Patch Tuesday
January 2026
On the second Tuesday of each month Microsoft, Adobe, SAP, Siemens and Schneider Electric publish in bulk; Oracle on the third Tuesday of January, April, July and October. Records published that day, from our own database, sorted by action score: KEV and mature exploits first.
How it is computed: CNA stamp + publication date (two-day window, UTC). No claim of a one-to-one match with the vendor bulletin; out-of-band updates land on other days.
206 records · 3 KEV
Affecting your stack
This month's records that match the products and versions in your stack.
Sign in to see the ones matching your stack; records and notifications are free. →
Microsoft · January 13
112 · 2 KEV · 1 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
78This week | CVE-2026-20963Weaponized | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Critical9.8 | KEV | 29.6% | Jan 13, 2026 |
54Plan | CVE-2026-20805Weaponized | Desktop Window Manager Information Disclosure Vulnerabilitymicrosoft · windows 10 1607 · CWE-200 | Medium5.5 | KEV | 7.2% | Jan 13, 2026 |
41Plan | CVE-2026-20947No exploit | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-89 | High8.8 | — | 18.8% | Jan 13, 2026 |
35Monitor | CVE-2026-20868No exploit | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | High8.8 | — | 1.4% | Jan 13, 2026 |
34Monitor | CVE-2026-20860No exploit | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-843 | High7.8 | — | 8.4% | Jan 13, 2026 |
33Monitor | CVE-2026-20817Proof of concept | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-280 | High7.8 | — | 5.5% | Jan 13, 2026 |
33Monitor | CVE-2026-20944No exploit | Microsoft Word Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-125 | High8.4 | — | 0.5% | Jan 13, 2026 |
33Monitor | CVE-2026-20952No exploit | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-416 | High8.4 | — | 0.5% | Jan 13, 2026 |
33Monitor | CVE-2026-20953No exploit | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-416 | High8.4 | — | 0.6% | Jan 13, 2026 |
32Monitor | CVE-2026-20820Proof of concept | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | High7.8 | — | 2.6% | Jan 13, 2026 |
32Monitor | CVE-2026-20840No exploit | Windows NTFS Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | High7.8 | — | 4.7% | Jan 13, 2026 |
32Monitor | CVE-2026-20843No exploit | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-284 | High7.8 | — | 3.5% | Jan 13, 2026 |
- CVE-2026-2096378This week
Microsoft SharePoint Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 30%microsoft · sharepoint serverJan 13, 2026
- CVE-2026-2080554Plan
Desktop Window Manager Information Disclosure Vulnerability
MediumCVSS 5.5KEVWeaponizedEPSS 7%microsoft · windows 10 1607Jan 13, 2026
- CVE-2026-2094741Plan
Microsoft SharePoint Server Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 19%microsoft · sharepoint serverJan 13, 2026
- CVE-2026-2086835Monitor
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 10 1607Jan 13, 2026
- CVE-2026-2086034Monitor
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 8%microsoft · windows 10 1607Jan 13, 2026
- CVE-2026-2081733Monitor
Windows Error Reporting Service Elevation of Privilege Vulnerability
HighCVSS 7.8Proof of conceptEPSS 6%microsoft · windows 10 21h2Jan 13, 2026
- CVE-2026-2094433Monitor
Microsoft Word Remote Code Execution Vulnerability
HighCVSS 8.4No exploitEPSS 1%microsoft · 365 appsJan 13, 2026
- CVE-2026-2095233Monitor
Microsoft Office Remote Code Execution Vulnerability
HighCVSS 8.4No exploitEPSS 1%microsoft · 365 appsJan 13, 2026
- CVE-2026-2095333Monitor
Microsoft Office Remote Code Execution Vulnerability
HighCVSS 8.4No exploitEPSS 1%microsoft · 365 appsJan 13, 2026
- CVE-2026-2082032Monitor
Windows Common Log File System Driver Elevation of Privilege Vulnerability
HighCVSS 7.8Proof of conceptEPSS 3%microsoft · windows 10 1607Jan 13, 2026
- CVE-2026-2084032Monitor
