logo

Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical

ID: 83c5b9d2-2bfc-5d30-b2a4-bbc81a7f283a

STIX ID: report--83c5b9d2-2bfc-5d30-b2a4-bbc81a7f283a

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Matt Kapko

...
...

Microsoft's Patch Tuesday disclosed 137 vulnerabilities across enterprise products, including 13 critical issues — notably unauthenticated remote-code-execution flaws in Windows DNS (CVE-2026-41096) and Netlogon (CVE-2026-41089), and a CVSS 9.9 Dynamics 365 vulnerability (CVE-2026-42898). While Microsoft reported no actively exploited zero-days, the vendor designated 13 defects as more likely to be exploited, and researchers warned that several of the bugs could enable broad enterprise compromise if not patched promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.