Microsoft’s January 2026 updates fix 113 flaws, including exploited DWM bug

THE BRIEF
According to Krebs on Security, Microsoft’s January 2026 security updates address at least 113 vulnerabilities across various Windows operating systems and supported software. Eight issues received the company’s “critical” rating. Microsoft also warned that attackers are already exploiting one of the vulnerabilities fixed in the release: CVE-2026-20805, a flaw in Desktop Window Manager (DWM), the Windows component that organizes windows on a user’s screen. The report says Kev Breen, senior director of cyber threat research at Immersive, noted that Microsoft gave the issue a CVSS score of 5.5 while confirming exploitation in the wild. Breen said flaws of this type are commonly used to undermine Address Space Layout Randomization (ASLR), a Windows security feature. The supplied report does not provide further details about affected organizations, exploitation methods, or outcomes. Administrators should review Microsoft’s January fixes, identify systems running affected Windows or supported software, and prioritize assessment of CVE-2026-20805 because Microsoft has reported active exploitation.
WHY IT MATTERS
This matters because the release combines a broad patch set with a vulnerability Microsoft says is already being exploited. The affected DWM component is part of Windows, and the report links the issue to efforts that can undermine ASLR, a core security feature. A middling CVSS score should not outweigh the exploitation warning. Organizations that delay review may leave the reported zero-day unresolved while also missing eight vulnerabilities Microsoft classified as critical. The available information does not establish who was targeted or what occurred after exploitation, so risk decisions should remain grounded in local asset and exposure data.
WHO SHOULD CARE
Windows administrators, vulnerability-management teams, security leaders, and organizations running Microsoft-supported software should care. They need to determine whether affected systems are in their environments, assess the January fixes, and give particular attention to Microsoft’s warning that CVE-2026-20805 is being exploited.
WHAT TO DO NOW
- Inventory Windows operating systems and supported Microsoft software in your environment.
- Review and apply Microsoft’s January 2026 security updates according to your change-management process.
- Prioritize assessment and remediation of CVE-2026-20805 because Microsoft reported active exploitation.
- Track the eight vulnerabilities Microsoft classified as critical and verify remediation status.