboard Server Elevation of Privilege Vulnerability
CVE-2026-20847 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Microsoft Windows File Explorer Spoofing Vulnerability
and 10 more
KB5073455KB5073457KB5073695KB5073696KB5073698KB5073699KB5073722KB5073723KB5073724KB5074109CVE-2026-20848 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20849 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows Kerberos Elevation of Privilege Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20851 ↗2026-01-13Windows Server 2025 (Server Core installation)Important1%KB5073379KB5074109Capability Access Management Service (camsvc) Information Disclosure Vulnerability
CVE-2026-20852 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Hello Tampering Vulnerability
CVE-2026-20853 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073455KB5073722Windows WalletService Elevation of Privilege Vulnerability
CVE-2026-20854 ↗2026-01-13Windows Server 2025 (Server Core installation)Critical1%KB5073379KB5074109Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
CVE-2026-20856 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
CVE-2026-20857 ↗2026-01-13Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5073379KB5073450Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-20858 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20859 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
CVE-2026-20860 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant8%More likelyKB5073379KB5073450Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20861 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20862 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows Management Services Information Disclosure Vulnerability
CVE-2026-20863 ↗2026-01-13Windows Server 2022Important0%KB5073379KB5073450Win32k Elevation of Privilege Vulnerability
CVE-2026-20864 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-20865 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20866 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20867 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20868 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20869 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20870 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
CVE-2026-20871 ↗2026-01-13Windows Server 2022Important4%More likelyKB5073379KB5073450Desktop Window Manager Elevation of Privilege Vulnerability
CVE-2026-20872 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant19%KB5073379KB5073450NTLM Hash Disclosure Spoofing Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20873 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20874 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20875 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5073379KB5073450Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20876 ↗2026-01-13Windows Server 2025 (Server Core installation)Critical1%KB5073379KB5073450Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20877 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20918 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20919 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20920 ↗2026-01-13Windows Server 2022Important0%KB5073450KB5073455Win32k Elevation of Privilege Vulnerability
and 1 more
KB5073457CVE-2026-20921 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows SMB Server Elevation of Privilege Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20922 ↗2026-01-13Windows Server 2022 (Server Core installation)Important1%More likelyKB5073379KB5073450Windows NTFS Remote Code Execution Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20923 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20924 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows Management Services Elevation of Privilege Vulnerability
CVE-2026-20925 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant17%KB5073379KB5073450NTLM Hash Disclosure Spoofing Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20926 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20927 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows SMB Server Denial of Service Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20929 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073450KB5073455Windows HTTP.sys Elevation of Privilege Vulnerability
and 10 more
KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724CVE-2026-20931 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%VulnCheckKB5073379KB5073450Windows Telephony Service Elevation of Privilege Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20932 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20934 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-20935 ↗2026-01-13Windows 11 Version 25H2 for ARM64-based SystemsImportant0%KB5073455KB5074109Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
CVE-2026-20936 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows NDIS Information Disclosure Vulnerability
and 12 more
KB5073455KB5073457KB5073695KB5073696KB5073697KB5073698KB5073699KB5073700KB5073722KB5073723KB5073724KB5074109CVE-2026-20937 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20938 ↗2026-01-13Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5073455KB5074109Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2026-20939 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5073379KB5073450Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20940 ↗2026-01-13Windows 10 Version 22H2 for 32-bit SystemsImportant0%KB5073455KB5073457Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2026-20941 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Host Process for Windows Tasks Elevation of Privilege Vulnerability
CVE-2026-20943 ↗2026-01-13Microsoft SharePoint Server 2019Important1%KB5002822KB5002825Microsoft Office Click-To-Run Remote Code Execution Vulnerability
CVE-2026-20944 ↗2026-01-13Microsoft 365 Apps for Enterprise for 32-bit SystemsCritical0%Microsoft Word Remote Code Execution Vulnerability
CVE-2026-20946 ↗2026-01-13Microsoft Office 2019 for 32-bit editionsImportant1%KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20947 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important18%KB5002822KB5002823Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-20948 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important1%KB5002823KB5002825Microsoft Word Remote Code Execution Vulnerability
CVE-2026-20949 ↗2026-01-13Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Excel Security Feature Bypass Vulnerability
