INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Patches 138 Vulnerabilities

| 2026-05-13 10:36 CRITICAL HIGH
Executive Summary AI-generated
The patch wave is gaining momentum, with Microsoft on pace to break its annual vulnerability record. The company has already patched over 500 vulnerabilities this year alone, including a critical flaw in Windows Netlogon and another in the DNS Client. This trend suggests that AI-driven vulnerability discovery will continue to scale, making it increasingly difficult for organizations to stay ahead of threats. As researchers like Tom Gallagher at Microsoft's Security Response Center note, "The findings in this Patch Tuesday and the retrospective recall on five years of CLFS MSRC cases are evidence that AI vulnerability findings can scale." This implies that companies must be prepared to adapt their patching strategies as new vulnerabilities emerge.
Technical Mitigations AI-generated
* Implement a robust vulnerability scanning and monitoring system: Utilize AI-driven tools to continuously scan for vulnerabilities across the organization's software, hardware, and infrastructure. This can help identify potential security threats before they become actual issues. * Develop an incident response plan that leverages AI-powered threat detection: Create a comprehensive plan that incorporates AI-assisted threat detection, rapid analysis of incidents, and swift action to mitigate damage. This will enable the organization to respond effectively to emerging threats in real-time. * Regularly update software with known vulnerabilities patched: Ensure all critical software updates are applied promptly, even if they don't have any human researcher identifying them first. AI-powered tools can help identify potential issues before they become actual problems. * Implement a secure coding practice that encourages responsible AI development: Foster an environment where developers feel comfortable contributing to security research and testing without fear of retribution or negative consequences. This will encourage the use of AI-driven vulnerability detection in software development. * Develop a culture of continuous learning and improvement: Encourage employees to stay up-to-date with emerging threats, vulnerabilities, and best practices through regular training sessions, workshops, and online resources. This will help ensure that security measures are always aligned with industry standards and best practices.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud CVE-2026-32177CVE-2026-32177 CVE-2026-41095CVE-2026-41095 CVE-2026-41097CVE-2026-41097 CVE-2026-35420CVE-2026-35420 CVE-2026-34331CVE-2026-34331 CVE-2026-35433CVE-2026-35433 CVE-2026-35422CVE-2026-35422 CVE-2026-32204CVE-2026-32204 CVE-2026-32209CVE-2026-32209 CVE-2026-40369CVE-2026-40369 CVE-2026-34345CVE-2026-34345 CVE-2026-40406CVE-2026-40406 CVE-2026-33834CVE-2026-33834 CVE-2026-33837CVE-2026-33837 CVE-2026-40357CVE-2026-40357 CVE-2026-41611CVE-2026-41611 CVE-2026-41109CVE-2026-41109 CVE-2026-32161CVE-2026-32161 CVE-2026-33844CVE-2026-33844 CVE-2026-33840CVE-2026-33840 CVE-2026-40403CVE-2026-40403 CVE-2026-26164CVE-2026-26164 CVE-2026-34350CVE-2026-34350 