INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Fixes Critical Flaws in May Patch Tuesday

| 2026-05-13 08:15 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
Cybersecurity experts are sounding the alarm after Microsoft revealed a staggering 120 critical vulnerabilities in its latest patch Tuesday, with 16 of them being newly discovered by a multi-model agentic security system. The list includes remote code execution (RCE) exploits, elevation of privilege (EoP) flaws, and information disclosure vulnerabilities that could compromise endpoint security across corporate networks. Microsoft's Windows Attack Research and Protection team has been credited with identifying multiple critical vulnerabilities in the software, highlighting the need for swift action to prevent widespread disruption.
Technical Mitigations AI-generated
• Microsoft has implemented a new "agentic security harness" system, MDASH, which uses over 100 specialized agents across multiple models to find novel vulnerabilities. • The multi-model agentic scanning harness runs a configurable panel of models, including SOTA (State-of-the-art) and distilled models for high-volume passes. • Microsoft's Windows Attack Research and Protection (WARP) team collaborated with the WARP team on a new "agentic security" initiative to discover 16 critical vulnerabilities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sn•••••.org
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-41096CVE-2026-41096 CVE-2026-41089CVE-2026-41089 CVE-2026-40415CVE-2026-40415 CVE-2026-40397CVE-2026-40397 CVE-2026-40365CVE-2026-40365 CVE-2026-40364CVE-2026-40364 CVE-2026-40358CVE-2026-40358 CVE-2026-40398CVE-2026-40398 CVE-2026-42823CVE-2026-42823 CVE-2026-32161CVE-2026-32161 CVE-2026-42831CVE-2026-42831 CVE-2026-35421CVE-2026-35421 CVE-2026-33109CVE-2026-33109 CVE-2026-33841CVE-2026-33841 CVE-2026-40366CVE-2026-40366 CVE-2026-33835CVE-2026-33835 CVE-2026-40403CVE-2026-40403 CVE-2026-40363CVE-2026-40363 CVE-2026-35417CVE-2026-35417 CVE-2026-42898CVE-2026-42898 CVE-2026-40361CVE-2026-40361 CVE-2026-40367CVE-2026-40367 CVE-2026-40369CVE-2026-40369 CVE-2026-33837CVE-2026-33837 CVE-2026-41103CVE-2026-41103 CVE-2026-33840CVE-2026-33840 CVE-2026-35416CVE-2026-35416 CVE-2026-33844CVE-2026-33844
Target & Sectors
Global Scope
Incident Timeline
‎12 May
Microsoft explained in a blog post on May 12 that WARP collaborated with its Autonomous Code Security (ACS) team to identify 16 Critical Vulnerabilities Exploited by Threat Actors.
‎2026/05/13
Microsoft addressed 137 vulnerabilities in May's Patch Tuesday, including 13 rated critical.
organisation Microsoft Dynamics 365 On-Premises
organisation Microsoft Dynamics
infrastructure Windows
organisation Microsoft Dynamics 365
organisation Netlogon
organisation the Windows DNS Client, Dynamics 365
organisation Microsoft Word
organisation Windows DNS Client
organisation Microsoft Windows
organisation Microsoft Office
infrastructure Android
organisation Microsoft SharePoint
organisation Windows Graphics Component
organisation the Windows TCP
organisation CVE-2026-41089
organisation CVE-2026
organisation CVE-2026-40361
organisation Remote Desktop Client
organisation Microsoft Fixes
organisation Critical Flaws
organisation CVSS
organisation AI-Powered Vulnerability Research
organisation Windows Attack Research and Protection
organisation Windows Remote Desktop
organisation Office,
organisation Copilot
organisation Telnet
organisation DNS
organisation the Windows DNS Client
organisation DNS Client
organisation the DNS Client
organisation Win32k Elevation of Privilege Vulnerability
organisation Windows Ancillary Function
organisation WinSock Elevation of Privilege Vulnerability
organisation Windows Win32k
organisation Microsoft
organisation Dynamics CRM
organisation CVSS Critical
organisation Microsoft SSO Plugin for Jira &
organisation Critical
organisation TCP
organisation Preview Pane
organisation SecurityAffairs
organisation Azure Managed Instance for Apache Cassandra
organisation Trend Micro’s Zero Day Initiative
organisation Microsoft’s Security Response Center
infrastructure 365 infrastructure
organisation Microsoft Office Word
organisation Enhanced Metafile
organisation EMF
organisation Microsoft Paint
organisation Office
organisation Cisco Security Firewall
organisation SRU
organisation Snort 3
‎May 2026
Microsoft released a monthly security update for May 2026, which included fixes for 138 vulnerabilities across various products.
infrastructure Windows
organisation Microsoft
organisation Windows, Office
tactic T1584.004 - Server
general_metric 138 bugs
general_metric 30 critical bugs
vulnerability CVE-2026-42898
general_metric 365 Microsoft Dynamics
tactic Remote Code Execution
vulnerability CVSS score of 9.9
infrastructure 9.9
organisation Microsoft Patch
organisation Snort
general_metric 31 RCE
general_metric 137 vulnerabilities
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎9.9
Software Version
Metrics
infrastructure
365
Infrastructure
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎Android
Affected Product
Intelligence Sources