BlackTreeCVE IntelligenceCanonical Patch Tuesday catalogue
January 2026 Patch Tuesday catalogue.
Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 63 operational patch records link 156 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.
January 2026 Patch Tuesday
Patch catalogue
Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.
AdobeUpdate Adobe Substance 3D Modeler to the fixed Adobe releaseAPSB26-08 · Updated 2026-01-13Product and releaseAdobe Substance 3D Modeler1.22.5Review linked CVEs (6) No confirmed exploitation stated
Operational summary
Adobe published APSB26-08 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 6 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-08
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Painter to the fixed Adobe releaseAPSB26-10 · Updated 2026-01-13Product and releaseAdobe Substance 3D Painter11.1.2Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-10 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-10
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Sampler to the fixed Adobe releaseAPSB26-11 · Updated 2026-01-13Product and releaseAdobe Substance 3D Sampler5.1.3Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-11 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-11
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe ColdFusion to the fixed Adobe releaseAPSB26-12 · Updated 2026-01-13Product and releaseAdobe ColdFusionUpdate 6, Update 18Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-12 on Patch Tuesday for Adobe ColdFusion. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-12
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Adobe priority 1
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Designer to the fixed Adobe releaseAPSB26-13 · Updated 2026-01-13Product and releaseAdobe Substance 3D Designer15.1.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-13 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-13
- Platform
- All
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important; CVSS 5.5; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe DreamWeaver | to the fixed Adobe releaseAPSB26-01 · Updated 2026-01-13Product and releaseAdobe DreamWeaver |21.7Review linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB26-01 on Patch Tuesday for Adobe DreamWeaver |. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-01
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.6; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InDesign to the fixed Adobe releaseAPSB26-02 · Updated 2026-01-13Product and releaseAdobe InDesignID21.1, ID20.5.1Review linked CVEs (5) No confirmed exploitation stated
Operational summary
Adobe published APSB26-02 on Patch Tuesday for Adobe InDesign. The bulletin links 5 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-02
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Illustrator to the fixed Adobe releaseAPSB26-03 · Updated 2026-01-13Product and releaseAdobe Illustrator29.8.4 and above, 30.1 and aboveReview linked CVEs (2) No confirmed exploitation stated
Operational summary
Adobe published APSB26-03 on Patch Tuesday for Adobe Illustrator. The bulletin links 2 CVEs and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-03
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 8.6; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe InCopy to the fixed Adobe releaseAPSB26-04 · Updated 2026-01-13Product and releaseAdobe InCopy21.1, 20.5.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-04 on Patch Tuesday for Adobe InCopy. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-04
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Bridge to the fixed Adobe releaseAPSB26-07 · Updated 2026-01-13Product and releaseAdobe Bridge15.1.3 (LTS), 16.0.1Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-07 on Patch Tuesday for Adobe Bridge. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-07
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
AdobeUpdate Adobe Substance 3D Stager to the fixed Adobe releaseAPSB26-09 · Updated 2026-01-13Product and releaseAdobe Substance 3D Stager3.1.6Review linked CVEs (1) No confirmed exploitation stated
Operational summary
Adobe published APSB26-09 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 1 CVE and provides fixed release guidance.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- APSB26-09
- Platform
- Windows and macOS
- Restart
- unknown
- CVE state
- Complete For Advisory
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Critical; CVSS 7.8; Adobe priority 3
Decision confidence: high
Known gaps and caveats
- Restart requirements are not asserted unless the reviewed bulletin states them explicitly.
MicrosoftDeploy Microsoft Azure update for Azure Core shared client library for PythonMSRC-2026-01-azure-change-log · Updated 2026-01-13Product and releaseAzure Core shared client library for Python1.38.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Core shared client library for Python.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-01-azure-change-log
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Windows Admin Center in Azure PortalMSRC-2026-01-azure-release-notes · Updated 2026-01-13Product and releaseWindows Admin Center in Azure Portal0.70.0.0Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Admin Center in Azure Portal.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-01-azure-release-notes
- Platform
- Azure