CVE-2026-35423CVE-2026-35423 CVE-2026-40381CVE-2026-40381 CVE-2026-34347CVE-2026-34347 CVE-2026-35415CVE-2026-35415 CVE-2026-41100CVE-2026-41100 CVE-2026-42826CVE-2026-42826 CVE-2026-40374CVE-2026-40374 CVE-2025-54518CVE-2025-54518 CVE-2026-33835CVE-2026-33835 CVE-2026-40358CVE-2026-40358 CVE-2026-40379CVE-2026-40379 CVE-2026-35417CVE-2026-35417 CVE-2026-40413CVE-2026-40413 CVE-2026-34340CVE-2026-34340 CVE-2026-21530CVE-2026-21530 CVE-2026-35438CVE-2026-35438 CVE-2026-40401CVE-2026-40401 CVE-2026-40363CVE-2026-40363 CVE-2026-40415CVE-2026-40415 CVE-2026-40377CVE-2026-40377 CVE-2026-33841CVE-2026-33841 CVE-2026-40368CVE-2026-40368 CVE-2026-34334CVE-2026-34334 CVE-2026-34336CVE-2026-34336 CVE-2026-42825CVE-2026-42825 CVE-2026-40362CVE-2026-40362 CVE-2026-42832CVE-2026-42832 CVE-2026-40361CVE-2026-40361 CVE-2026-35419CVE-2026-35419 CVE-2026-40370CVE-2026-40370 CVE-2026-34341CVE-2026-34341 CVE-2026-42898CVE-2026-42898 CVE-2026-33109CVE-2026-33109 CVE-2026-35421CVE-2026-35421 CVE-2026-41094CVE-2026-41094 CVE-2026-33117CVE-2026-33117 CVE-2026-33112CVE-2026-33112 CVE-2026-42899CVE-2026-42899 CVE-2026-42896CVE-2026-42896 CVE-2026-34330CVE-2026-34330 CVE-2026-41612CVE-2026-41612 CVE-2026-41102CVE-2026-41102 CVE-2026-42833CVE-2026-42833 CVE-2026-40410CVE-2026-40410 CVE-2026-34344CVE-2026-34344 CVE-2026-40366CVE-2026-40366 CVE-2026-40397CVE-2026-40397 CVE-2026-40365CVE-2026-40365 CVE-2026-35416CVE-2026-35416 CVE-2026-40360CVE-2026-40360 CVE-2026-40402CVE-2026-40402 CVE-2026-33839CVE-2026-33839 CVE-2026-34343CVE-2026-34343 CVE-2026-40417CVE-2026-40417 CVE-2026-40418CVE-2026-40418 CVE-2026-32185CVE-2026-32185 CVE-2026-35418CVE-2026-35418 CVE-2026-40398CVE-2026-40398 CVE-2026-34332CVE-2026-34332 CVE-2026-40408CVE-2026-40408 CVE-2026-32170CVE-2026-32170 CVE-2026-35440CVE-2026-35440 CVE-2026-40464CVE-2026-40464 CVE-2026-40364CVE-2026-40364 CVE-2026-34351CVE-2026-34351 CVE-2026-35436CVE-2026-35436 CVE-2026-42823CVE-2026-42823 CVE-2026-35439CVE-2026-35439 CVE-2026-33833CVE-2026-33833 CVE-2026-34342CVE-2026-34342 CVE-2026-41089CVE-2026-41089 CVE-2026-40382CVE-2026-40382 CVE-2026-33823CVE-2026-33823 CVE-2026-41101CVE-2026-41101 CVE-2026-40380CVE-2026-40380 CVE-2026-35424CVE-2026-35424 CVE-2026-41613CVE-2026-41613 CVE-2026-42893CVE-2026-42893 CVE-2026-40367CVE-2026-40367 CVE-2026-32175CVE-2026-32175 CVE-2026-34329CVE-2026-34329 CVE-2026-34337CVE-2026-34337 CVE-2026-42831CVE-2026-42831 CVE-2026-41088CVE-2026-41088 CVE-2026-35428CVE-2026-35428 CVE-2026-41614CVE-2026-41614 CVE-2026-40405CVE-2026-40405 CVE-2026-40399CVE-2026-40399 CVE-2026-34339CVE-2026-34339 CVE-2026-40421CVE-2026-40421 CVE-2026-41610CVE-2026-41610 CVE-2026-40419CVE-2026-40419 CVE-2026-41086CVE-2026-41086 CVE-2026-41096CVE-2026-41096 CVE-2026-40420CVE-2026-40420 CVE-2026-40414CVE-2026-40414 CVE-2026-40359CVE-2026-40359 CVE-2026-33110CVE-2026-33110 CVE-2026-42830CVE-2026-42830 CVE-2026-40407CVE-2026-40407 CVE-2026-34333CVE-2026-34333 CVE-2026-41103CVE-2026-41103 CVE-2026-34338CVE-2026-34338 CVE-2026-33838CVE-2026-33838
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎November 2025
Threat actors exploited a previously unknown vulnerability in Microsoft's Windows operating system to gain unauthorized access.
