Microsoft security patch release for CVE-2026-20805
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft released January 2026 security updates for Windows and supported software, fixing at least 113 vulnerabilities and 8 critical flaws. The release includes CVE-2026-20805, an actively exploited zero-day in Desktop Window Manager (DWM) that can help attackers bypass ASLR and chain into code execution. It also covers critical Microsoft Office RCE bugs and a Secure Boot bypass, making rapid deployment important across supported Windows systems.
Related Happenings
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score78
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveAbout this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft security patch release for CVE-2026-56164
Security Patch Release
H score11
First: 14.07.2026 23:25
Last: 14.07.2026 23:25
Sources 1
About this happening:
Microsoft released a record 622-CVE Patch Tuesday that includes two exploited flaws in SharePoint Server and Active Directory Federation Services, raising urgency...
Microsoft security patch release for CVE-2026-56164
Security Patch ReleaseAbout this happening: Microsoft released a record 622-CVE Patch Tuesday that includes two exploited flaws in SharePoint Server and Active Directory Federation Services, raising urgency...
Microsoft Corp. security patch release for CVE-2026-56155
Security Patch Release
H score48
First: 14.07.2026 22:22
Last: 14.07.2026 22:22
Sources 1
About this happening:
Microsoft released July 2026 Patch Tuesday updates that close at least 570 security holes in Windows and other software, expanding the remediation burden for defen...
Microsoft Corp. security patch release for CVE-2026-56155
Security Patch ReleaseAbout this happening: Microsoft released July 2026 Patch Tuesday updates that close at least 570 security holes in Windows and other software, expanding the remediation burden for defen...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch Release
H score32
First: 17.06.2026 20:36
Last: 17.06.2026 20:36
Sources 1
About this happening:
Microsoft has released a security update for CVE-2026-50656, remediating RoguePlanet in the Microsoft Malware Protection Engine (mpengine.dll). The flaw is a *...
Microsoft releases RoguePlanet Defender security update for CVE-2026-50656
Security Patch ReleaseAbout this happening: Microsoft has released a security update for CVE-2026-50656, remediating RoguePlanet in the Microsoft Malware Protection Engine (mpengine.dll). The flaw is a *...
Latest development: 09.07.2026 11:48
Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.
Microsoft Office launch disruption after June 2026 Windows updates
Service Disruption
H score0
First: 17.06.2026 14:54
Last: 17.06.2026 14:54
Sources 1
About this happening:
Microsoft is investigating a Windows update-related disruption that can stop third-party applications from launching Word, Excel, PowerPoint, Access or opening documen...
Microsoft Office launch disruption after June 2026 Windows updates
Service DisruptionAbout this happening: Microsoft is investigating a Windows update-related disruption that can stop third-party applications from launching Word, Excel, PowerPoint, Access or opening documen...
Timeline
-
14.01.2026 02:47 2 articles · 6mo ago
Microsoft January 2026 Windows patch release with exploited DWM zero-day
Initial DisclosureMicrosoft issued January 2026 security updates for Windows and supported software, fixing at least 113 vulnerabilities and 8 critical flaws while warning that CVE-2026-20805 in Desktop Window Manager (DWM) is already being exploited in the wild. The release also includes Microsoft Office remote code execution bugs triggered through the Preview Pane, removal of legacy modem drivers tied to CVE-2023-31096, and remediation for the Windows Secure Boot bypass CVE-2026-21265 across supported Windows systems.
Show sources
- Patch Tuesday, January 2026 Edition — krebsonsecurity.com — 14.01.2026 02:47
- Patch Tuesday, January 2026 Edition — krebsonsecurity.com — 14.01.2026 02:47