EXECUTIVE SUMMARY
Microsoft’s January 2026 Patch Tuesday fixes 114 vulnerabilities, including three zero-days and multiple critical RCE and elevation-of-privilege flaws. Organizations should urgently prioritize zero-days, LSASS, SMB, internet-facing services, and Office to reduce exploitation risk.
- Active Region: Global
- Affected Sector: All sectors using Windows and Microsoft Office, including enterprise IT and developer environments.
- Affected Product: Microsoft Windows, Microsoft Office (Word, Excel), SharePoint Server, Azure components
- Severity: Critical – including three zero-days.
- Published Date: January 14, 2026
CVE DETAILS
- …..



