Microsoft released fixes for 137 vulnerabilities across Windows, Azure, Microsoft 365, developer tools, and AI-related products, with no zero-days reported as exploited in the wild. The most urgent issues included a wormable pre-auth remote code execution flaw in Windows Netlogon (CVE-2026-41089), an unauthenticated RCE in the Windows DNS Client (CVE-2026-41096) that can be triggered through crafted DNS responses, and a remote code execution bug in Microsoft Dynamics 365 on-premises (CVE-2026-42898). Microsoft also patched an authenticated SharePoint Server RCE (CVE-2026-40365), multiple Microsoft Word Preview Pane RCEs, and a critical authentication bypass in the Microsoft SSO Plugin for Jira & Confluence (CVE-2026-41103).
The release was notable for its severity, with reports citing 16 to 30 critical vulnerabilities depending on classification, and 14 flaws scoring 9.0 or higher, including an Azure DevOps information disclosure issue rated CVSS 10.0 that Microsoft said had already been fully mitigated. Elevation-of-privilege bugs made up the largest share of fixes, spanning the Windows kernel, Win32k, TCP/IP, SMB Client, Print Spooler, and other core components; two locally exploitable issues, including Windows Print Spooler (CVE-2026-34342) and Windows Message Queueing (CVE-2026-33838), were publicly disclosed alongside patches. Microsoft said its AI-driven bug-finding system MDASH identified 16 of the vulnerabilities, and it separately warned enterprises to complete Secure Boot certificate updates before June 26, 2026, while noting a BitLocker Recovery issue on some Windows Server 2025 systems with an unrecommended Group Policy setting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed that its AI-based MDASH bug-hunting system identified 16 of the vulnerabilities included in the May 2026 Patch Tuesday release.
In conjunction with the May 2026 Patch Tuesday guidance, Microsoft reminded organizations of a deadline to apply Secure Boot certificate updates by June 26, 2026, and also noted a BitLocker Recovery issue affecting some Windows Server 2025 systems with an unrecommended Group Policy setting.
Coverage of the May 2026 release identified the most urgent patched issues as a wormable Windows Netlogon RCE affecting domain controllers, an unauthenticated Windows DNS Client RCE, and a Dynamics 365 on-premises RCE.
ZDI publicly disclosed CVE-2026-34342 on the same day Microsoft released a patch, describing a race condition in splwow64.exe that could let a low-privileged attacker escalate privileges.
ZDI publicly disclosed CVE-2026-33838 on the same day Microsoft released a fix, describing a double-free flaw in the mqac.sys driver that could lead to kernel-level code execution from low privileges.
As part of the May 2026 release, Microsoft said it had already fully mitigated a CVSS 10.0 Azure DevOps information disclosure vulnerability before or at disclosure time.
Microsoft issued its May 2026 Patch Tuesday security updates, fixing 137 vulnerabilities across Windows, Office, Azure, developer tools, AI products, and server components. Microsoft said no zero-days were publicly disclosed before release or known to be exploited in the wild.
Microsoft posted Security Update Guide entries for several Edge and Edge for Android issues, including CVE-2026-41107, CVE-2026-42891, CVE-2026-42838, and CVE-2026-35429.
Microsoft's Security Update Guide published CVE-2026-33821, an elevation of privilege vulnerability in Microsoft Dynamics 365 Customer Insights, ahead of the broader May Patch Tuesday release.
Researcher Marcin Wiazowski reported CVE-2026-34342, a Windows Print Spooler local privilege escalation vulnerability, to Microsoft through ZDI.
Zero Day Initiative reported CVE-2026-33838, a local privilege escalation flaw in Microsoft Windows Message Queueing, to Microsoft for coordinated disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
46 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethecyberthrone.in
Open sourcetheregister.com
Open sourceexpel.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.