Visualização normal

Antes de ontemStream principal

Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack

13 de Agosto de 2026, 09:51

Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.

The post Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack appeared first on TechRepublic.

  • ✇Malwarebytes
  • Patch Tuesday: Update now to fix 421 flaws, including three zero-days
    Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of-co
     

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

12 de Agosto de 2026, 10:48

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges.

The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of-concept (PoC), a newly completed unauthenticated SharePoint remote code execution (RCE) chain, and a potentially wormable Windows DNS Server flaw.

How to apply patches and check if you’re protected

These updates fix security problems and help keep your Windows PC protected. Here’s how to make sure you’re up to date:

  • Click the Start button, then open Settings.
  • Select Windows Update (usually at the bottom of the menu on the left).
  • Click Check for updates. Windows will search for the latest security updates. If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately to complete the update. Otherwise, continue to the next step.
Windows update history - August 12, 2026
  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.
  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Windows up to date

Technical details

Windows Deployment Services (WDS) users should prioritize CVE-2026-62893 (CVSS score 9.8 out of 10), an unauthenticated RCE flaw in the TFTP (Trivial File Transfer Protocol) server. TFTP normally runs on UDP port 69 and has no built-in authentication. It is primarily an enterprise and school network issue, but it could enable lateral movement where WDS is deployed.

Microsoft also fixed CVE-2026-62832, a publicly disclosed elevation of privilege (EoP) vulnerability in the Windows User Profile Service. It maps to the issue researchers called LegacyHive, for which a limited public proof of concept was released in July.

The PoC demonstrates how a local authenticated attacker could abuse the service’s registry hive handling to load another user’s hive, potentially including an administrator’s. The released demonstration is deliberately constrained and requires credentials for another user, but the availability of code and the broad Windows footprint make this one a strong candidate for exploitation attempts.

Another good reason to promptly update is the number (I counted 48) of remote code execution (RCE) fixes for Office applications and components, including Excel, Word, Outlook, PowerPoint, and the Office graphics component. Document-borne vulnerabilities are attractive to phishing operators because email attachments and shared documents provide delivery mechanisms that people are likely to open.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Cisco Talos
    Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This
     

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

11 de Agosto de 2026, 19:21
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." 

Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild 

CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This vulnerability has a CVSS base score of 7.0. 

Out of 62 "critical" vulnerabilities, 40 are remote code execution (RCE) vulnerabilities. 

Microsoft considers exploitation of the following vulnerabilities more likely. 

CVE-2026-62893 is a remote code execution vulnerability affecting Windows Deployment Services TFTP Server. A Use After Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.8. 

CVE-2026-65665 is a remote code execution vulnerability affecting Microsoft SharePoint Server. Deserialization of Untrusted Data could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62823 is a remote code execution vulnerability affecting Windows DHCP Server. A Heap-based Buffer Overflow could allow an unauthorized attacker to execute code over an adjacent network. This vulnerability has a CVSS base score of 8.8. 

Microsoft considers exploitation of the following vulnerabilities less likely. 

CVE-2026-62830 is an elevation of privilege vulnerability affecting Azure SRE Agent. Missing Authorization could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-50516 is an elevation of privilege vulnerability affecting Microsoft Azure Kubernetes Service. Missing Authentication for Critical Function could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.4. 

Three remote code execution vulnerabilities, CVE-2026-68794CVE-2026-68816 and CVE-2026-68804, affect Microsoft Excel and have a CVSS base score of 7.8. An unauthorized attacker could execute code locally. CVE-2026-68794 is a Heap-based Buffer Overflow. CVE-2026-68816 is a Stack-based Buffer Overflow. CVE-2026-68804 involves a Numeric Truncation Error and a Heap-based Buffer Overflow. 

CVE-2026-62911 is an elevation of privilege vulnerability affecting Microsoft Exchange Server. Authentication Bypass by Capture-replay could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.0. 

Nine remote code execution vulnerabilities, CVE-2026-63515CVE-2026-65657CVE-2026-63532CVE-2026-64898CVE-2026-64903CVE-2026-64909CVE-2026-64910CVE-2026-64911 and CVE-2026-70130, affect Microsoft Office and could allow an unauthorized attacker to execute code locally. CVE-2026-63515 involves an Out-of-bounds Read and an Integer Underflow (Wrap or Wraparound) and has a CVSS base score of 7.8. CVE-2026-65657 is a Use After Free and has a CVSS base score of 7.8. CVE-2026-63532 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-64898 involves a Heap-based Buffer Overflow and an Integer Overflow or Wraparound and has a CVSS base score of 7.8. CVE-2026-64903 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-64909 involves an Integer Underflow (Wrap or Wraparound), an Out-of-bounds Read and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-64910 is an Untrusted Pointer Dereference and has a CVSS base score of 7.8. CVE-2026-64911 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-70130 is a Heap-based Buffer Overflow and has a CVSS base score of 8.4. 

Five remote code execution vulnerabilities, CVE-2026-63513CVE-2026-63519CVE-2026-65664CVE-2026-63526 and CVE-2026-66807, affect Microsoft Office Graphics Component and have a CVSS base score of 7.8. An unauthorized attacker could execute code locally. CVE-2026-63513 is a Heap-based Buffer Overflow. CVE-2026-63519 is a Heap-based Buffer Overflow. CVE-2026-65664 is a Heap-based Buffer Overflow. CVE-2026-63526 is a Stack-based Buffer Overflow. CVE-2026-66807 is a Stack-based Buffer Overflow. 

Three remote code execution vulnerabilities, CVE-2026-63518CVE-2026-63525 and CVE-2026-64907, affect Microsoft Office Word and have a CVSS base score of 7.8. An unauthorized attacker could execute code locally. CVE-2026-63518is a Heap-based Buffer Overflow. CVE-2026-63525 is a Numeric Truncation Error. CVE-2026-64907 is a Stack-based Buffer Overflow.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827 

Two elevation of privilege vulnerabilities, CVE-2026-62827 and CVE-2026-64921, affect Microsoft SharePoint Server and have a CVSS base score of 8.8. An authorized attacker could elevate privileges over a network. CVE-2026-62827involves Improper Authentication. CVE-2026-64921 involves Missing Authentication for Critical Function. 

CVE-2026-62824 is a remote code execution vulnerability affecting Remote Desktop Client. A Stack-based Buffer Overflow could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62818 is a remote code execution vulnerability affecting Windows Active Directory Certificate Services (AD CS). A Use After Free could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.8. 

Three remote code execution vulnerabilities, CVE-2026-62817CVE-2026-62820 and CVE-2026-62878, affect Windows DNS Server. CVE-2026-62817 is an Out-of-bounds Write that could allow an unauthorized attacker to execute code over an adjacent network and has a CVSS base score of 8.8. CVE-2026-62820 involves Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), could allow an unauthorized attacker to execute code over a network and has a CVSS base score of 8.1. CVE-2026-62878 is a Stack-based Buffer Overflow that could allow an unauthorized attacker to execute code over a network and has a CVSS base score of 9.8. 

Two remote code execution vulnerabilities, CVE-2026-66802 and CVE-2026-71331, affect Windows Device Health Attestation (DHA), could allow an unauthorized attacker to execute code over a network and have a CVSS base score of 8.1. CVE-2026-66802 involves Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and a Use After Free. CVE-2026-71331 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow. 

Two remote code execution vulnerabilities, CVE-2026-62890 and CVE-2026-62822, affect Windows GDI+. CVE-2026-62890 is a Heap-based Buffer Overflow that could allow an authorized attacker to execute code locally and has a CVSS base score of 7.8. CVE-2026-62822 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow, could allow an unauthorized attacker to execute code over a network and has a CVSS base score of 8.8. 

CVE-2026-66799 is an elevation of privilege vulnerability affecting Windows Key Guard. A Heap-based Buffer Overflow could allow an authorized attacker to elevate privileges locally. This vulnerability has a CVSS base score of 7.8. 

CVE-2026-62816 is a remote code execution vulnerability affecting Windows Reliable Multicast Transport Driver (RMCAST). A Heap-based Buffer Overflow and an Integer Overflow or Wraparound could allow an unauthorized attacker to execute code over an adjacent network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62819 is a remote code execution vulnerability affecting Windows Routing and Remote Access Service (RRAS). A Use After Free could allow an attacker to gain unauthorized access to a victim's machine. This vulnerability has a CVSS base score of 8.1. 

CVE-2026-62889 is a remote code execution vulnerability affecting Windows Secure Socket Tunneling Protocol (SSTP). A Double Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.1. 

Microsoft considers exploitation of the following vulnerabilities unlikely. 

