# Microsoft patches actively exploited CVE-2026-20805

Published: 2026-01-13 · Severity: high
Canonical: https://vorant.io/reports/d63be3a5-f44a-57e3-962b-b94d93a288bd/microsoft-patches-actively-exploited-cve-2026-20805

> Microsoft's January 2026 Patch Tuesday addresses multiple vulnerabilities including CVE-2026-20805, which is actively exploited in the wild.

Japan's IPA (Information-technology Promotion Agency) has issued an advisory regarding Microsoft's January 2026 security update release. The update addresses multiple vulnerabilities that could lead to application crashes or allow attackers to gain control of affected systems.

Microsoft has confirmed active exploitation of CVE-2026-20805, indicating threat actors are already leveraging this vulnerability in real-world attacks. IPA is urging organizations to apply security updates immediately to prevent further compromise. The advisory emphasizes that the threat is escalating and immediate action is required.

The updates are typically deployed automatically through Windows Update for most users. Organizations managing their own update processes should consult Microsoft's official patch documentation and expedite deployment across their environments. Systems may require a restart to complete the security update installation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20805 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/0114-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d63be3a5-f44a-57e3-962b-b94d93a288bd/microsoft-patches-actively-exploited-cve-2026-20805.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
