Illustration of an IT administrator under an umbrella as Microsoft CVEs and product logos rain down during May 2026 Patch Tuesday

Microsoft’s May Patch Tuesday Rains Down 138 Fixes

Microsoft’s May Patch Tuesday landed with the subtlety of a dump truck in a server room.

Thirty critical flaws. Hundreds of fixes. DNS, Netlogon, Office, Azure and Edge all took hits as Microsoft delivered another supersized Patch Tuesday—thankfully without an active zero-day panic attached.

Microsoft’s patches tallied 138 CVEs, including 30 rated critical. The haul brought equal parts relief and resignation to administrators quietly holding together sprawling Windows, Office, Azure and Edge environments with caffeine, caution and deferred maintenance windows.

The month’s flaws ranged from remote code execution bugs and privilege-escalation issues to spoofing, security feature bypasses and memory corruption vulnerabilities—the sort of alphabet soup attackers love and admins dread.

“This large volume of fixes follows the largest monthly release in Microsoft’s history and reflects the trend across the industry of a high number of submissions,” said Dustin Childs in Microsoft Patch Tuesday analysis published by the Zero Day Initiative.

The silver lining in this month’s bug barrage: none of the patched flaws were publicly known or under active exploitation at release time. In Patch Tuesday terms, that practically counts as a spa day.

Many of the “critical” flaws also reside in Microsoft Azure and Microsoft 365 cloud services, meaning admins won’t have to scramble through emergency maintenance windows or late-night patch rollouts for every issue. Microsoft will quietly push many of those fixes through the cloud infrastructure itself—a subtle reminder that Patch Tuesday increasingly involves trusting Microsoft to patch the plumbing while enterprises watch from the passenger seat.

Still, several vulnerabilities stood out for defenders tasked with protecting core Windows infrastructure.

At the top of the “drop everything and patch this” list is CVE-2026-41089, a critical remote code execution flaw in Windows Netlogon carrying a CVSS severity score of 9.8. The vulnerability could allow attackers to execute code remotely against one of the most sensitive parts of a Windows enterprise environment: authentication infrastructure.

If Netlogon is the month’s Darth Vader, then CVE-2026-41096 plays the role of Loki—the quieter trickster capable of causing enormous damage behind the scenes.

The flaw is a buffer overflow vulnerability in the Windows DNS Client that allows remote code execution. According to researchers, attackers would only need DNS access to a target server, opening the door to man-in-the-middle attacks, rogue DNS responses and traffic redirection shenanigans administrators never enjoy investigating at 2 a.m.

CVE-2026-42898 may be the most consequential bug for organizations still running Microsoft Dynamics 365 On-Premises. The flaw carries a CVSS score of 9.9 and stems from a code injection issue that allows an authenticated user to execute code with a scope change.

The good news is attackers need authenticated access first. The bad news is many enterprise environments still have too many overprivileged accounts, stale credentials and service accounts nobody wants to touch because someone set them up years ago and nobody is entirely sure what breaks if they are changed.

That “scope change” detail matters. It means exploitation could reach beyond the vulnerable component and affect other resources. Those bugs are uncommon, and they tend to raise the stakes because the blast radius is harder to contain. Organizations running Dynamics 365 On-Prem should treat this as a priority patch after testing.

CVE-2026-40415 is also worth attention because it sits in the Windows TCP/IP stack. The flaw is a use-after-free vulnerability that could allow remote code execution without authentication or user interaction. That makes it technically wormable.

Fortunately, this is not quite a Hollywood outbreak scenario. Exploitation requires the target to be under sustained low-memory conditions—what researchers call “memory pressure” and what many administrators might just call “a bad Tuesday.”

That limitation makes widespread exploitation less likely, but not impossible. In the wrong environment, an attacker could still weaponize the flaw to spread malicious code across vulnerable systems without users clicking a thing.

It is less Contagion and more “the server room has been running hot for three hours and nobody likes the smell coming from rack seven.”

The month’s critical bugs also touched Microsoft Office, SharePoint, Azure DevOps, Visual Studio and Windows Remote Desktop components, underscoring how sprawling Microsoft’s attack surface has become.

And because Patch Tuesday misery loves company, Adobe joined the festivities with fixes for 52 vulnerabilities across products including Adobe After Effects, Adobe Illustrator and Adobe Premiere Pro.

None of Adobe’s flaws were classified as top deployment priorities, but administrators are still being advised to update as soon as possible—because somewhere, somehow, an unpatched creative workstation is probably already opening email attachments it shouldn’t.

Shaun Nichols headshot

Shaun Nichols is an IT news journalist. He has spent nearly 20 years covering the industry with a specialty in the cybersecurity

(Image Credit: Gemini prompt “Surreal”)

Total
0
Shares
Previous Article
Rising in Cyber 2026 honoree banner outside the New York Stock Exchange featuring top cybersecurity startups.

Q1 2026 Top 30 Cybersecurity Startups

Next Article
3D isometric illustration of red cloud server rack connected to desktop and mobile devices on a dark platform, representing cloud-managed MSP firewall infrastructure

SonicWall Just Plugged the Hole in Its MSP Firewall Strategy

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading