Microsoft released its monthly security updates addressing 137 vulnerabilities across its product portfolio, and Hungary's National Cyber Security Center (NBSZ NKI) warned that the flaws affect a broad range of Microsoft software. The alert said none of the patched issues were known to be publicly disclosed zero-days or actively exploited before the fixes were issued, but it still urged organizations to deploy the updates without delay through automatic update channels or manual installation.
The release notes include a large set of Chromium-based browser vulnerabilities affecting Microsoft Edge and Google Chrome, spanning identifiers such as CVE-2026-7896 through CVE-2026-8022, CVE-2026-8509 through CVE-2026-8587, and CVE-2026-9110 through CVE-2026-9126, alongside an AMD CPU branch vulnerability tracked as CVE-2025-54518. While the published material provides limited technical detail on impact or exploitation, the breadth of affected components highlights the need for prompt enterprise patching and validation across endpoints, browsers, and hardware-dependent systems.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released security updates on July 6, 2026 to remediate multiple vulnerabilities across several products. The advisory highlighted issues including CVE-2026-57100 in Microsoft Entra Provisioning Service and CVE-2026-58289 in Chromium-based Microsoft Edge, and recommended prompt patch deployment after testing.
Hungary's National Cyber Security Center issued an alert warning about critical-risk vulnerabilities affecting Microsoft products, citing the severity, exploitability, and broad deployment of the affected software. It urged users to install the available updates immediately via automatic update mechanisms or manual download.
Microsoft's May 2026 monthly security update package fixed 137 distinct vulnerabilities across a wide range of products, including Windows components, Office, Azure services, Edge, Teams, SQL Server, Visual Studio, and Copilot-related offerings. The Hungarian NBSZ NKI alert states Microsoft reported that none of the patched flaws were publicly disclosed zero-days or actively exploited before release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
egfincirt.org.eg
Open sourcenki.gov.hu
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.