Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-54518 | Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a diff Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation. NVD description · AI analysis pending | 7.3 | <1% | — | — | ||
| CVE-2026-33109 +1 in the same advisory: …33844 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 9.9 group max | <1% |
| — | ||
| CVE-2026-33117 | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6. NVD description · AI analysis pending | 9.1 | <1% |
| — | ||
| CVE-2026-33823 | Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-35428 | Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing ove Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. NVD description · AI analysis pending | 9.6 | <1% |
| — | ||
| CVE-2026-40364 +1 in the same advisory: …40361 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 8.4 | 4% |
| — | ||
| CVE-2026-40379 | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-41096 +1 in the same advisory: …40402 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2026-41089 | Unauthenticated Stack Buffer Overflow RCE in Windows Server Netlogon (CVE-2026-41089) CVE-2026-41089 is a stack-based buffer overflow (CWE-121) in the Netlogon service of Windows Server. An unauthenticated remote attacker can trigger it by sending crafted network requests to the Netlogon RPC interface, with no privileges or user interaction required per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact; on domain controllers, where Netlogon runs by default, this typically means compromise of a critical authentication server and risk of broader domain compromise. All organizations running the affected Windows Server versions (2012, 2016, 2019, 2022, 2022 23H2, and 2025) are in scope, with Active Directory domain controllers the highest-value targets. Microsoft fixed the flaw in its May 2026 Patch Tuesday release (138 vulnerabilities patched), and security reporting indicates the RCE is being exploited with domain controllers at risk; a public proof-of-concept is available, it is not yet in CISA KEV, and EPSS assigns a 79.6% probability of exploitation within 30 days. Do: Apply Microsoft's May 2026 cumulative security updates (or later) to all listed Windows Server versions, prioritizing domain controllers. Until patched, restrict unauthenticated network access to domain controllers' Netlogon/RPC interfaces (e.g., limit TCP 135 and dynamic RPC ports to trusted hosts) and monitor for anomalous Netlogon activity. The flaw is not yet in CISA KEV, but treat it as actively exploited given current reporting and the available public PoC. | 9.8 | 80% | PoC ×3 |
| massmillions of systems (Netlogon runs by default on every Windows Server Active Directory domain controller and most domain-joined servers) | |
| CVE-2026-41103 | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.1 | 5% |
| — | ||
| CVE-2026-42823 | Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 9.9 | <1% |
| — | ||
| CVE-2026-42826 | Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2026-42898 +1 in the same advisory: …42833 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 9.9 group max | 1% |
| — |
Full article1,367 words · extracted from thehackernews.com · click to collapse
Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack.
Of the 138 flaws, 30 are rated Critical, 104 are rated Important, three are rated Moderate, and one is rated Low in severity. As many as 61 vulnerabilities are classified as privilege escalation bugs, followed by 32 remote code execution, 15 information disclosure, 14 spoofing, eight denial-of-service, six security feature bypass, and two tampering flaws.
The update list also includes a vulnerability that was patched by AMD (CVE-2025-54518, CVSS score: 7.3) this month. It relates to a case of improper isolation of shared resources within the CPU operation cache on Zen 2-based products that could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
The patches are also in addition to 127 security flaws that Google has addressed in Chromium, which forms the basis for Microsoft's Edge browser.
One of the most severe vulnerabilities patched by Redmond is CVE-2026-41096 (CVSS score: 9.8), a heap-based buffer overflow flaw impacting Windows DNS that could allow an unauthorized attacker to execute code over a network.
"An attacker could exploit this vulnerability by sending a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory," Microsoft said. "In certain configurations, this could allow the attacker to run code remotely on the affected system without authentication."
Also fixed by Microsoft are several Critical- and Important-rated flaws -
- CVE-2026-42826 (CVSS score: 10.0) - An exposure of sensitive information to an unauthorized actor in Azure DevOps that allows an unauthorized attacker to disclose information over a network. (Requires no customer action)
- CVE-2026-33109 (CVSS score: 9.9) - An improper access control in Azure Managed Instance for Apache Cassandra that allows an authorized attacker to execute code over a network. (Requires no customer action)
- CVE-2026-42898 (CVSS score: 9.9) - A code injection vulnerability in Microsoft Dynamics 365 (on-premises) that allows an authorized attacker to execute code over a network.
- CVE-2026-42823 (CVSS score: 9.9) - An improper access control in Azure Logic Apps that allows an authorized attacker to elevate privileges over a network.
- CVE-2026-41089 (CVSS score: 9.8) - A stack-based buffer overflow in Windows Netlogon that allows an unauthorized attacker to execute code over a network without needing to sign in or have prior access by sending a specially crafted network request to a Windows server that is acting as a domain controller.
