January 2026 [New Year, New Vulns, New Certs]

Episode 27   Published January 13, 2026 14 minute watch

Summary

Automox's Ryan Braunstein and Seth Hoyt open 2026 with the year's biggest patching project: Microsoft's 2011 Secure Boot Root of Trust certificates start expiring in June and October. CVE-2026-21265 means you have to update both your OS and your BIOS, or stay exposed to boot-level rootkits. Seth walks through CVE-2026-20816, a time-of-check to time-of-use race condition in the Windows Installer that lets a local attacker escalate to SYSTEM. They close on CVE-2026-20805, a Desktop Window Manager information disclosure flaw that's already being exploited in the wild and can break out of a container.