January 2026 Patch TuesdayKB5073723Out-of-band action
Microsoft · KB5073723
KB5073723 release notes, known issues and patch guidance
This official Microsoft Patch Tuesday update addresses 70 linked CVEs for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more. Microsoft reports exploitation for CVE-2026-20805.
- Product
- Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more
- Release
- 10.0.17763.8276
- Published
- 2026-01-13
- Updated
- 2026-01-13
Out-of-band actionBlackTree recommended timinghigh confidence
70Vendor-linked CVEsComplete For Update
1Preserved revisionsCanonical history remains visible
0Known issuesVendor-documented context only
- Known issues
- Microsoft documents a known issue: Japanese characters fail to render correctly in PowerShell.
- Issue resolution
- Microsoft points to KB5082123 as a resolution in this article. Confirm applicability in the official source.
- CVEs named in article
- The article does not name CVE identifiers directly; see the separately sourced patch relationships below.
- Deployment sections
- No prerequisite or restart section verified
- Snapshot
- Captured 28 Sept 2026, 02:48 UTC.
Action and evidence
Operational decision
- Action type
- Deploy Patch
- Platform
- Windows
- Restart
- yes
- Vendor signal
- Critical
Why this urgency
- Fix Available
- Active Exploitation Confirmed
Evidence signals kept separate
- CISA KEV
- Unknown
- Confirmed exploitation
- Confirmed
- Vendor exploitability
- Microsoft reports exploitation
- Maximum CVSS
- 8.8 (CVSS 3.1, CVE-2026-20868)
- Maximum EPSS
- Not loaded for this patch record
Out-of-band actionBlackTree recommends an out-of-band change assessment. Do not wait for the normal patch window when this update applies, but still use tested deployment and rollback controls.
BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.
Environment override questions
- Is Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more exposed to untrusted networks or content?
- Does this update affect an identity, management, backup or other control-plane system?
- Are compensating controls tested and monitored until the selected patch window?
Deployment context
Effects and caveats
- Use the vendor update channel or update catalogue entry for the applicable product release.
- Plan a restart when the vendor remediation marks one as required.
Known data gaps
- Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Deployment plan
Guidance basis: Blacktree Generic
Prerequisites
- Confirm the affected product, edition, architecture and current build before deployment.
Sequencing
- Test the update in a representative deployment ring before broad release.
Downtime
A restart is required. Plan service interruption and validation.
Rollback and recovery
- Capture the current version and a recoverable backup or snapshot before the change.
- Use the vendor-supported uninstall or recovery path when one is available.
Workarounds
- No vendor workaround is asserted unless it appears in the official advisory.
Provenance
Field verification
- Patch_identity_and_productsmsrc-cvrf/vendor-fixVerified Automatic · Retrieved 26 Aug 2026, 11:55 UTC
- Cve_relationships_and_exploit_statusmsrc-cvrf/vulnerabilityVerified Automatic · Retrieved 26 Aug 2026, 11:55 UTC
Open official vendor sourceRevision history
Canonical record changes
- Revision 12026-01-13
Initial Patch Tuesday publication.
Publication review
The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner approved automatic Patch Tuesday publication. Each published record passed its own official-source completeness gate. Pending sources expose readiness only and prior approved records are retained on refresh failure.