Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Cybersecurity News
Cybersecurity News

Microsoft's January 2026 Patch Tuesday lands; New York cyber officials urge immediate updates

Microsoft shipped its January 2026 security fixes on January 13, and state advisories flag remote code execution bugs as the most severe issues patched.

Malik Johnson, · January 14, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
IT administrator approving updates across office computers

Microsoft released its January 2026 Patch Tuesday security updates on January 13, 2026, fixing a batch of vulnerabilities across Windows and related products. The most severe flaws allow remote code execution, meaning an attacker can run software on an unpatched machine without the user doing anything careless. New York's Office of Information Technology Services flagged the rollout in advisory 2026-002 on January 13, urging organizations to apply the updates promptly — routine language for these monthly releases, but consistent with the risk level of the bugs involved.

What is in the advisory?

The New York ITS advisory, published January 13, 2026, covers multiple vulnerabilities in Microsoft products and rates the most severe as enabling remote code execution, per the advisory text. It follows Microsoft's standard monthly cadence, in which fixes ship on the second Tuesday of each month and enterprise admins stage deployment over the following days. Specific counts and CVE-level detail live in Microsoft's Security Update Guide; this report will be updated if exploitation of any January flaw is confirmed in the wild.

Are any of the flaws being exploited?

Not confirmed in the material published as of January 14, 2026. When a January flaw does come under active attack, the usual markers follow quickly: CISA adds it to its Known Exploited Vulnerabilities catalog, and vendor advisories gain exploitation notes. None of that had appeared for this release at the time of writing. Treat that as a snapshot, not a promise — most actively exploited Windows flaws were patched before attackers picked them up, sometimes months earlier.

What should you do now?

  1. Windows home users: open Settings > Windows Update and click Check for updates. Install everything offered and reboot when asked. The January fixes arrive as a cumulative update, so one restart completes it.
  2. Microsoft 365 and Office users: let the apps auto-update, or force it via File > Account > Update Options in the desktop apps.
  3. Businesses: prioritize internet-facing systems — exchange and collaboration servers, remote-access hosts, and exposed IIS boxes — then standard workstations, per the standard deployment ring approach the ITS advisory and Microsoft both recommend.
  4. Check CISA's KEV catalog over the coming weeks; if any January CVE lands there, its patch deadline becomes immediate for federal networks and a sensible deadline for everyone else.

Microsoft's Patch Tuesday remains the single most reliable maintenance rhythm in consumer security: showing up for it every month closes the majority of the doors attackers actually walk through.

Frequently Asked Questions

When was Microsoft's January 2026 Patch Tuesday?
January 13, 2026 — the second Tuesday of the month, matching Microsoft's standard release cadence. New York ITS published its corresponding advisory the same day.
Were any January 2026 flaws known to be exploited at release?
No exploitation was confirmed in advisories published as of January 14, 2026. Confirmation typically surfaces days or weeks later via CISA's Known Exploited Vulnerabilities catalog, which is worth monitoring after each Patch Tuesday.
Do home users need to do anything special?
No — open Windows Update, install everything, and reboot. The fixes are cumulative, so a fully updated Windows machine needs no extra steps beyond enabling automatic updates.