Microsoft's January 2026 Patch Tuesday Addresses 113 CVEs Including CVE-2026-20805
Medium
Executive Summary
Microsoft’s January 2026 Patch Tuesday addresses 114 CVEs, including three zero-day vulnerabilities. The update includes fixes for 8 critical and 105 important vulnerabilities, alongside the removal of legacy Agere modem drivers (CVE-2023-31096).
Vulnerability Details
Affected Product: Windows Desktop Window Manager (DWM) - All Versions
Identifier: CVE-2026-20805
CVSS Score: 5.5 (Medium) - WARNING: Operationally Critical due to exploit utility.
Exploitation Status: Actively Exploited (Confirmed by CISA/Microsoft)
Risk & Impact
Triage: Patch within 24 hours.
Attack Vector: Local Information Disclosure.
Ease of Exploit: High utility; used in chains to bypass Address Space Layout Randomization (ASLR).
Action Plan
Immediate Action: Apply the January 2026 Cumulative Update immediately.
Relevant professional terms
CVE (Common Vulnerabilities and Exposures)
A list of publicly disclosed computer security flaws.
Zero-day Vulnerability
A computer-software vulnerability that is unknown to, or unaddressed by, those who should be mitigating the vulnerability.
MongoDB has disclosed an unauthenticated memory disclosure vulnerability, CVE 2025-14847, dubbed MongoBleed, which allows unauthorized access to sensitive data. This vulnerability has a CVSS score of 8.7 and is currently under investigation for its exploitation status.
Vulnerability Details
Affected Product: MongoDB (versions not specified)
Identifier: CVE 2025-14847
CVSS Score: 8.7 (High)
Exploitation Status:Actively Exploited (Listed in CISA KEV)
Risk & Impact
Triage: Immediate - Critical
Attack Vector: Pre-authentication remote memory scraping via compressed packets.
Ease of Exploit: Low Complexity (Public PoC available).
Action Plan
Immediate Action: Patch to versions 8.0.17+, 7.0.28+, 6.0.27+, or 5.0.32+.
Critical Step: You MUST rotate all credentials (API keys, passwords, certificates) resident on the server, as they may have been leaked.
Relevant professional terms
Memory Disclosure
A type of vulnerability where sensitive information stored in a system's memory is unintentionally revealed to unauthorized parties.
CVSS Score
A numerical score representing the severity of a security vulnerability, based on metrics like exploitability, impact, and scope.
AZ Monica, a Belgian hospital, shut down servers following a supply chain attack targeting its patient registration software vendor. The breach has affected at least five hospitals across Belgium.
Attack Overview
Attack Path: The hospital's systems experienced a serious IT disruption, leading to a proactive shutdown of all servers.
Impact Assessment
Operational Impact: The attack forced the hospital to suspend scheduled procedures, reduce emergency services, and transfer critical patients.
Strategic Takeaway
Cyberattacks on hospitals can severely disrupt critical medical services, endangering patient lives and highlighting the need for robust cybersecurity measures.
Relevant professional terms
Cyberattack
An attempt to damage or disrupt computer systems or networks.
Ransomware
A type of malware that encrypts a victim's files, with the attacker demanding a ransom to restore access.
The Void Blizzard group targeted Ukraine's Defense Forces between October and December 2025, using a charity-themed campaign to deliver the PluggyApe backdoor. The attackers used social engineering via messaging apps to trick victims into downloading malicious files.
Key TTPs
Initial Access: Instant messages via Signal and WhatsApp with links to fake charity websites.
Execution: Executable files disguised as documents (.docx.pif, .pdf.exe).
Defense Evasion: Obfuscation, anti-analysis checks, and fetching C2 addresses from paste services.
Campaign Analysis
The PluggyApe malware, written in Python, establishes communication with a remote server using WebSockets or MQTT. Newer versions feature improved obfuscation and anti-analysis to evade detection.
Targeting & Infrastructure
Target Profile: Officials of Ukraine's Defense Forces.
Infrastructure: Fake charity websites and command-and-control servers.
A Magecart campaign is actively skimming credit card data from online checkouts, targeting major payment networks like American Express, Diners Club, and Mastercard. The attackers inject malicious JavaScript into e-commerce sites to capture sensitive payment information during checkout.
Key TTPs
Initial Access: Exploitation for Client Execution via malicious JavaScript injection into e-commerce sites.
Execution: The skimming code creates a malicious iframe which renders a fake payment form, complete with relevant branding and styling, that replaces the real form.
Defense Evasion: The script checks for the existence of the "wpadminbar" element; if detected (indicating an admin is logged in), the malware self-destructs to avoid detection.
Campaign Analysis
The Magecart campaign has been active since early 2022, remaining largely undetected. The attackers use bulletproof hosting to maintain a stable environment.
Targeting & Infrastructure
Target Profile: Online shoppers and e-commerce stores are the primary targets.
Infrastructure: The campaign utilizes a network of domains and bulletproof hosting.
Actionable Intelligence
Domains: cdn-cookie[.]com
Relevant Terms
Web Skimming: A technique where malicious JavaScript code is injected into e-commerce websites to steal payment information.
Bulletproof Hosting: Hosting services that ignore abuse complaints and allow malicious activities to continue.
Taiwan's critical infrastructure is experiencing a surge in cyberattacks originating from China, with a significant increase in daily intrusion attempts in 2025. The energy sector and hospitals are particularly affected, signaling a strategic effort to disrupt essential services.
Key Findings
Chinese cyberattacks on Taiwan's critical infrastructure rose by 6% in 2025, averaging 2.63 million attacks daily.
The energy sector experienced a tenfold increase in cyberattacks.
Emergency rescue entities and hospitals saw a 54% increase in intrusion attempts.
The Bottom Line
The escalating cyber activity from China against Taiwan's critical infrastructure underscores a hybrid warfare strategy aimed at undermining the island's stability and functionality. The focus on essential services like energy and healthcare suggests an intent to disrupt daily life and erode public confidence. Organizations should prioritize strengthening their defenses, particularly against vulnerability exploitation, which accounts for over half of the attacks.
Relevant Terms
Critical Infrastructure: Assets, systems, and networks essential to a society's functioning, including energy, water, and healthcare.
Cyberattack: An attempt to gain unauthorized access to a computer system, network, or digital device with the intent to steal, alter, expose, or destroy data.
Microsoft and law enforcement disrupted the RedVDS cybercrime service, which enabled threat actors to conduct various malicious activities. The service facilitated millions in fraud losses by providing access to disposable virtual computers.
The Scheme
TTP 1: Set up servers for phishing attacks.
TTP 2: Facilitate BEC attacks and account takeover.
TTP 3: Enable financial fraud.
The Players
Threat Actor:Storm-2470
The Consequence
Outcome: Key malicious infrastructure seized and the RedVDS marketplace taken offline.
Assets Seized/Forfeited:US $40 million in reported fraud losses in the United States alone.
Strategic Takeaway
Disrupting services like RedVDS is crucial to combating the surge in cyber-enabled crime that impacts individuals, businesses, and communities.
Relevant Terms
BEC: Business Email Compromise, a type of fraud where attackers impersonate a legitimate business to steal funds or information.
RDP: Remote Desktop Protocol, a proprietary protocol developed by Microsoft which provides a user with a graphical interface to connect to another computer over a network connection.