logo

Microsoft Patch Tuesday for May 2026 fix 138 bugs, some of them are alarming

ID: 267aa79a-51dd-5a02-85e4-9e4e8af4778d

STIX ID: report--267aa79a-51dd-5a02-85e4-9e4e8af4778d

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-14

Author: Pierluigi Paganini

...
...

Microsoft's May 2026 Patch Tuesday fixes 138 vulnerabilities across Windows, Office, Azure, Edge, SQL Server and more, including 30 critical flaws — notably a wormable Netlogon RCE (CVE-2026-41089), a Windows DNS Client RCE (CVE-2026-41096), and a Microsoft Dynamics 365 On‑Premises code injection (CVE-2026-42898). The report emphasizes unauthenticated remote code execution risks, high CVSS scores, Preview Pane Word exploits that require no user interaction, and urges organizations to prioritize the most urgent patches to prevent large-scale domain or network compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.