logo

Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs

ID: 702a7cfa-038e-53f3-a41d-3de14b26ecb9

STIX ID: report--702a7cfa-038e-53f3-a41d-3de14b26ecb9

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-13

...
...

Microsoft released fixes for 137 CVEs including 30 critical flaws; notable high-severity RCEs include CVE-2026-41096 (Windows DNS Client heap overflow allowing unauthenticated RCE), CVE-2026-41089 (Netlogon stack overflow, wormable unauthenticated RCE), and CVE-2026-42898 (Dynamics 365 on-premises RCE). Microsoft reports no known active exploitation and has mitigated a 10.0-rated Azure DevOps information disclosure; administrators are urged to prioritize testing and deploying patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.