HomeMicrosoft Patch Tuesday › January 2026

Microsoft Patch Tuesday, January 2026

·

Microsoft's January 2026 security release, published January 13, 2026: 27 updates fixing 108 CVEs, ranked by confirmed exploitation, ransomware use, and severity. Provided by Senserva.

Still active now. 3 CVEs from this release are on the Senserva hot list today (as of 2026-08-20), still ranked among the most dangerous vulnerabilities right now by confirmed exploitation, ransomware use, EPSS, and severity. See the current hot list.
27
Updates (KBs)
108
CVEs fixed
3
On the CISA KEV list
11
Critical updates

Actively exploited CVEs (CISA KEV)

CVE-2026-20963Microsoft SharePoint Remote Code Execution VulnerabilityCVSS 9.8Exploited Hot now
CVE-2026-21509Microsoft Office Security Feature Bypass VulnerabilityCVSS 7.8Exploited Hot now
CVE-2026-20805Desktop Window Manager Information Disclosure VulnerabilityCVSS 5.5Exploited Hot now

Other high-risk CVEs (CVSS 8.8+)

CVE-2025-6965Integer Truncation on SQLiteCVSS 9.8
CVE-2026-20868Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVSS 8.8
CVE-2026-20947Microsoft SharePoint Server Remote Code Execution VulnerabilityCVSS 8.8

Products fixed this month

Windows 10 Version 1809 for 32-bit Systems (10)Windows 11 Version 25H2 for x64-based Systems (7)Windows 11 Version 25H2 for ARM64-based Systems (7)Windows Server 2019 (7)Microsoft SharePoint Server 2019 (7)Microsoft Office 2019 for 32-bit editions (4)Microsoft Office 2016 (32-bit edition) (4)Microsoft Office 2016 (64-bit edition) (4)Windows Server 2019 (Server Core installation) (4)Windows Server 2022 (4)

Every update in this release

All 27 update articles, worst first: anything on the CISA KEV list, then by highest CVSS. Each row links our page for the update, Microsoft's support article, and the Update Catalog for a standalone download.

UpdateSeverityMax CVSSCVEs fixedProductsAlso
KB5074109 ExploitedCritical9.886Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5073723 ExploitedCritical9.873Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5073457 ExploitedCritical9.878Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5073724 ExploitedCritical9.873Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5073379 ExploitedCritical9.886Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5073455 ExploitedCritical9.880Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5073450 ExploitedCritical9.880Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, Windows 10 Version 1809 for 32-bit SystemsSupport · Catalog
KB5073722 ExploitedCritical9.854Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002825 ExploitedCritical9.87Microsoft SharePoint Server 2019, Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002828 ExploitedCritical9.87Microsoft SharePoint Server 2019, Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002822 ExploitedCritical9.86Microsoft SharePoint Server 2019, Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5073698 ExploitedHigh8.836Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5073696 ExploitedHigh8.837Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019Support · Catalog
KB5002713 ExploitedHigh7.81Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5073697High8.826Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5073700High8.826Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5073695High8.828Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5073699High8.828Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022Support · Catalog
KB5002827High8.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002823High8.82Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription EditionSupport · Catalog
KB5002826High8.43Microsoft SharePoint Server 2019, Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)Support · Catalog
KB5002831High7.83Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editions, Microsoft 365 Apps for Enterprise for 32-bit SystemsSupport · Catalog
KB5002824High7.83Office Online Server, Microsoft Office 2019 for 32-bit editions, Microsoft Office 2019 for 64-bit editionsSupport · Catalog
KB5002829High7.81Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft Office 2019 for 32-bit editionsSupport · Catalog
KB5073031High7.21Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 22)Support · Catalog
KB5073177High7.21Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 22)Support · Catalog
KB5072936High7.21Microsoft SQL Server 2022 for x64-based Systems (GDR), Microsoft SQL Server 2025 for x64-based Systems (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 22)Support · Catalog
Take this release to your AI

Composed from the January 2026 release data above. Copy it into Claude, ChatGPT, or Copilot. Free, no sign-in.

Reference: Microsoft CVE and vulnerability management, ranked by real-world risk, and the Microsoft patching guide.
Data notice: this page is provided as is, for informational purposes only, without warranty of any kind. Senserva, LLC does not guarantee the accuracy, completeness, or timeliness of third-party data (MSRC, NVD, CISA KEV, EPSS) and accepts no liability for actions taken based on it; verify against the authoritative Microsoft advisory before acting. Built daily with Senserva Trustworthy AI. All use of this data is subject to the Senserva EULA.