logo

Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)

ID: e6a41691-46af-5255-8e55-fee9d2e425c8

STIX ID: report--e6a41691-46af-5255-8e55-fee9d2e425c8

Feed Name: Tenable Blog

Threat Score
70/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Research Special Operations

...
...

Microsoft's May 2026 Patch Tuesday addressed 118 CVEs (16 critical, 102 important), with elevation-of-privilege issues comprising ~48.3% and remote code execution ~24.6% of fixes. Notable fixes include a critical Microsoft SSO Plugin for Jira & Confluence EoP (CVE-2026-41103, CVSS 9.1, Exploitation More Likely), multiple Windows Kernel EoPs (CVE-2026-33841, CVE-2026-35420, CVE-2026-40369), several Microsoft Word RCEs exploitable via emailed/malicious documents, and a high-severity Netlogon RCE (CVE-2026-41089, CVSS 9.8) assessed as “Exploitation Less Likely.” Tenable recommends prompt patching and scanning to identify unpatched systems; Microsoft reported no zero-days observed exploited in the wild for this release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.