# Microsoft Patch Tuesday Fixes Exploited CVE-2026-20805

Published: 2026-01-13 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/d63be3a5-f44a-57e3-962b-b94d93a288bd/microsoft-patch-tuesday-fixes-exploited-cve-2026-20805

> IPA warns that Microsoft's January 2026 patches address a vulnerability, CVE-2026-20805, already being exploited in the wild.

IPA (Japan's Information-technology Promotion Agency) issued an alert on January 14, 2026, summarizing Microsoft's monthly security update release. The bulletin covers multiple vulnerabilities affecting Microsoft products that could allow application crashes or full attacker control of affected systems if exploited.

Of particular concern is CVE-2026-20805, which Microsoft has confirmed is being actively exploited in the wild. IPA warns that damage from this flaw could expand and urges organizations and users to apply the security updates immediately, either through automatic Windows Update or via managed patch deployment processes. No technical details of the exploitation or specific threat actors were disclosed in this advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20805 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0114-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d63be3a5-f44a-57e3-962b-b94d93a288bd/microsoft-patch-tuesday-fixes-exploited-cve-2026-20805.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