Windows NTFS Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 5%microsoft · windows 10 1607Jan 13, 2026
- CVE-2026-2084332Monitor
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 3%microsoft · windows 10 1607Jan 13, 2026
+100 moreAll records of the vendor
Adobe · January 13
25 · 0 KEV · 0 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-21267No exploit | Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)adobe · dreamweaver · CWE-78 | High8.6 | — | 0.8% | Jan 13, 2026 |
34Monitor | CVE-2026-21268No exploit | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | High8.6 | — | 0.2% | Jan 13, 2026 |
34Monitor | CVE-2026-21271No exploit | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | High8.6 | — | 0.2% | Jan 13, 2026 |
34Monitor | CVE-2026-21272No exploit | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | High8.6 | — | 0.2% | Jan 13, 2026 |
34Monitor | CVE-2026-21280No exploit | Illustrator | Untrusted Search Path (CWE-426)adobe · illustrator · CWE-426 | High8.6 | — | 0.3% | Jan 13, 2026 |
31Monitor | CVE-2026-21274No exploit | Dreamweaver Desktop | Incorrect Authorization (CWE-863)adobe · dreamweaver · CWE-863 | High7.8 | — | 0.2% | Jan 13, 2026 |
31Monitor | CVE-2026-21275No exploit | InDesign Desktop | Access of Uninitialized Pointer (CWE-824)adobe · indesign · CWE-824 | High7.8 | — | 0.2% | Jan 13, 2026 |
31Monitor | CVE-2026-21276No exploit | InDesign Desktop | Access of Uninitialized Pointer (CWE-824)adobe · indesign · CWE-824 | High7.8 | — | 0.2% | Jan 13, 2026 |
31Monitor | CVE-2026-21277No exploit | InDesign Desktop | Heap-based Buffer Overflow (CWE-122)adobe · indesign · CWE-122 | High7.8 | — | 0.3% | Jan 13, 2026 |
31Monitor | CVE-2026-21281No exploit | InCopy | Heap-based Buffer Overflow (CWE-122)adobe · incopy · CWE-122 | High7.8 | — | 0.2% | Jan 13, 2026 |
31Monitor | CVE-2026-21283No exploit | Bridge | Heap-based Buffer Overflow (CWE-122)adobe · bridge · CWE-122 | High7.8 | — | 0.3% | Jan 13, 2026 |
31Monitor | CVE-2026-21287No exploit | Substance3D - Stager | Use After Free (CWE-416)adobe · substance 3d stager · CWE-416 | High7.8 | — | 0.2% | Jan 13, 2026 |
- CVE-2026-2126734Monitor
Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
HighCVSS 8.6No exploitEPSS 1%adobe · dreamweaverJan 13, 2026
- CVE-2026-2126834Monitor
Dreamweaver Desktop | Improper Input Validation (CWE-20)
HighCVSS 8.6No exploitEPSS 0%adobe · dreamweaverJan 13, 2026
- CVE-2026-2127134Monitor
Dreamweaver Desktop | Improper Input Validation (CWE-20)
HighCVSS 8.6No exploitEPSS 0%adobe · dreamweaverJan 13, 2026
- CVE-2026-2127234Monitor
Dreamweaver Desktop | Improper Input Validation (CWE-20)
HighCVSS 8.6No exploitEPSS 0%adobe · dreamweaverJan 13, 2026
- CVE-2026-2128034Monitor
Illustrator | Untrusted Search Path (CWE-426)
HighCVSS 8.6No exploitEPSS 0%adobe · illustratorJan 13, 2026
- CVE-2026-2127431Monitor
Dreamweaver Desktop | Incorrect Authorization (CWE-863)
HighCVSS 7.8No exploitEPSS 0%adobe · dreamweaverJan 13, 2026
- CVE-2026-2127531Monitor
InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
HighCVSS 7.8No exploitEPSS 0%adobe · indesignJan 13, 2026
- CVE-2026-2127631Monitor
InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
HighCVSS 7.8No exploitEPSS 0%adobe · indesignJan 13, 2026
- CVE-2026-2127731Monitor
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
HighCVSS 7.8No exploitEPSS 0%adobe · indesignJan 13, 2026
- CVE-2026-2128131Monitor
InCopy | Heap-based Buffer Overflow (CWE-122)
HighCVSS 7.8No exploitEPSS 0%adobe · incopyJan 13, 2026
- CVE-2026-2128331Monitor
Bridge | Heap-based Buffer Overflow (CWE-122)
HighCVSS 7.8No exploitEPSS 0%adobe · bridgeJan 13, 2026
- CVE-2026-2128731Monitor
Substance3D - Stager | Use After Free (CWE-416)
HighCVSS 7.8No exploitEPSS 0%adobe · substance 3d stagerJan 13, 2026
+13 moreAll records of the vendor
SAP · January 13
0 · 0 KEV · 0 criticalNo records in this window.