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Azure update for Azure Connected Machine AgentMSRC-2026-01-azure-release-notes · Updated 2026-01-13Product and releaseAzure Connected Machine Agent1.60.03293.2680, 1.60.03293.809Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Connected Machine Agent.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-01-azure-release-notes
- Platform
- Azure
- Restart
- no
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools update for Windows SDKMSRC-2026-01-developer-tools-release-notes · Updated 2026-01-13Product and releaseWindows SDK10.0.26100.7463Review linked CVEs (1) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows SDK.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- MSRC-2026-01-developer-tools-release-notes
- Platform
- Developer Tools
- Restart
- varies by product
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft ESU security update KB5073695KB5073695 · Updated 2026-01-13Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28117Review linked CVEs (26) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5073695
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2026-0386
- CVE-2026-20816
- CVE-2026-20820
- CVE-2026-20821
- CVE-2026-20828
- CVE-2026-20831
- CVE-2026-20833
- CVE-2026-20834
- CVE-2026-20839
- CVE-2026-20840
- CVE-2026-20843
- CVE-2026-20847
- CVE-2026-20849
- CVE-2026-20860
- CVE-2026-20868
- CVE-2026-20869
- CVE-2026-20872
- CVE-2026-20875
- CVE-2026-20921
- CVE-2026-20922
- CVE-2026-20925
- CVE-2026-20927
- CVE-2026-20929
- CVE-2026-20931
- CVE-2026-20936
- CVE-2026-20940
MicrosoftDeploy Microsoft ESU security update KB5073696KB5073696 · Updated 2026-01-13Product and releaseWindows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)6.3.9600.22968Review linked CVEs (35) Confirmed exploitation
Operational summary
This official Microsoft Patch Tuesday update addresses 35 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft reports exploitation for CVE-2026-20805.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5073696
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Active Exploitation Confirmed
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2026-0386
- CVE-2026-20805
- CVE-2026-20809
- CVE-2026-20816
- CVE-2026-20820
- CVE-2026-20821
- CVE-2026-20824
- CVE-2026-20828
- CVE-2026-20831
- CVE-2026-20833
- CVE-2026-20834
- CVE-2026-20839
- CVE-2026-20840
- CVE-2026-20843
- CVE-2026-20847
- CVE-2026-20848
- CVE-2026-20849
- CVE-2026-20856
- CVE-2026-20860
- CVE-2026-20868
- CVE-2026-20869
- CVE-2026-20872
- CVE-2026-20875
- CVE-2026-20919
- CVE-2026-20921
- CVE-2026-20922
- CVE-2026-20925
- CVE-2026-20926
- CVE-2026-20927
- CVE-2026-20929
- CVE-2026-20931
- CVE-2026-20934
- CVE-2026-20936
- CVE-2026-20940
- CVE-2026-21265
MicrosoftDeploy Microsoft ESU security update KB5073697KB5073697 · Updated 2026-01-13Product and releaseWindows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more6.0.6003.23717Review linked CVEs (24) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 24 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5073697
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2026-0386
- CVE-2026-20816
- CVE-2026-20820
- CVE-2026-20821
- CVE-2026-20828
- CVE-2026-20831
- CVE-2026-20833
- CVE-2026-20834
- CVE-2026-20840
- CVE-2026-20843
- CVE-2026-20849
- CVE-2026-20860
- CVE-2026-20868
- CVE-2026-20869
- CVE-2026-20872
- CVE-2026-20875
- CVE-2026-20921
- CVE-2026-20922
- CVE-2026-20925
- CVE-2026-20927
- CVE-2026-20929
- CVE-2026-20931
- CVE-2026-20936
- CVE-2026-20940
MicrosoftDeploy Microsoft ESU security update KB5073698KB5073698 · Updated 2026-01-13Product and releaseWindows Server 2012, Windows Server 2012 (Server Core installation)6.2.9200.25868Review linked CVEs (34) Confirmed exploitation
Operational summary
This official Microsoft Patch Tuesday update addresses 34 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft reports exploitation for CVE-2026-20805.
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5073698
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Active Exploitation Confirmed
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2026-0386
- CVE-2026-20805
- CVE-2026-20816
- CVE-2026-20820
- CVE-2026-20821
- CVE-2026-20824
- CVE-2026-20828
- CVE-2026-20831
- CVE-2026-20833
- CVE-2026-20834
- CVE-2026-20839
- CVE-2026-20840
- CVE-2026-20843
- CVE-2026-20847
- CVE-2026-20848
- CVE-2026-20849
- CVE-2026-20856
- CVE-2026-20860
- CVE-2026-20868
- CVE-2026-20869
- CVE-2026-20872
- CVE-2026-20875
- CVE-2026-20919
- CVE-2026-20921
- CVE-2026-20922
- CVE-2026-20925
- CVE-2026-20926
- CVE-2026-20927
- CVE-2026-20929
- CVE-2026-20931
- CVE-2026-20934
- CVE-2026-20936
- CVE-2026-20940
- CVE-2026-21265
MicrosoftDeploy Microsoft ESU security update KB5073699KB5073699 · Updated 2026-01-13Product and releaseWindows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)6.1.7601.28117Review linked CVEs (26) No confirmed exploitation stated
Operational summary
This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).
Open official sourceCanonical detail recordEvidence and release
- Advisory
- KB5073699
- Platform
- ESU
- Restart
- yes
- CVE state
- Complete For Update
Why this urgency
- Fix Available
- Routine Review
Vendor signal: Important
Decision confidence: high
Known gaps and caveats
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
- CVE-2026-0386
- CVE-2026-20816
- CVE-2026-20820
- CVE-2026-20821
- CVE-2026-20828
- CVE-2026-20831
- CVE-2026-20833
- CVE-2026-20834
- CVE-2026-20839
- CVE-2026-20840
- CVE-2026-20843
- CVE-2026-20847
- CVE-2026-20849
- CVE-2026-20860
- CVE-2026-20868
- CVE-2026-20869
- CVE-2026-20872
- CVE-2026-20875
- CVE-2026-20921
- CVE-2026-20922
- CVE-2026-20925
- CVE-2026-20927
- CVE-2026-20929
- CVE-2026-20931
- CVE-2026-20936
- CVE-2026-20940