ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Microsoft May 2026 Patch Tuesday: Many fixes, but no zero-days

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-40364
+1 in the same advisory: …40361
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
8.44%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
  • +1 more
CVE-2026-41096
+1 in the same advisory: …40402
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • microsoft windows 11 23h2
  • microsoft windows 11 24h2
  • microsoft windows 11 25h2
  • +1 more
CVE-2026-41089
Unauthenticated Stack Buffer Overflow RCE in Windows Server Netlogon (CVE-2026-41089)

CVE-2026-41089 is a stack-based buffer overflow (CWE-121) in the Netlogon service of Windows Server. An unauthenticated remote attacker can trigger it by sending crafted network requests to the Netlogon RPC interface, with no privileges or user interaction required per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact; on domain controllers, where Netlogon runs by default, this typically means compromise of a critical authentication server and risk of broader domain compromise. All organizations running the affected Windows Server versions (2012, 2016, 2019, 2022, 2022 23H2, and 2025) are in scope, with Active Directory domain controllers the highest-value targets. Microsoft fixed the flaw in its May 2026 Patch Tuesday release (138 vulnerabilities patched), and security reporting indicates the RCE is being exploited with domain controllers at risk; a public proof-of-concept is available, it is not yet in CISA KEV, and EPSS assigns a 79.6% probability of exploitation within 30 days.

Do: Apply Microsoft's May 2026 cumulative security updates (or later) to all listed Windows Server versions, prioritizing domain controllers. Until patched, restrict unauthenticated network access to domain controllers' Netlogon/RPC interfaces (e.g., limit TCP 135 and dynamic RPC ports to trusted hosts) and monitor for anomalous Netlogon activity. The flaw is not yet in CISA KEV, but treat it as actively exploited given current reporting and the available public PoC.

9.880% PoC ×3
  • microsoft Windows Server 2012
  • microsoft Windows Server 2016
  • microsoft Windows Server 2019
  • +3 more
massmillions of systems (Netlogon runs by default on every Windows Server Active Directory domain controller and most domain-joined servers)
Full article525 words · extracted from helpnetsecurity.com · click to collapse

Microsoft has marked May 2026 Patch Tuesday by releasing fixes for 120+ CVE-numbered vulnerabilities, none of which (for a change) are actively exploited or have been publicly disclosed.

OPIS

Still, some deserve more consideration and should be addressed sooner than others.

Patches to prioritize

For Satnam Narang, senior staff research engineer at Tenable, the four critical remote code execution bugs in Microsoft Word stand out in this release, and especially the two (CVE-2026-40361, CVE-2026-40364) that have been deemed by Microsoft more likely to be exploited.

“These flaws could be exploited by an attacker who sends a malicious document to a target. The other common thread across these vulnerabilities is that a target doesn’t need to even open the document to trigger the exploit. Exploitation is possible just by viewing a malicious document in the Preview Pane. Therefore, patching is the most reliable way to protect against flaws like these,” he explained his reasoning.

Jason Kikta, CTO at Automox, says that CVE-2026-41089, a stack-based buffer overflow in Windows Netlogon that could lead to remote code execution, should be patched on all domain controllers in the same maintenance window.

“Half-patched forests are not a defensible state for a pre-auth DC bug,” he noted.

The vulnerability can be triggered by a specially crafted network request to a Windows server that is acting as a domain controller, and may allow the attacker to run code on the affected system without needing to sign in or have prior access, Microsoft explained.

Aside from patching, he also advises restricting Netlogon traffic at the network layer. “Domain controllers do not need to accept Netlogon from arbitrary segments,” he opined.

CVE-2026-40402 is a elevation of privilege vulnerability in Hyper-V, Windows’ built-in hypervisor, which lets users run multiple virtual machines on a single physical computer.

This issue could allow a malicious guest VM to force the host’s kernel to read from a memory address of the attacker’s choosing, and potentially set up the stage for a guest-to-host escalation.

Though the vulnerability is less likely to be exploited (according to Microsoft), Kikta advises organizations to patch multi-tenant virtual desktop infrastructure, on-premises virtualization with untrusted workloads, or any Hyper-V host running guests they don’t fully control.

Finally, CVE-2026-41096 can be exploited by sending a specially crafted DNS response to a Windows system with a vulnerable DNS Client.

“In certain configurations, this could allow the attacker to run code remotely on the affected system without authentication,” Microsoft noted, but did not specify the susceptible configurations.

Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, pointed out that since the DNS Client runs on virtually every Windows machine, the attack surface is enormous.

“An attacker with a position to influence DNS responses (MitM, rogue server) could achieve unauthenticated RCE across your enterprise,” he explained.

Kikta advised organizations to patch all Windows servers and endpoints. “Any Windows host issuing a DNS query is potentially in scope, which includes every workstation sitting behind a compromised resolver,” he pointed out.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/05/12/microsoft-may-2026-patch-tuesday/