logo

Microsoft May 2026 Patch Tuesday: Many fixes, but no zero-days

ID: 51c03afe-304a-571c-a313-8d3c95b0b3f9

STIX ID: report--51c03afe-304a-571c-a313-8d3c95b0b3f9

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Zeljka Zorz

...
...

Microsoft's May 2026 Patch Tuesday addresses 120+ CVE-numbered vulnerabilities; the report highlights critical remote code execution and privilege escalation flaws in Microsoft Word (including CVE-2026-40361 and CVE-2026-40364), a pre-auth Netlogon stack overflow affecting domain controllers (CVE-2026-41089), a Hyper-V elevation-of-privilege (CVE-2026-40402), and a DNS Client RCE (CVE-2026-41096). None are currently reported as actively exploited, but their severity and broad Windows attack surface make prompt patching — especially for domain controllers, Hyper-V hosts, and systems behind compromised DNS resolvers — a high priority.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.