- CVE-2026-33823 (CVSS score: 9.6) - An improper authorization in Microsoft Teams that allows an authorized attacker to disclose information over a network. (Requires no customer action)
- CVE-2026-35428 (CVSS score: 9.6) - A command injection vulnerability in Azure Cloud Shell that allows an unauthorized attacker to perform spoofing over a network. (Requires no customer action)
- CVE-2026-40379 (CVSS score: 9.3) - An exposure of sensitive information to an unauthorized actor in Azure Entra ID that allows an unauthorized attacker to perform spoofing over a network. (Requires no customer action)
- CVE-2026-40402 (CVSS score: 9.3) - A user-after-free in Windows Hyper-V that allows an unauthorized attacker to gain SYSTEM privileges and access the Hyper-V host environment.
- CVE-2026-41103 (CVSS score: 9.1) - An incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence that allows an unauthorized attacker to gain unauthorized access to Jira or Confluence as a valid user and perform actions with the same permissions as the compromised account.
- CVE-2026-33117 (CVSS score: 9.1) - An improper authentication in Azure SDK that allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-42833 (CVSS score: 9.1) - An execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) that allows an authorized attacker to execute code over a network and gain the ability to interact with other tenant’s applications and content.
- CVE-2026-33844 (CVSS score: 9.0) - An improper input validation in Azure Managed Instance for Apache Cassandra that allows an authorized attacker to execute code over a network. (Requires no customer action)
- CVE-2026-40361 (CVSS score: 8.4) - A use-after-free vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally without requiring user interaction.
- CVE-2026-40364 (CVSS score: 8.4) - A type confusion vulnerability in Microsoft Office Word that allows an unauthorized attacker to execute code locally without requiring user interaction.
"This critical elevation of privilege vulnerability allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, thus bypassing Entra ID," Adam Barnett, lead software engineer at Rapid7, said about CVE-2026-41103.
Jack Bicer, director of vulnerability research at Action1, described CVE-2026-42898 as a critical flaw that allows an authenticated attacker with low privileges to run arbitrary code over the network by manipulating process session data within Dynamics CRM.
"With no user interaction required, and the potential to impact systems beyond the vulnerable component's original security scope, this vulnerability poses serious enterprise risk: an attacker with only basic access could turn a business application server into a remote execution platform," Bicer said.
"Compromise of Dynamics 365 infrastructure can expose customer records, operational workflows, financial information, and integrated business systems. Since CRM environments often connect with identity services, databases, and enterprise applications, successful exploitation could lead to broader organizational compromise and operational disruption."
Organizations are also advised to update Windows Secure Boot certificates to their 2023 counterparts ahead of next month, when the 2011-issued certificates are set to expire. Microsoft first announced the change in November 2025.
"The most critical non-CVE update involves the mandatory rollout of updated Secure Boot certificates," Rain Baker, senior incident response specialist at Nightwing, said. "Devices failing to receive these updates before the June 26 deadline face 'catastrophic boot-level security failures' or degraded security states. Ensure your entire fleet successfully rotates to the new trust anchors before the June 26, 2026, deadline."
Over 500 CVEs in 2026 So Far
According to Satnam Narang, senior staff research engineer at Tenable, Microsoft has already patched over 500 CVEs five months into the year. This large volume of fixes reflects a broader industry trend where vulnerability discovery has scaled new highs, with a chunk of them flagged via artificial intelligence (AI)-powered approaches.
Microsoft, in a report published Tuesday, said AI-assisted vulnerability discovery is expected to increase the scale of Patch Tuesday releases in the coming months, adding 16 of the flaws fixed this month across the Windows networking and authentication stack were identified through its new multi-model AI-driven vulnerability discovery system, codenamed MDASH (short for multi-model agentic scanning harness).
"In this month's release, a greater share of the issues addressed were discovered by Microsoft, compared to prior months," Tom Gallagher, vice president of engineering at Microsoft Security Response Center, said. "Many of these were surfaced through AI investments and investigations across our engineering and research teams, including the use of Microsoft's new multi-model AI-driven scanning harness."
Microsoft also emphasized that the scale and speed of vulnerability discovery brought about by AI can raise operational demands and requires a consistent, disciplined approach to risk management in order to ensure that issues are mitigated quickly and fixed in a timely fashion.
"Stay current on supported operating systems, products, and patches, and revisit the speed and consistency of your patching cadence," Gallagher said. "Triage by exposure and impact, not raw count."
Other recommendations outlined by Microsoft include reducing unnecessary internet exposure, improving configuration hygiene, removing legacy authentication, enabling multi-factor authentication (MFA), enforcing strong access controls, segmenting environments to contain incidents, and investing in detection and response.
"The work of finding and fixing vulnerabilities continues to get faster, broader, and more rigorous across the industry," the tech giant said. "What we encourage in turn is a thoughtful look at whether the practices that worked well for the patching landscape of a few years ago are still well matched to where the landscape is heading."
"The fundamentals have not changed. The pace at which they need to be applied is changing, and the organizations that adjust with it will be the ones best positioned for what comes next."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/05/microsoft-patches-138-vulnerabilities.html