Source: Tenable Blog
Author: Research Special Operations
URL: https://www.tenable.com/blog/microsofts-january-2026-patch-tuesday-addresses-113-cves-cve-2026-20805
ONE SENTENCE SUMMARY:
Microsoft’s January 2026 Patch Tuesday addressed 113 CVEs, including two zero-days, with significant vulnerabilities in Office and NTFS.
MAIN POINTS:
- Patched 113 CVEs, with 8 critical and 105 important.
- Two zero-day vulnerabilities, one already exploited.
- Multiple critical RCE vulnerabilities in Microsoft Office.
- Key vulnerabilities found in NTFS affecting code execution.
- Secure Boot certificate expiration poses security threats.
- Many vulnerabilities involve elevation of privilege and remote code execution.
- Exploitation of Preview Pane in Office doesn’t require file opening.
- Specific CVEs include CVE-2026-20805 and CVE-2026-20952/53.
- Important components patched include Windows, Azure, and SQL Server.
- Tenable recommends prompt patching and vulnerability scanning.
TAKEAWAYS:
- Prioritize patching critical and exploited vulnerabilities.
- Monitor Secure Boot certificate expirations for security maintenance.
- Be aware of Office vulnerabilities exploiting Preview Pane.
- Ensure comprehensive vulnerability assessments and updates.
- Engage with cyber threat discussions for ongoing security awareness.