Microsoft January update fixes 112 vulnerabilities, including exploited Desktop Window Manager zero-day

THE BRIEF
CyberScoop reports that Microsoft’s first security update of 2026 addressed 112 vulnerabilities affecting Microsoft products and underlying systems. The January 13 release includes CVE-2026-20805, an information-disclosure vulnerability in Desktop Window Manager that Microsoft says is being actively exploited, according to the report. The flaw has a CVSS score of 5.5 and can allow an unauthorized attacker to expose sensitive information. The Cybersecurity and Infrastructure Security Agency added CVE-2026-20805 to its Known Exploited Vulnerabilities catalog on Tuesday. Microsoft’s update is the second consecutive month in which the company disclosed no critical vulnerabilities. The batch also contains more than 110 CVEs for the second January in a row. Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, said information-disclosure vulnerabilities are exploited in the wild sporadically, but not often. The report identifies the Desktop Window Manager issue as the release’s actively exploited zero-day. The report does not provide further details about exploitation or affected environments.
WHY IT MATTERS
The immediate priority is CVE-2026-20805’s reported active exploitation, not simply the size of the 112-vulnerability release. Its inclusion in CISA’s KEV catalog provides a clear signal for organizations that use Microsoft products to review exposure and patch status. The moderate CVSS score of 5.5 does not eliminate operational concern because the reported impact is unauthorized disclosure of sensitive information. At the same time, the report says exploitation of this vulnerability type is sporadic, so teams should avoid assuming details about scope or attacker behavior that were not provided.
WHO SHOULD CARE
Windows and Microsoft-product administrators, vulnerability-management teams, security operations staff, and leaders responsible for patch prioritization should review this update, especially where Desktop Window Manager exposure and CISA KEV tracking are part of their workflows.
WHAT TO DO NOW
- Inventory Microsoft systems and confirm which environments include Desktop Window Manager.
- Prioritize and apply the Microsoft update addressing CVE-2026-20805 according to internal change-management procedures.
- Check CISA’s Known Exploited Vulnerabilities catalog and update patch-priority records for CVE-2026-20805.
- Review available security telemetry for unusual access to sensitive information while avoiding assumptions about exploitation patterns not detailed in the report.