INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ATTENTION: This report is based on previous data. New intelligence sources have been linked and the Executive Summary and Mitigations need to be re-synthesized.

Microsoft Fixes 17 Critical Flaws in May Patch Tuesday

| 2026-05-13 08:15 CRITICAL HIGH
Executive Summary AI-generated
The recent patch Tuesday for May 2026 has fixed a plethora of critical vulnerabilities across Microsoft's portfolio, including Windows and Office. A notable exploit was the remote code execution (RCE) vulnerability in the Windows DNS Client, which could be used to silently compromise large enterprise networks without authentication or user interaction. This bug carried a CVSS score of 9.8, making it one of the most urgent patches in recent security updates. The patch also fixed several other notable vulnerabilities, including those in Microsoft Dynamics 365 On-Premises and Windows Netlogon, which could potentially allow unauthenticated remote code execution without user interaction or authentication.
Technical Mitigations AI-generated
* Implement secure coding practices: Ensure that developers and testers follow best practices for secure coding, such as using input validation, sanitizing user input, and avoiding buffer overflows. * Regularly update software and systems: Keep all operating systems, applications, and services up to date with the latest security patches and updates to ensure that known vulnerabilities are addressed before they can be exploited. * Use secure protocols for communication: Ensure that network connections use secure protocols such as HTTPS or SFTP instead of unencrypted protocols like HTTP or FTP. This helps prevent eavesdropping and man-in-the-middle attacks. * Implement access controls and authentication: Use strong passwords, multi-factor authentication (MFA), and role-based access control to limit user privileges and ensure that only authorized users can access sensitive data. * Monitor system logs and perform regular security audits: Regularly review system logs for suspicious activity and perform thorough security audits to identify potential vulnerabilities or weaknesses in the system.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-41096CVE-2026-41096 CVE-2026-41089CVE-2026-41089 CVE-2026-40415CVE-2026-40415 CVE-2026-40397CVE-2026-40397 CVE-2026-40365CVE-2026-40365 CVE-2026-40364CVE-2026-40364 CVE-2026-40358CVE-2026-40358 CVE-2026-40398CVE-2026-40398 CVE-2026-42823CVE-2026-42823 CVE-2026-32161CVE-2026-32161 CVE-2026-42831CVE-2026-42831 CVE-2026-35421CVE-2026-35421 CVE-2026-33109CVE-2026-33109 CVE-2026-33841CVE-2026-33841 CVE-2026-40366CVE-2026-40366 CVE-2026-33835CVE-2026-33835 CVE-2026-40403CVE-2026-40403 CVE-2026-40363CVE-2026-40363 CVE-2026-35417CVE-2026-35417 CVE-2026-42898CVE-2026-42898 CVE-2026-40361CVE-2026-40361 CVE-2026-40367CVE-2026-40367 CVE-2026-40369CVE-2026-40369 CVE-2026-33837CVE-2026-33837 CVE-2026-41103CVE-2026-41103 CVE-2026-33840CVE-2026-33840 CVE-2026-35416CVE-2026-35416 CVE-2026-33844CVE-2026-33844
Target & Sectors
Global Scope
Incident Timeline
‎12 May
Threat actors exploited 17 critical vulnerabilities in Microsoft's May Patch Tuesday update.
‎2026/05/13
Microsoft has fixed 17 critical vulnerabilities in its software this May Patch Tuesday.
infrastructure Windows
organisation Windows Remote Desktop
organisation CVSS Critical
organisation Microsoft SSO Plugin for Jira &
organisation Office,
organisation Copilot
organisation Telnet
organisation the Windows DNS Client
organisation DNS
organisation the Windows TCP
organisation CVE-2026-41089
organisation CVE-2026
organisation Windows DNS Client
organisation Netlogon
organisation the Windows DNS Client, Dynamics 365
organisation Microsoft Word
organisation CVSS
organisation AI-Powered Vulnerability Research
organisation Windows Attack Research and Protection
organisation Microsoft Windows
organisation DNS Client
organisation Microsoft Dynamics 365
organisation Microsoft Office
infrastructure Android
organisation Microsoft SharePoint
organisation Windows Graphics Component
organisation the DNS Client
organisation Win32k Elevation of Privilege Vulnerability
organisation Windows Ancillary Function
organisation WinSock Elevation of Privilege Vulnerability
organisation Windows Win32k
organisation Microsoft
organisation Remote Desktop Client
organisation Critical
organisation Microsoft Dynamics 365 On-Premises
organisation Microsoft Dynamics
organisation CVE-2026-40361
organisation TCP
organisation Preview Pane
organisation SecurityAffairs
organisation Microsoft Fixes
organisation Critical Flaws
organisation Dynamics CRM
organisation Azure Managed Instance for Apache Cassandra
organisation Trend Micro’s Zero Day Initiative
organisation Microsoft’s Security Response Center
infrastructure 365 infrastructure
organisation Microsoft Office Word
organisation Enhanced Metafile
organisation EMF
organisation Microsoft Paint
organisation Office
organisation Cisco Security Firewall
organisation SRU
organisation Snort 3
‎May 2026
Microsoft Patch Tuesday for May 2026 fixed 138 vulnerabilities, including 30 critical ones.
infrastructure Windows
organisation Microsoft
organisation Windows, Office
tactic T1584.004 - Server
general_metric 138 bugs
general_metric 30 critical bugs
vulnerability CVSS score of 9.9
general_metric 365 Microsoft Dynamics
tactic Remote Code Execution
vulnerability CVE-2026-42898
infrastructure 9.9
organisation Microsoft Patch
organisation Snort
general_metric 31 RCE
general_metric 137 vulnerabilities
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎9.9
Software Version
Metrics
infrastructure
365
Infrastructure
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎Android
Affected Product
Intelligence Sources