Microsoft released its May Patch Tuesday updates fixing 137 vulnerabilities across Windows, Office, Azure, Dynamics 365, SharePoint, Copilot, and other products, with no actively exploited zero-days or publicly disclosed flaws reported at release. The update included multiple high-severity remote code execution bugs, notably Microsoft Word flaws CVE-2026-40361 and CVE-2026-40364, which can be triggered through the Preview Pane by sending a malicious document, as well as CVE-2026-42898 in Microsoft Dynamics 365 On-Premises, CVE-2026-42823 in Azure Logic Apps, and CVE-2026-33109 in Azure Managed Instance for Apache Cassandra. Researchers also flagged CVE-2026-41089 in Windows Netlogon and CVE-2026-41096 in Windows DNS Client as especially urgent because they expose broadly deployed enterprise infrastructure to remote compromise.
Microsoft’s Windows 11 cumulative updates, including KB5089549 and KB5087420, delivered many of the security fixes alongside reliability and usability improvements, and Microsoft said it was not aware of new issues with the release. Coverage and advisories also showed the breadth of the month’s attack surface, with additional fixes for SharePoint Server remote code execution, Office Click-to-Run privilege escalation, Hyper-V guest-to-host escalation, Teams spoofing, Outlook for iOS tampering, and several Copilot and Visual Studio Code vulnerabilities. Security researchers said the growing volume of Microsoft disclosures may reflect increased AI-assisted vulnerability discovery, while defenders were urged to prioritize patching domain controllers, DNS-exposed Windows systems, Office deployments, and internet-facing enterprise applications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
34 events from the most recent confirmed update back to the earliest known activity.
A July 2026 report stated that Windows Netlogon remote code execution flaw CVE-2026-41089 is now being actively exploited in the wild. The report also said public proof-of-concept code is available, increasing the urgency of patching affected domain controllers.
On 2026-05-21, Microsoft published Security Update Guide entry CVE-2026-42534, described as a Jostle logic bypass vulnerability that degrades resolution performance. This is a newly documented Microsoft flaw not previously captured in the timeline.
On 2026-05-21, Microsoft published Security Update Guide entry CVE-2026-42827, an information disclosure vulnerability affecting M365 Copilot. This appears to be a newly documented Microsoft flaw not previously identified in the existing timeline.
On 2026-05-19, Microsoft published Security Update Guide entry CVE-2026-42834, an elevation-of-privilege vulnerability affecting Windows Admin Center in Azure Portal. This added a specific newly documented Microsoft flaw not previously called out in the existing timeline.
On 2026-05-12, Microsoft published CVE-2026-33834, an Important elevation-of-privilege vulnerability in the Windows Event Logging Service caused by improper access control. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered less likely, and the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-40363, a Critical Microsoft Office remote code execution vulnerability caused by a heap-based buffer overflow. Microsoft said the flaw can be exploited via a local attack vector and that the Preview Pane is an attack vector; a fix was available and the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-33839, an Important elevation-of-privilege vulnerability in Windows Win32K - GRFX caused by a race condition. The local flaw could allow an authorized low-privileged attacker to obtain SYSTEM privileges without user interaction if they win the race condition; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-34333, an Important elevation-of-privilege vulnerability in Windows Win32K-GRFX caused by use-after-free and integer overflow or wraparound conditions. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-34330, an Important elevation-of-privilege vulnerability in Windows Win32K - GRFX caused by integer overflow or wraparound and use-after-free conditions. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-41088, an Important elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock caused by external control of a file name or path. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-40397, an Important elevation-of-privilege vulnerability in the Windows Common Log File System Driver caused by an integer underflow. The local flaw could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered more likely, and the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-41102, an Important spoofing vulnerability affecting Microsoft PowerPoint for Android and Microsoft Office PowerPoint caused by improper access control. Microsoft said the local flaw could be exploited by a low-privileged authorized attacker without user interaction, that a fix was available, and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-41100, an Important spoofing vulnerability affecting Microsoft 365 Copilot for Android caused by improper access control. Microsoft said the local flaw could be exploited by a low-privileged authorized attacker without user interaction, that a fix was available, and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-34334, an Important elevation-of-privilege vulnerability in Windows TCP/IP caused by a race condition. The local flaw could allow a low-privileged authorized attacker to gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-33835, an Important elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver caused by a use-after-free flaw. The local bug could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered more likely, and the flaw was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-40360, an Important Microsoft Excel information disclosure vulnerability caused by an out-of-bounds read. The flaw can let an unauthorized attacker read small portions of heap memory if a user opens a malicious Office file; Microsoft said the Preview Pane is not an attack vector, a fix was available, and the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-40369, an Important Windows Kernel elevation-of-privilege vulnerability caused by an untrusted pointer dereference. The local flaw could let a low-privileged attacker gain limited SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered more likely, and the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-35420, an Important Windows Kernel elevation-of-privilege vulnerability caused by a heap-based buffer overflow. The local flaw could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-33841, an Important Windows Kernel elevation-of-privilege vulnerability caused by a heap-based buffer overflow. The local flaw could let a low-privileged attacker escape a low-integrity sandbox and elevate to Medium or High Integrity Level; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-34338, an Important elevation-of-privilege vulnerability in Windows Telephony Service caused by a use-after-free flaw. The local bug could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the flaw was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-40382, an Important elevation-of-privilege vulnerability in Windows Telephony Service caused by a use-after-free flaw. The local bug could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said it was neither publicly disclosed nor exploited at release and assessed exploitation as less likely.
