Microsoft’s January 2026 updates address 114 vulnerabilities, including critical remote code execution bugs in Office apps and Windows services like LSASS.
This Patch Tuesday fixes critical vulnerabilities that allow remote code execution and several privilege escalation problems that could let attackers take over systems.
By infosecbulletin
/ Tuesday , June 30 2026
Attackers are now using a flaw (called CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial app, according to the security...
Read More
By infosecbulletin
/ Tuesday , June 30 2026
WhatsApp is about to release a big update that may change how people communicate on the app. Soon, users can...
Read More
By infosecbulletin
/ Monday , June 29 2026
The Linux Foundation said on Thursday that they are starting a new project to fix flaws in open source software...
Read More
By infosecbulletin
/ Sunday , June 28 2026
KDDI Corporation, a Japanese telecom company, revealed a data breach. Hackers got into one of its email systems that five...
Read More
By infosecbulletin
/ Sunday , June 28 2026
Two Asian AI companies have released new models this week that compete with Anthropic’s recently limited Mythos and Fable models,...
Read More
By infosecbulletin
/ Saturday , June 27 2026
Polymarket is a platform for prediction markets using cryptocurrency. It lets users bet on what might happen in real-life events...
Read More
By infosecbulletin
/ Saturday , June 27 2026
Anthropic said that Claude Mythos 5, its strongest AI security model, will be sent back to some U.S. orgs that...
Read More
By infosecbulletin
/ Friday , June 26 2026
A complex phishing attack targets AWS console users by misusing Cloudflare-hosted websites to steal login details. Each domain had a nearly...
Read More
By infosecbulletin
/ Friday , June 26 2026
Cyberattacks are rising around the world, including ransomware, malware, data leaks, and hacked websites. These events show how complex and...
Read More
By infosecbulletin
/ Thursday , June 25 2026
WhatsApp is rolling a new security warning on Android and iOS. It shows up before users open a chat with...
Read More
The number of bugs in each vulnerability category is listed below:
| Vulnerability Type |
Count |
| Remote Code Execution |
22 |
| Denial of Service |
2 |
| Elevation of Privilege |
57 |
| Information Disclosure |
22 |
| Security Feature Bypass |
3 |
| Spoofing |
5 |
| Tampering |
3 |
| Total |
114 |
Zero-Day Vulnerabilities:
CVE-2026-20805 has high-severity flaws in Desktop Windows Manager that can expose information. CVE-2026-21265 relates to digital media handling that can lead to privilege escalation, often used in chained attacks. CVE-2023-31096 seems to be a backported or related fix included in cumulative updates.
| CVE ID |
Component |
Type |
Severity |
Key Notes |
| CVE-2026-20805 |
Desktop Windows Manager |
Information Disclosure |
Important (High per Check Point) |
Allows unauthorized access to sensitive data; patched January 13, 2026 ​ |
| CVE-2026-21265 |
Windows Digital Media |
Elevation of Privilege |
Not specified |
Enables local privilege escalation ​ |
| CVE-2023-31096 |
Unknown (legacy) |
Zero-day (contextual) |
Not specified |
Included in January 2026 updates despite earlier assignment |
Click here for the full list.