Skip to content
Noroxi

Patch Tuesday

January 2026

On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.

How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.

206 records · 3 KEV

Affecting your stack

This month's records that match the products and versions in your stack.

Sign in to see the ones matching your stack; records and notifications are free. →

Microsoft · January 13

112 · 2 KEV · 1 critical

+100 moreAll records of the vendor

Adobe · January 13

25 · 0 KEV · 0 critical
  • Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)

    HighCVSS 8.6No exploitEPSS 1%

    adobe · dreamweaverJan 13, 2026

  • Dreamweaver Desktop | Improper Input Validation (CWE-20)

    HighCVSS 8.6No exploitEPSS 0%

    adobe · dreamweaverJan 13, 2026

  • Dreamweaver Desktop | Improper Input Validation (CWE-20)

    HighCVSS 8.6No exploitEPSS 0%

    adobe · dreamweaverJan 13, 2026

  • Dreamweaver Desktop | Improper Input Validation (CWE-20)

    HighCVSS 8.6No exploitEPSS 0%

    adobe · dreamweaverJan 13, 2026

  • Illustrator | Untrusted Search Path (CWE-426)

    HighCVSS 8.6No exploitEPSS 0%

    adobe · illustratorJan 13, 2026

  • Dreamweaver Desktop | Incorrect Authorization (CWE-863)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · dreamweaverJan 13, 2026

  • InDesign Desktop | Access of Uninitialized Pointer (CWE-824)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · indesignJan 13, 2026

  • InDesign Desktop | Access of Uninitialized Pointer (CWE-824)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · indesignJan 13, 2026

  • InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · indesignJan 13, 2026

  • InCopy | Heap-based Buffer Overflow (CWE-122)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · incopyJan 13, 2026

  • Bridge | Heap-based Buffer Overflow (CWE-122)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · bridgeJan 13, 2026

  • Substance3D - Stager | Use After Free (CWE-416)

    HighCVSS 7.8No exploitEPSS 0%

    adobe · substance 3d stagerJan 13, 2026

+13 moreAll records of the vendor

SAP · January 13

0 · 0 KEV · 0 critical

No records in this window.

Siemens · January 13

3 · 0 KEV · 1 critical
  • Affected devices do not properly enforce user authentication on specific API endpoints.

    CriticalCVSS 10.0No exploitEPSS 1%

    siemens · industrial edge cloud device (iecd)Jan 13, 2026

  • A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6E

    HighCVSS 8.7No exploitEPSS 0%

    siemens · simatic et 200al im 157-1 pnJan 13, 2026

  • A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4).

    HighCVSS 7.3No exploitEPSS 0%

    siemens · telecontrol server basicJan 13, 2026

All records of the vendor

Schneider Electric · January 13

0 · 0 KEV · 0 critical

No records in this window.

Oracle (Critical Patch Update) · January 20

66 · 1 KEV · 2 critical
  • Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serve

    CriticalCVSS 10.0KEVWeaponizedEPSS 73%

    oracle · http serverJan 20, 2026

  • Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).

    CriticalCVSS 9.8No exploitEPSS 0%

    oracle · agile product lifecycle management for processJan 20, 2026

  • Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).

    HighCVSS 8.6No exploitEPSS 0%

    oracle · hospitality opera 5Jan 20, 2026

  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).

    HighCVSS 8.2Proof of conceptEPSS 0%

    oracle · vm virtualboxJan 20, 2026

  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).

    HighCVSS 8.2No exploitEPSS 0%

    oracle · vm virtualboxJan 20, 2026

  • Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management Sy

    HighCVSS 8.1No exploitEPSS 0%

    oracle · flexcube investor servicingJan 20, 2026

  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).

    HighCVSS 8.2No exploitEPSS 0%

    oracle · vm virtualboxJan 20, 2026

  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).

    HighCVSS 8.2No exploitEPSS 0%

    oracle · vm virtualboxJan 20, 2026

  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).

    HighCVSS 8.1No exploitEPSS 0%

    oracle · vm virtualboxJan 20, 2026

  • Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).

    HighCVSS 8.2No exploitEPSS 0%

    oracle · vm virtualboxJan 20, 2026

  • Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).

    HighCVSS 7.5No exploitEPSS 0%

    oracle · siebel customer relationship management deploymentJan 20, 2026

  • Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).

    HighCVSS 7.5No exploitEPSS 0%

    oracle · supply chain products suiteJan 20, 2026

+54 moreAll records of the vendor