Siemens · January 13
3 · 0 KEV · 1 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-40805No exploit | Affected devices do not properly enforce user authentication on specific API endpoints.siemens · industrial edge cloud device (iecd) · CWE-639 | Critical10.0 | — | 0.7% | Jan 13, 2026 |
34Monitor | CVE-2025-40944No exploit | A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6Esiemens · simatic et 200al im 157-1 pn · CWE-400 | High8.7 | — | 0.4% | Jan 13, 2026 |
29Monitor | CVE-2025-40942No exploit | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4).siemens · telecontrol server basic · CWE-250 | High7.3 | — | 0.2% | Jan 13, 2026 |
- CVE-2025-4080540Plan
Affected devices do not properly enforce user authentication on specific API endpoints.
CriticalCVSS 10.0No exploitEPSS 1%siemens · industrial edge cloud device (iecd)Jan 13, 2026
- CVE-2025-4094434Monitor
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6E
HighCVSS 8.7No exploitEPSS 0%siemens · simatic et 200al im 157-1 pnJan 13, 2026
- CVE-2025-4094229Monitor
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4).
HighCVSS 7.3No exploitEPSS 0%siemens · telecontrol server basicJan 13, 2026
Schneider Electric · January 13
0 · 0 KEV · 0 criticalNo records in this window.
Oracle (Critical Patch Update) · January 20
66 · 1 KEV · 2 critical| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
92Now | CVE-2026-21962Weaponized | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serveoracle · http server · CWE-284 | Critical10.0 | KEV | 73.2% | Jan 20, 2026 |
39Monitor | CVE-2026-21969No exploit | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).oracle · agile product lifecycle management for process | Critical9.8 | — | 0.5% | Jan 20, 2026 |
34Monitor | CVE-2026-21967No exploit | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).oracle · hospitality opera 5 | High8.6 | — | 0.3% | Jan 20, 2026 |
32Monitor | CVE-2026-21955Proof of concept | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox · CWE-400 | High8.2 | — | 0.3% | Jan 20, 2026 |
32Monitor | CVE-2026-21956No exploit | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox · CWE-400 | High8.2 | — | 0.3% | Jan 20, 2026 |
32Monitor | CVE-2026-21973No exploit | Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management Syoracle · flexcube investor servicing | High8.1 | — | 0.3% | Jan 20, 2026 |
32Monitor | CVE-2026-21987No exploit | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | High8.2 | — | 0.2% | Jan 20, 2026 |
32Monitor | CVE-2026-21988No exploit | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | High8.2 | — | 0.2% | Jan 20, 2026 |
32Monitor | CVE-2026-21989No exploit | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | High8.1 | — | 0.2% | Jan 20, 2026 |
32Monitor | CVE-2026-21990No exploit | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | High8.2 | — | 0.2% | Jan 20, 2026 |
30Monitor | CVE-2026-21926No exploit | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).oracle · siebel customer relationship management deployment | High7.5 | — | 0.4% | Jan 20, 2026 |
30Monitor | CVE-2026-21940No exploit | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).oracle · supply chain products suite · CWE-200 | High7.5 | — | 0.4% | Jan 20, 2026 |
- CVE-2026-2196292Now
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serve
CriticalCVSS 10.0KEVWeaponizedEPSS 73%oracle · http serverJan 20, 2026
- CVE-2026-2196939Monitor
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).
CriticalCVSS 9.8No exploitEPSS 0%oracle · agile product lifecycle management for processJan 20, 2026
- CVE-2026-2196734Monitor
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).
HighCVSS 8.6No exploitEPSS 0%oracle · hospitality opera 5Jan 20, 2026
- CVE-2026-2195532Monitor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
HighCVSS 8.2Proof of conceptEPSS 0%oracle · vm virtualboxJan 20, 2026
- CVE-2026-2195632Monitor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
HighCVSS 8.2No exploitEPSS 0%oracle · vm virtualboxJan 20, 2026
- CVE-2026-2197332Monitor
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management Sy
HighCVSS 8.1No exploitEPSS 0%oracle · flexcube investor servicingJan 20, 2026
- CVE-2026-2198732Monitor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
HighCVSS 8.2No exploitEPSS 0%oracle · vm virtualboxJan 20, 2026
- CVE-2026-2198832Monitor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
HighCVSS 8.2No exploitEPSS 0%oracle · vm virtualboxJan 20, 2026
- CVE-2026-2198932Monitor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
HighCVSS 8.1No exploitEPSS 0%oracle · vm virtualboxJan 20, 2026
- CVE-2026-2199032Monitor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
HighCVSS 8.2No exploitEPSS 0%oracle · vm virtualboxJan 20, 2026
- CVE-2026-2192630Monitor
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).
HighCVSS 7.5No exploitEPSS 0%oracle · siebel customer relationship management deploymentJan 20, 2026
- CVE-2026-2194030Monitor
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).
HighCVSS 7.5No exploitEPSS 0%oracle · supply chain products suiteJan 20, 2026
+54 moreAll records of the vendor