Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft security patch release for CVE-2026-20805

Security Patch Release
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft released January 2026 security updates for Windows and supported software, fixing at least 113 vulnerabilities and 8 critical flaws. The release includes CVE-2026-20805, an actively exploited zero-day in Desktop Window Manager (DWM) that can help attackers bypass ASLR and chain into code execution. It also covers critical Microsoft Office RCE bugs and a Secure Boot bypass, making rapid deployment important across supported Windows systems.

Related Happenings

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score78 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

Microsoft security patch release for CVE-2026-56164

Security Patch Release
H score11 First: 14.07.2026 23:25 Last: 14.07.2026 23:25 Sources 1

About this happening: Microsoft released a record 622-CVE Patch Tuesday that includes two exploited flaws in SharePoint Server and Active Directory Federation Services, raising urgency...

Microsoft Corp. security patch release for CVE-2026-56155

Security Patch Release
H score48 First: 14.07.2026 22:22 Last: 14.07.2026 22:22 Sources 1

About this happening: Microsoft released July 2026 Patch Tuesday updates that close at least 570 security holes in Windows and other software, expanding the remediation burden for defen...

Microsoft releases RoguePlanet Defender security update for CVE-2026-50656

Security Patch Release
H score32 First: 17.06.2026 20:36 Last: 17.06.2026 20:36 Sources 1

About this happening: Microsoft has released a security update for CVE-2026-50656, remediating RoguePlanet in the Microsoft Malware Protection Engine (mpengine.dll). The flaw is a *...

Latest development: 09.07.2026 11:48

Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.

Microsoft Office launch disruption after June 2026 Windows updates

Service Disruption
H score0 First: 17.06.2026 14:54 Last: 17.06.2026 14:54 Sources 1

About this happening: Microsoft is investigating a Windows update-related disruption that can stop third-party applications from launching Word, Excel, PowerPoint, Access or opening documen...

Timeline

  1. 14.01.2026 02:47 2 articles · 6mo ago

    Microsoft January 2026 Windows patch release with exploited DWM zero-day

    Initial Disclosure

    Microsoft issued January 2026 security updates for Windows and supported software, fixing at least 113 vulnerabilities and 8 critical flaws while warning that CVE-2026-20805 in Desktop Window Manager (DWM) is already being exploited in the wild. The release also includes Microsoft Office remote code execution bugs triggered through the Preview Pane, removal of legacy modem drivers tied to CVE-2023-31096, and remediation for the Windows Secure Boot bypass CVE-2026-21265 across supported Windows systems.

    Show sources