On 2026-05-12, Microsoft published CVE-2026-32170, an Important elevation-of-privilege vulnerability in the Windows Rich Text Edit Control caused by a double-free weakness. Microsoft said exploitation requires local access, low privileges, user interaction, and winning a race condition; a fix was available and the flaw was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-40417, an Important elevation-of-privilege vulnerability in Microsoft Dynamics 365 Business Central caused by weak authentication. The local flaw could allow a low-privileged authorized attacker to gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-33833, an Important spoofing vulnerability affecting Azure Machine Learning notebooks. The network-exploitable flaw could be triggered if a user opens or views a malicious notebook in the Azure ML web interface, potentially exposing sensitive information; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-40418, an Important elevation-of-privilege vulnerability in Microsoft Office Click-To-Run caused by a use-after-free flaw. The local bug could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the flaw was neither publicly disclosed nor exploited at release.
On 2026-05-12, Microsoft published CVE-2026-35436, an Important elevation-of-privilege vulnerability in Microsoft Office Click-To-Run caused by insufficient access control granularity. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.
On 2026-05-12, Cisco Talos published analysis of Microsoft's May 2026 Patch Tuesday and released Snort 2 and Snort 3 rules to help detect exploitation attempts against some of the disclosed vulnerabilities. Talos highlighted numerous critical remote code execution issues and several elevation-of-privilege flaws considered more likely to be exploited.
On 2026-05-12, Microsoft released Windows 11 cumulative updates KB5089549 for versions 25H2/24H2 and KB5087420 for version 23H2. The mandatory updates included security fixes tied to the May Patch Tuesday release and additional reliability, usability, and performance improvements across core Windows components.
The 2026-05-12 Patch Tuesday also remediated several especially dangerous enterprise vulnerabilities, including Dynamics 365 On-Premises RCE CVE-2026-42898, Azure Logic Apps EoP CVE-2026-42823, Azure Managed Instance for Apache Cassandra RCE CVE-2026-33109, Windows Netlogon RCE CVE-2026-41089, and Windows DNS Client RCE CVE-2026-41096. Researchers warned these bugs could enable broad compromise of enterprise environments and domain controllers if left unpatched.
As part of the 2026-05-12 release, Microsoft fixed Microsoft Word remote code execution vulnerabilities including CVE-2026-40361 and CVE-2026-40364 that can be triggered through the Preview Pane by sending a malicious document, requiring no file opening by the victim. Coverage highlighted these flaws as among the most urgent issues in the release.
On 2026-05-12, Microsoft released its May 2026 Patch Tuesday updates, fixing 137 vulnerabilities across Windows, Office, Azure, Dynamics 365, SharePoint, Copilot, and other products. Multiple reports noted this was the first Patch Tuesday in nearly two years with no actively exploited zero-days or previously disclosed flaws at release time.
On 2026-05-07, Microsoft published Security Update Guide entry CVE-2026-33821, an elevation-of-privilege vulnerability affecting Microsoft Dynamics 365 Customer Insights. This is a newly documented Microsoft flaw not previously captured in the timeline.
On 2026-05-07, Microsoft published CVE-2026-26129, a Critical information disclosure vulnerability affecting M365 Copilot caused by improper neutralization of special elements. Microsoft said the network-exploitable issue was fully mitigated with no customer action required and was neither publicly disclosed nor exploited at publication.
On 2026-04-14, Microsoft's April 2026 Patch Tuesday addressed 165 vulnerabilities, including eight rated critical. Microsoft disclosed that SharePoint spoofing flaw CVE-2026-32201 had already been exploited in the wild, and Talos published Snort detection rules for the release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.