Microsoft's May security release addressed 120 vulnerabilities across Windows, Office, .NET, Azure, Teams, and SharePoint, with no publicly reported zero-days at disclosure. The most urgent on-premises issues included multiple authenticated SharePoint Server remote code execution flaws—CVE-2026-33110, CVE-2026-33112, CVE-2026-35439, and CVE-2026-40357—that let users with low site-level privileges such as Site Member or Site Owner execute arbitrary code remotely through unsafe deserialization. Microsoft shipped cumulative updates for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, and noted there are no workarounds for the affected builds.
The same release also patched a large set of local privilege escalation bugs across Windows and related components, including the TCP/IP stack (CVE-2026-34351), Win32k (CVE-2026-35417), the Windows kernel (CVE-2026-35420, CVE-2026-33841), Event Logging Service (CVE-2026-33834), Cloud Files Mini Filter Driver (CVE-2026-34337), Storage Spaces Controller (CVE-2026-35415), Office Click-to-Run (CVE-2026-35436), .NET (CVE-2026-32177, CVE-2026-35433), and Azure Monitor Agent on Linux (CVE-2026-32204). Microsoft also disclosed several high-severity cloud-service vulnerabilities that were already remediated server-side, including flaws in Azure DevOps, Azure Cloud Shell, Azure Managed Instance for Apache Cassandra, Azure Machine Learning, Microsoft 365 Copilot Business Chat, Teams Events Portal, Azure Monitor, and Azure AI Foundry, meaning most customers did not need to patch those hosted services directly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
By 2026-05-18, Microsoft had addressed CVE-2026-42822 in Azure Local Disconnected Operations, applying server-side mitigation for Azure Resource Manager environments and requiring ALDO customers to update to version 2604.2.25645 or later. The flaw could allow full privilege escalation over the network when an attacker had access to the internal ALDO network and relevant identity context.
On 2026-05-12, Microsoft released updated Office Click-to-Run builds to fix CVE-2026-35436, an access control weakness that could let a low-privilege local attacker escape AppContainer and gain SYSTEM privileges. The issue affected Click-to-Run Office deployments rather than MSI-based installations.
On 2026-05-12, Microsoft disclosed and patched CVE-2026-33833 in Azure Machine Learning Notebooks. The fix was delivered in version 1.7.6 of the @azure-notebooks component, with no workaround provided.
On 2026-05-12, Microsoft fixed CVE-2026-32204 in Azure Monitor Agent by releasing build 1.14.0. The flaw allowed a low-privilege local user on Linux to gain root through path and filename manipulation in configuration message handling.
On 2026-05-12, Microsoft released fixes for .NET elevation-of-privilege flaws CVE-2026-32177 and CVE-2026-35433. Updated runtime versions were issued for supported .NET release lines, and the guidance included updating runtimes, SDKs, and republishing self-contained applications where needed.
On 2026-05-12, Microsoft fixed a broad set of Windows local privilege escalation vulnerabilities affecting the TCP/IP stack, Win32k ICOMP, Storage Spaces Controller, Windows Kernel, Event Logging Service, Cloud Files Mini Filter Driver, and other kernel components. The updates were distributed through Patch Tuesday cumulative updates and, for some platforms, hotpatches.
On 2026-05-12, Microsoft patched several authenticated remote code execution flaws in on-premises SharePoint Server, including CVE-2026-33110, CVE-2026-33112, CVE-2026-35439, and CVE-2026-40357. The fixes were delivered through cumulative updates for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, with no workarounds documented.
On 2026-05-12, Microsoft issued its May 2026 Patch Tuesday updates covering 120 vulnerabilities across Windows, Office, SharePoint, .NET, Azure components, and other products. Multiple references note that none of the vulnerabilities were marked as publicly exploited at release time.
On 2026-05-07, Microsoft publicly disclosed a set of cloud-service vulnerabilities affecting Azure DevOps, Azure Cloud Shell, Azure Managed Instance for Apache Cassandra, Azure Machine Learning, Azure Monitor, Teams Events Portal, Microsoft 365 Copilot Business Chat, Edge Copilot Chat, and Azure AI Foundry M365 agents. The referenced advisories state these issues had already been mitigated server-side and required no customer action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
36 references tracked. Mallory keeps watching after this page renders.
gs.statcounter.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcedevblogs.microsoft.com
Open sourceaka.ms
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.