Microsoft released its January 2026 Patch Tuesday security updates on January 13, 2026, fixing a batch of vulnerabilities across Windows and related products. The most severe flaws allow remote code execution, meaning an attacker can run software on an unpatched machine without the user doing anything careless. New York's Office of Information Technology Services flagged the rollout in advisory 2026-002 on January 13, urging organizations to apply the updates promptly — routine language for these monthly releases, but consistent with the risk level of the bugs involved.
What is in the advisory?
The New York ITS advisory, published January 13, 2026, covers multiple vulnerabilities in Microsoft products and rates the most severe as enabling remote code execution, per the advisory text. It follows Microsoft's standard monthly cadence, in which fixes ship on the second Tuesday of each month and enterprise admins stage deployment over the following days. Specific counts and CVE-level detail live in Microsoft's Security Update Guide; this report will be updated if exploitation of any January flaw is confirmed in the wild.
Are any of the flaws being exploited?
Not confirmed in the material published as of January 14, 2026. When a January flaw does come under active attack, the usual markers follow quickly: CISA adds it to its Known Exploited Vulnerabilities catalog, and vendor advisories gain exploitation notes. None of that had appeared for this release at the time of writing. Treat that as a snapshot, not a promise — most actively exploited Windows flaws were patched before attackers picked them up, sometimes months earlier.
What should you do now?
- Windows home users: open Settings > Windows Update and click Check for updates. Install everything offered and reboot when asked. The January fixes arrive as a cumulative update, so one restart completes it.
- Microsoft 365 and Office users: let the apps auto-update, or force it via File > Account > Update Options in the desktop apps.
- Businesses: prioritize internet-facing systems — exchange and collaboration servers, remote-access hosts, and exposed IIS boxes — then standard workstations, per the standard deployment ring approach the ITS advisory and Microsoft both recommend.
- Check CISA's KEV catalog over the coming weeks; if any January CVE lands there, its patch deadline becomes immediate for federal networks and a sensible deadline for everyone else.
Microsoft's Patch Tuesday remains the single most reliable maintenance rhythm in consumer security: showing up for it every month closes the majority of the doors attackers actually walk through.
For more context, read Microsoft's April 2026 Patch Tuesday fixes 163 bugs, including two exploited zero-days.
For more context, read oracle critical patch update january 2026.
For more context, read cisa kev catalog march 2026.

