Vietnam Social Security strengthens handling of Microsoft's security vulnerability just announced

Thùy Linh |

Vietnam Social Security has just strengthened the handling of Microsoft security vulnerability announced in January 2026

According to information from the Information Technology and Digital Transformation Center (Vietnam Social Security), Microsoft has just warned about 114 highly and seriously affected security vulnerabilities that exist in its products in January 2026.

These vulnerabilities can be exploited, causing unsafety for information systems that use Microsoft products, especially the Windows operating system.

The most notable point of this update is that Microsoft confirmed that there are up to three unknown vulnerabilities that have been patched, of which at least one vulnerability has been exploited in practice. This makes the January 2026 patch a top priority for security and system administrator teams.

Immediately after receiving the warning, Vietnam Social Security checked, reviewed, and identified servers and workstations using operating systems that may be affected by the above security vulnerabilities. For affected cases, patch updates are applied to the vulnerabilities according to Microsoft's instructions.

In addition, Vietnam Social Security also strengthens supervision and is ready with handling plans when detecting signs of being exploited and cyberattacked; and regularly monitors the warning channels of functional agencies and large organizations on information security to promptly detect cyberattack risks.

According to Microsoft statistics, 114 patched vulnerabilities include 57 privileged escalation vulnerabilities, 22 remote code execution vulnerabilities, 22 information leakage vulnerabilities, 5 fake vulnerabilities, 3 vulnerabilities beyond security mechanisms and 2 service denial vulnerabilities. The overall picture shows that the attack surface is still strongly focused on privileged mechanisms and memory processing.

The most dangerous vulnerability in this release is CVE-2026-20805, an information leak that does not require authentication to exploit the vulnerability. Although it does not directly allow system control, memory information leakage can become an important link in more complex exploitation chains.

This vulnerability has been included by the US Network and Infrastructure Security Agency in the list of exploited vulnerabilities, and organizations are required to complete the patch before February 3, 2026.

More worrying for the business environment is the CVE-2026-20854 vulnerability in local security services. This is a component that plays a central role in the authentication and login information management mechanism.

According to Microsoft, an attacker already has legitimate rights that can be exploited to remotely enforce code over the network, creating serious risks to internal systems and infrastructure.

With the actual vulnerability being exploited, Microsoft recommends that organizations test and deploy patches in January 2026. In the context of increasingly sophisticated attack chains and thoroughly exploiting unknown vulnerabilities, this warning is not only a periodic update but also a defense work that needs to be implemented as soon as possible.

These highly and serious security vulnerabilities can be exploited by attackers to carry out illegal acts, causing risks of information insecurity and affecting the information systems of agencies, organizations and businesses.

Thùy Linh
RELATED NEWS

Social insurance will conduct specialized inspections according to new regulations

|

New regulations on decentralizing specialized inspection of social insurance, health insurance, and unemployment insurance have just been issued.

Vietnam Social Security inspects and reviews all documents in 2026

|

Vietnam Social Security has just issued a plan to inspect and review documents in 2026.

It's a bit of a bit of a bit of a bit of a bit of a bit.

Light Concert – Opening Song of the Hanoi International Light Festival

|

On the evening of January 31, the "Light Concert - Welcoming the New Year 2026" program took place at August Revolution Square, opening the Hanoi International Light Festival.

Businesses cry out due to imported goods congestion, have to wait for instructions

|

Many types of imported goods are currently congested and cannot be cleared due to obstacles in the implementation of Decree No. 46/2026/ND-CP.

Live football Hai Phong vs The Cong Viettel in round 12 of V.League

|

Live match between Hai Phong and The Cong Viettel in round 12 of LPBank V.League 2025-2026, taking place at 6:00 PM today (January 31).

Gold falls very sharply and a series of unexpected trading suspension announcements

|

Many gold shops suddenly posted notices restricting quantities or temporarily stopping sales, making it difficult for cash holders to transact.

Vietnam Airlines records highest revenue in history in 2025

|

Informing Lao Dong Newspaper, on January 30, Vietnam Airlines said that the consolidated revenue in 2025 of this airline reached 121,429 billion VND.

Stock market regains balance amid profit-taking pressure

|

Cash flow circulating through industry groups has helped VN-Index maintain the important milestone of 1,800 points when the stock market entered a correction phase.

Cựu Giám đốc Bảo hiểm xã hội khai về khoản tiền nhận hối lộ theo trí nhớ

Việt Dũng |

Cựu Giám đốc Bảo hiểm xã hội tỉnh Bắc Giang - Thân Đức Lại bị cáo buộc nhận hối lộ từ doanh nghiệp LanQ của bị cáo Nguyễn Mạnh Quyền.

Social insurance will conduct specialized inspections according to new regulations

Thùy Linh |

New regulations on decentralizing specialized inspection of social insurance, health insurance, and unemployment insurance have just been issued.

Vietnam Social Security inspects and reviews all documents in 2026

Thùy Linh |

Vietnam Social Security has just issued a plan to inspect and review documents in 2026.

It's a bit of a bit of a bit of a bit of a bit of a bit.