CVE-2026-20950 ↗2026-01-13Office Online ServerImportant0%KB5002824KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20951 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important1%KB5002822KB5002825Microsoft SharePoint Server Remote Code Execution Vulnerability
and 1 more
KB5002828CVE-2026-20952 ↗2026-01-13Microsoft Office 2019 for 64-bit editionsCritical0%KB5002826Microsoft Office Remote Code Execution Vulnerability
CVE-2026-20953 ↗2026-01-13Microsoft Office 2019 for 64-bit editionsCritical1%KB5002826Microsoft Office Remote Code Execution Vulnerability
CVE-2026-20955 ↗2026-01-13Office Online ServerCritical1%KB5002824Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20956 ↗2026-01-13Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20957 ↗2026-01-13Office Online ServerCritical0%KB5002824KB5002831Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-20958 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important0%KB5002822KB5002825Microsoft SharePoint Information Disclosure Vulnerability
and 1 more
KB5002828CVE-2026-20959 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important7%KB5002822KB5002825Microsoft SharePoint Server Spoofing Vulnerability
and 1 more
KB5002828CVE-2026-20962 ↗2026-01-13Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5073379KB5073450Dynamic Root of Trust for Measurement (DRTM) Information Disclosure Vulnerability
CVE-2026-20963 ↗2026-01-13Microsoft SharePoint Enterprise Server 2016Important29%CISA KEVVulnCheckENISAKB5002822KB50028251 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
and 1 more
KB5002828CVE-2026-20965 ↗2026-01-13Windows Admin Center in Azure PortalImportant0%Windows Admin Center Elevation of Privilege Vulnerability
CVE-2026-21219 ↗2026-01-13Windows SDKImportant0%Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2026-21221 ↗2026-01-13Windows Server 2025 (Server Core installation)Important0%KB5073379KB5074109Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2026-21224 ↗2026-01-13Azure Connected Machine AgentImportant0%Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-21226 ↗2026-01-13Azure Core shared client library for PythonImportant1%Azure Core shared client library for Python Remote Code Execution Vulnerability
CVE-2026-21265 ↗2026-01-13Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5073379KB5073450Secure Boot Certificate Expiration Security Feature Bypass Vulnerability
CVE-2026-22701 ↗2026-01-13cbl2 python-filelock 3.0.12-13 on CBL Mariner 2.0Moderate—filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
CVE-2026-22702 ↗2026-01-13cbl2 python-virtualenv 20.26.6-3 on CBL Mariner 2.0Moderate—virtualenv Has TOCTOU Vulnerabilities in Directory Creation
CVE-2026-21860 ↗2026-01-11cbl2 python-tensorboard 2.11.0-3 on CBL Mariner 2.0ModerateOut-of-band—Werkzeug safe_join() allows Windows special device names with compound extensions
CVE-2026-0719 ↗2026-01-11azl3 libsoup 3.4.4-11 on Azure Linux 3.0ImportantOut-of-band—Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlm authentication
CVE-2026-21895 ↗2026-01-11azl3 kata-containers-cc 3.15.0.aks0-5 on Azure Linux 3.0LowOut-of-band—rsa crate has potential panic on a prime being equal to 1
CVE-2026-22693 ↗2026-01-11azl3 harfbuzz 8.3.0-4 on Azure Linux 3.0ModerateOut-of-band—Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS
CVE-2025-69195 ↗2026-01-10azl3 wget 2.1.0-6 on Azure Linux 3.0ImportantOut-of-band—Wget2: gnu wget2: memory corruption and crash via filename sanitization logic with attacker-controlled urls
CVE-2025-69194 ↗2026-01-10azl3 wget 2.1.0-6 on Azure Linux 3.0ImportantOut-of-band—Wget2: arbitrary file write via metalink path traversal in gnu wget2
CVE-2025-68151 ↗2026-01-10azl3 coredns 1.11.4-12 on Azure Linux 3.0ModerateOut-of-band—CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CVE-2026-0628 ↗2026-01-09Microsoft Edge (Chromium-based)N/AOut-of-band7%Chromium: CVE-2026-0628 Insufficient policy enforcement in WebView tag
CVE-2025-15444 ↗2026-01-09azl3 libsodium 1.0.19-1 on Azure Linux 3.0ImportantOut-of-band—Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium
CVE-2026-21441 ↗2026-01-09azl3 tensorflow 2.16.1-9 on Azure Linux 3.0ImportantOut-of-band—urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
CVE-2025-14819 ↗2026-01-09azl3 curl 8.11.1-4 on Azure Linux 3.0ModerateOut-of-band—OpenSSL partial chain store policy bypass
CVE-2025-15079 ↗2026-01-09cbl2 curl 8.8.0-7 on CBL Mariner 2.0ModerateOut-of-band—libssh global known_hosts override
CVE-2025-14524 ↗2026-01-09azl3 cmake 3.30.3-10 on Azure Linux 3.0ModerateOut-of-band—bearer token leak on cross-protocol redirect
CVE-2025-15224 ↗2026-01-09cbl2 curl 8.8.0-7 on CBL Mariner 2.0LowOut-of-band—libssh key passphrase bypass without agent set
CVE-2025-14017 ↗2026-01-09azl3 curl 8.11.1-4 on Azure Linux 3.0ModerateOut-of-band—broken TLS options for threaded LDAPS
CVE-2025-13034 ↗2026-01-09cbl2 curl 8.8.0-7 on CBL Mariner 2.0ModerateOut-of-band—No QUIC certificate pinning with GnuTLS
CVE-2026-22184 ↗2026-01-09azl3 ceph 18.2.2-12 on Azure Linux 3.0CriticalOut-of-band—zlib <= 1.3.1.2 untgz Global Buffer Overflow in TGZfname()
CVE-2026-22185 ↗2026-01-09azl3 openldap 2.6.7-2 on Azure Linux 3.0ImportantOut-of-band—OpenLDAP <= 2.6.10 LMDB mdb_load Heap Buffer Underflow in readline()
CVE-2026-21444 ↗2026-01-07azl3 libtpms 0.9.6-8 on Azure Linux 3.0ModerateOut-of-band—libtpms returns wrong initialization vector when certain symmetric ciphers are used
CVE-2025-68756 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-band—block: Use RCU in blk_mq_[un]quiesce_tagset() instead of set->tag_list_lock
CVE-2025-68758 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—backlight: led-bl: Add devlink to supplier LEDs
CVE-2025-68757 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/vgem-fence: Fix potential deadlock on release
CVE-2025-68763 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—crypto: starfive - Correctly handle return of sg_nents_for_len
CVE-2025-68766 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-band—irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
CVE-2025-68759 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-band—wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring()
CVE-2025-68753 ↗2026-01-06azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-band—ALSA: firewire-motu: add bounds check in put_user loop for DSP events
CVE-2025-68765 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add()
CVE-2025-68755 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—staging: most: remove broken i2c driver
CVE-2025-68764 ↗2026-01-06azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-band—NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.