‎2026/04/13
Threat actors used AI-assisted vulnerability discovery to target organizations.
organisation National Cyber Security Centre
‎2026/05/13
Microsoft released patches for 138 security vulnerabilities across its product portfolio.
organisation CPU
organisation CVE-2025-54518
organisation AMD
organisation CVE-2026
organisation CVE-2026-32204
organisation CVE-2026-42830
infrastructure Visual Studio Code
organisation CPU Branch
organisation Important Data Deduplication CVE-2026-41095
organisation GitHub Copilot
organisation CVE-2026-41096
infrastructure Windows
organisation CVE-2026-41089
organisation Microsoft Office
organisation DNS
organisation Microsoft Dynamics 365
organisation Microsoft Teams
organisation Microsoft SSO Plugin for Jira &
organisation CVE-2026-40370
organisation CVE-2026-34343
organisation CVE-2026-34341
organisation CVE-2026-40406
organisation CVE-2026-34334
infrastructure Microsoft 365
infrastructure Android
infrastructure Ios
organisation Microsoft 365 Copilot
organisation Microsoft Outlook
organisation Copilot for Desktop CVE-2026-41614
organisation Microsoft Data Formulator CVE-2026-41094
organisation Microsoft Data
organisation Microsoft Office Click-To-Run CVE-2026-35436
organisation Microsoft Office Click-To-Run CVE-2026-40420
organisation Microsoft Office Click-To-Run CVE-2026-40418
organisation Microsoft Office Excel
organisation Microsoft Office PowerPoint
organisation Microsoft PowerPoint
organisation Microsoft Office SharePoint
organisation Microsoft SharePoint
organisation Microsoft Office Word CVE-2026-40367
organisation Microsoft Office Word CVE-2026-35440
organisation Microsoft Word
organisation Microsoft Office Word CVE-2026-40364
organisation Windows DNS Client
organisation Windows Admin Center
organisation Windows Ancillary Function
organisation Windows Application Identity
organisation WFP
organisation Internet Key Exchange
organisation Windows WAN
organisation Windows Lightweight Directory Access Protocol
organisation Microsoft Message Queuing
organisation Windows Message Queuing
organisation Windows TCP
organisation K - GRFX
data_breach 40410 Important Windows SMB Client
infrastructure 34350 Miniport Driver Denial
infrastructure 34334 IP Elevation
organisation CVE-2026-35417
organisation CVE-2026-33840
organisation Windows Graphics Component
organisation K - ICOMP
organisation Entra ID
infrastructure 7.3
organisation CVSS
organisation Microsoft Office Word
organisation the Windows DNS Client
organisation the DNS Client
organisation Patch Tuesday
organisation Netlogon
organisation Netlogon Flaw
organisation Automox
infrastructure 10.0
organisation CVE-2026-33109
infrastructure 9.0
infrastructure 9.9
organisation Microsoft Patch
organisation Azure Managed Instance for Apache Cassandra
organisation CVE-2026-42898
organisation Dynamics CRM
organisation CVE-2026-33823
organisation CVE-2026-40379
organisation CVE-2026-40361
infrastructure 8.4
organisation Microsoft
organisation Netlogon RCE Flaws
organisation Critical
organisation Important
organisation Google
organisation Chromium
organisation Azure SDK
organisation Nightwing
organisation Microsoft Security Response Center
organisation MFA
infrastructure 365 infrastructure
infrastructure Linux
organisation Copy Fail
organisation Security Update Guide
organisation Microsoft’s Security Response Center
organisation CLFS MSRC
organisation Apple
organisation Project Glasswing
organisation Glasswing
organisation HackerOne
organisation Cohesity
organisation Azure Service Health
organisation CVE
organisation Copilot
organisation Tyler Reguly
organisation CVE Title Severity
‎May 2026
Microsoft released a May 2026 update containing fixes for 137 vulnerabilities, including 13 high-priority ones.
organisation Microsoft
general_metric 120 flaws
‎June 26, 2026
Threat actors exploited a vulnerability in Microsoft's Windows operating system to gain unauthorized access.
‎June 26
Threat actors used Microsoft's Patch Tuesday to deploy a critical update that failed to install on devices before the June 26 deadline, resulting in catastrophic boot-level security failures.
‎the June 26, 2026
Threat actors used Microsoft's Patch Tuesday to deploy a vulnerability fix that targeted multiple systems across the globe.
Tactical Metrics
Metrics
infrastructure
‎7.3
Software Version
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
365
Infrastructure
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎8.4
Software Version
Metrics
infrastructure
‎9.0
Software Version
Metrics
infrastructure
‎9.9
Software Version
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
infrastructure
‎Android
Affected Product
Metrics
infrastructure
‎Ios
Affected Product
Metrics
data_breach
40,410
Important Windows Smb Client
Metrics
infrastructure
34,350
Miniport Driver Denial
Metrics
infrastructure
34,334
Ip Elevation