Patch Tuesday cycleJanuary 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

January 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 63 operational patch records link 156 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

63Patch recordsStable operational entries, not CVE duplicates
156Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
11Accelerated actionsOut-of-band action
0Revised entriesCanonical history remains visible

January 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
63 matching recordsPage 1 of 4
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
AdobeUpdate Adobe Substance 3D Modeler to the fixed Adobe releaseAPSB26-08 · Updated 2026-01-13
Product and releaseAdobe Substance 3D Modeler1.22.5
Review linked CVEs (6) No confirmed exploitation stated

Operational summary

Adobe published APSB26-08 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 6 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-08
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (6)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB26-10 · Updated 2026-01-13
Product and releaseAdobe Substance 3D Painter11.1.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-10 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-10
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB26-11 · Updated 2026-01-13
Product and releaseAdobe Substance 3D Sampler5.1.3
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-11 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-11
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB26-12 · Updated 2026-01-13
Product and releaseAdobe ColdFusionUpdate 6, Update 18
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-12 on Patch Tuesday for Adobe ColdFusion. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-12
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Adobe priority 1

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 1 with PoC or lab evidence · max CVSS 8.4
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Designer to the fixed Adobe releaseAPSB26-13 · Updated 2026-01-13
Product and releaseAdobe Substance 3D Designer15.1.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-13 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-13
Platform
All
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important; CVSS 5.5; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 5.5
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe DreamWeaver | to the fixed Adobe releaseAPSB26-01 · Updated 2026-01-13
Product and releaseAdobe DreamWeaver |21.7
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB26-01 on Patch Tuesday for Adobe DreamWeaver |. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-01
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB26-02 · Updated 2026-01-13
Product and releaseAdobe InDesignID21.1, ID20.5.1
Review linked CVEs (5) No confirmed exploitation stated

Operational summary

Adobe published APSB26-02 on Patch Tuesday for Adobe InDesign. The bulletin links 5 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-02
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (5)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-03 · Updated 2026-01-13
Product and releaseAdobe Illustrator29.8.4 and above, 30.1 and above
Review linked CVEs (2) No confirmed exploitation stated

Operational summary

Adobe published APSB26-03 on Patch Tuesday for Adobe Illustrator. The bulletin links 2 CVEs and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-03
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 8.6; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (2)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.6
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB26-04 · Updated 2026-01-13
Product and releaseAdobe InCopy21.1, 20.5.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-04 on Patch Tuesday for Adobe InCopy. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-04
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB26-07 · Updated 2026-01-13
Product and releaseAdobe Bridge15.1.3 (LTS), 16.0.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-07 on Patch Tuesday for Adobe Bridge. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-07
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB26-09 · Updated 2026-01-13
Product and releaseAdobe Substance 3D Stager3.1.6
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

Adobe published APSB26-09 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 1 CVE and provides fixed release guidance.

Open official sourceCanonical detail record

Evidence and release

Advisory
APSB26-09
Platform
Windows and macOS
Restart
unknown
CVE state
Complete For Advisory

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Critical; CVSS 7.8; Adobe priority 3

Decision confidence: high

Known gaps and caveats

  • Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Core shared client library for PythonMSRC-2026-01-azure-change-log · Updated 2026-01-13
Product and releaseAzure Core shared client library for Python1.38.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Core shared client library for Python.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-01-azure-change-log
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Windows Admin Center in Azure PortalMSRC-2026-01-azure-release-notes · Updated 2026-01-13
Product and releaseWindows Admin Center in Azure Portal0.70.0.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Admin Center in Azure Portal.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-01-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Connected Machine AgentMSRC-2026-01-azure-release-notes · Updated 2026-01-13
Product and releaseAzure Connected Machine Agent1.60.03293.2680, 1.60.03293.809
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Connected Machine Agent.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-01-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools update for Windows SDKMSRC-2026-01-developer-tools-release-notes · Updated 2026-01-13
Product and releaseWindows SDK10.0.26100.7463
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows SDK.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-01-developer-tools-release-notes
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.0
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft ESU security update KB5073695KB5073695 · Updated 2026-01-13
Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28117
Review linked CVEs (26) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5073695
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5073696KB5073696 · Updated 2026-01-13
Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22968
Review linked CVEs (35) Confirmed exploitation

Operational summary

This official Microsoft Patch Tuesday update addresses 35 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft reports exploitation for CVE-2026-20805.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5073696
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Active Exploitation Confirmed

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5073697KB5073697 · Updated 2026-01-13
Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23717
Review linked CVEs (24) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 24 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5073697
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5073698KB5073698 · Updated 2026-01-13
Product and releaseWindows Server 2012, Windows Server 2012 (Server Core installation)6.2.9200.25868
Review linked CVEs (34) Confirmed exploitation

Operational summary

This official Microsoft Patch Tuesday update addresses 34 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft reports exploitation for CVE-2026-20805.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5073698
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Active Exploitation Confirmed

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
MicrosoftDeploy Microsoft ESU security update KB5073699KB5073699 · Updated 2026-01-13
Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28117
Review linked CVEs (26) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5073699
Platform
ESU
Restart
yes
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.