CVE-2026-65789 is a remote code execution vulnerability affecting Windows DNS Server. A Use After Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.1. 

CVE-2026-65791 is a remote code execution vulnerability affecting Windows iSCSI Target Service. A Heap-based Buffer Overflow could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.8. 

Other critical vulnerabilities 

CVE-2026-49163 is an elevation of privilege vulnerability affecting Application Insights Profiler. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-50481 is an elevation of privilege vulnerability affecting Azure Active Directory. Modification of Assumed-Immutable Data (MAID) could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-68823 is a remote code execution vulnerability affecting Azure Confidential Ledger. Exposed Dangerous Method or Function could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.1. 

CVE-2026-62869 affects Azure Entra ID. Insufficient Verification of Data Authenticity could allow an authorized attacker to perform spoofing over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-56161 is an information disclosure vulnerability affecting Azure Logic Apps. Improper Access Control could allow an authorized attacker to disclose information over a network. This vulnerability has a CVSS base score of 9.6. 

Two elevation of privilege vulnerabilities, CVE-2026-63522 and CVE-2026-56162, affect Azure SQL Database. CVE-2026-63522 involves Incorrect Permission Assignment for Critical Resource, could allow an authorized attacker to elevate privileges locally and has a CVSS base score of 7.8. CVE-2026-56162 involves Improper Authentication, could allow an unauthorized attacker to elevate privileges over a network and has a CVSS base score of 10.0. 

CVE-2026-62836 is an elevation of privilege vulnerability affecting Azure SQL Managed Instance. Improper Restriction of Communication Channel to Intended Endpoints could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.7. 

CVE-2026-50515 is a remote code execution vulnerability affecting Azure Service Bus. Deserialization of Untrusted Data could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-62873 is an elevation of privilege vulnerability affecting Microsoft 365 Admin Center. Improper Verification of Cryptographic Signature could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.8. 

CVE-2026-59115 is an elevation of privilege vulnerability affecting Microsoft Entra Provisioning Service. Path Traversal: '.../...//' could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-70332 affects Microsoft Office SharePoint. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') could allow an unauthorized attacker to perform spoofing over a network. This vulnerability has a CVSS base score of 9.6. 

CVE-2026-63508 is an elevation of privilege vulnerability affecting Microsoft Planetary Computer Pro. Missing Authentication for Critical Function could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 10.0. 

CVE-2026-59118 is an elevation of privilege vulnerability affecting Copilot Cowork. Improper Authorization could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.3. 

CVE-2026-65668 is an elevation of privilege vulnerability affecting Microsoft Purview eDiscovery. Improper Access Control could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62815 is a remote code execution vulnerability affecting Microsoft QUIC. A Use After Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.8.  

Three vulnerabilities, CVE-2026-62896CVE-2026-62918 and CVE-2026-65667, affect Microsoft Teams. CVE-2026-62896 is an elevation of privilege vulnerability involving Improper Authentication that could allow an authorized attacker to elevate privileges over a network and has a CVSS base score of 9.6. CVE-2026-62918 involves Improper Verification of Cryptographic Signature that could allow an unauthorized attacker to perform spoofing over a network and has a CVSS base score of 7.5. CVE-2026-65667 is an elevation of privilege vulnerability involving Missing Authorization that could allow an unauthorized attacker to elevate privileges over a network and has a CVSS base score of 10.0.  

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:" 

CVE-2026-58650: Visual Studio Code Security Feature Bypass Vulnerability 

CVE-2026-63520: Microsoft SharePoint Server Remote Code Execution Vulnerability 

CVE-2026-59124: Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 

CVE-2026-59133: Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability 

CVE-2026-59132: Windows TCP/IP Denial of Service Vulnerability 

CVE-2026-61348: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 

CVE-2026-61925: Windows Installer Elevation of Privilege Vulnerability 

CVE-2026-61930: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62688: Windows MIDI Service Module Elevation of Privileges Vulnerability 

CVE-2026-62696: Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability 

CVE-2026-62713: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 

CVE-2026-62712: Windows Win32k Elevation of Privilege Vulnerability 

CVE-2026-62735: Windows HTTP.sys Elevation of Privilege Vulnerability 

CVE-2026-62737: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62783: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 

