January 2026 Patch Tuesday: what Security and IT teams should prioritise
January 2026 Patch Tuesday is now available in the canonical BlackTree Patch Intelligence catalogue. The current bounded cohort covers Microsoft, Adobe and SAP. This is not a claim of unlimited vendor coverage.
The operational queue contains 63 approved patch records linked to 156 unique CVEs. BlackTree currently marks 11 records for an accelerated or out-of-band assessment. BlackTree urgency is separate from vendor severity, CVSS and EPSS.
Security teams should start with confirmed exploitation and exposed control-plane systems. IT administrators should then review applicability, prerequisites, restart impact, sequencing, known issues and rollback guidance on each patch detail page.
Most important Microsoft patches this month
The following fixes deserve early attention based on confirmed exploitation, public disclosure, attack path and technical impact. Applicability still depends on the products and roles deployed in each environment.
- CVE-2026-20805: Desktop Window Manager Information Disclosure Vulnerability Microsoft marked exploitation as detected when the update shipped. Important, CVSS 5.5.
- CVE-2026-20944: Microsoft Word Remote Code Execution Vulnerability Successful exploitation can run attacker-controlled code in the affected component. Critical, CVSS 8.4.
- CVE-2026-20953: Microsoft Office Remote Code Execution Vulnerability Successful exploitation can run attacker-controlled code in the affected component. Critical, CVSS 8.4.
- CVE-2026-20952: Microsoft Office Remote Code Execution Vulnerability Successful exploitation can run attacker-controlled code in the affected component. Critical, CVSS 8.4.
Open the canonical January 2026 Patch Tuesday action queue on cve.blacktree.nl.
Patch details and exploitation assessments were checked against the Microsoft Security Update Guide release data for January 2026.
Editorial article generated from approved catalogue data. Recheck the canonical cycle for later vendor revisions or BlackTree corrections.
Update, 1 September 2026: SharePoint’s January RCE later entered KEV
CVE-2026-20963 is a critical SharePoint deserialization vulnerability that can let an unauthorised remote attacker execute code over the network. It was part of the January update cycle but was omitted from the original BlackTree priority list.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 18 March. Organisations running SharePoint Server should verify that the January fix is installed on every server in the farm, inspect the pre-patch exposure window and review web, process, file and account activity for evidence of code execution or persistence.
This entry is separate from the later SharePoint chains covered elsewhere on BlackTree. Installing only the newest emergency fix is not proof that the January update reached every server or that earlier compromise did not occur.
Primary sources: Microsoft Security Response Center and the CISA KEV catalogue.