CVE-2026-62766: Windows Kerberos Elevation of Privilege Vulnerability 

CVE-2026-65788: Desktop Window Manager Elevation of Privilege Vulnerability 

CVE-2026-69278: Visual Studio Code Security Feature Bypass Vulnerability 

CVE-2026-70307: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 

CVE-2026-70335: GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability 

CVE-2026-66804: Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability 

CVE-2026-70355: Microsoft SharePoint Server Elevation of Privilege Vulnerability 

CVE-2026-61358: Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability 

CVE-2026-61929: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62698: Microsoft Digest Authentication Elevation of Privilege Vulnerability 

CVE-2026-62721: Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability 

CVE-2026-62741: Windows HTTP.sys Elevation of Privilege Vulnerability 

CVE-2026-62788: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62832: Windows User Profile Service Elevation of Privilege Vulnerability 

CVE-2026-62888: Windows DWM Core Library Elevation of Privilege Vulnerability 

CVE-2026-65775: Windows Win32k Elevation of Privilege Vulnerability 

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org

Snort 2 rule coverage: 1:66902-1:66910, 1:66912-1:66923, 1:66929-1:66932, 1:66935-1:66948 

Snort 3 rule coverage: 1:66902, 1:301589-1:301607 

  • ✇Cybersecurity News
  • Microsoft August 2026 Patch Tuesday Fixes WinSock Zero-Day Exploited in the Wild Do Son
    Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild by Lazarus Group. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post Microsoft August 2026 Patch Tuesday Fixes WinSock Zero-Day Exploited in the Wild appeared first on Daily CyberSecurity
     
  • ✇Firewall Daily – The Cyber Express
  • Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days Ashish Khaitan
    Microsoft’s August 2026 Patch Tuesday release addresses roughly 400 security flaws across its products, including three Zero-days. One of the three is being actively exploited, while the other two were publicly disclosed before Microsoft issued fixes.  The August 2026 Patch Tuesday update includes 42 vulnerabilities rated “Critical.” Of those, 37 involve remote code execution, and five involve elevation of privilege. The vulnerability breakdown is approximately 176 elevation-of-privilege flaw
     

Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days

12 de Agosto de 2026, 04:22

August 2026 Patch Tuesday

Microsoft’s August 2026 Patch Tuesday release addresses roughly 400 security flaws across its products, including three Zero-days. One of the three is being actively exploited, while the other two were publicly disclosed before Microsoft issued fixes.  The August 2026 Patch Tuesday update includes 42 vulnerabilities rated “Critical.” Of those, 37 involve remote code execution, and five involve elevation of privilege. The vulnerability breakdown is approximately 176 elevation-of-privilege flaws, 11 security-feature bypasses, 110 remote-code-execution flaws, 86 information-disclosure issues, 12 denial-of-service vulnerabilities, and 21 spoofing vulnerabilities.  Although smaller than July’s 570-flaw release, the August 2026 Patch Tuesday remains unusually large. Microsoft has previously warned that security updates could increase as its AI-powered vulnerability discovery system identifies additional flaws across its software products. 

August 2026 Patch Tuesday Zero-days 

Microsoft defines a zero-day as a vulnerability that has been publicly disclosed or actively exploited before an official fix is available. The three Zero-days addressed in August 2026 are:  CVE-2026-68820 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability: This actively exploited flaw allows a locally authenticated attacker to trigger a race condition through a specially crafted application and obtain SYSTEM privileges without user interaction.  Microsoft credited Moshe Marelus and David Driker of Check Point. Check Point reported that North Korean Lazarus threat actors exploited the flaw in Zero-day attacks to deploy a new version of the FudModule kernel-mode rootkit. “During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit,” Check Point said. Microsoft has not disclosed exploitation details.  CVE-2026-62832 — Windows User Profile Service Elevation of Privilege Vulnerability: This publicly disclosed flaw can allow an authenticated attacker with credentials for another local account to load another user’s registry hive, potentially access or modify data and gain administrator privileges. Microsoft credited an anonymous researcher. The details match the “LegacyHive” Zero-day disclosed last month by researcher Nightmare Eclipse.  CVE-2026-72971 — Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability: This publicly disclosed flaw involves improper link resolution and allows authenticated attackers to perform local tampering. Microsoft attributed its discovery to yhw and txz but did not identify where the vulnerability was disclosed. 

August 2026 Security Updates 

Microsoft’s August 2026 release consists of 421 Microsoft CVEs spanning Azure, Defender, Developer Tools, Exchange Server, Office, Office 2016, Other, SharePoint Server and Windows. Windows accounts for 236 vulnerabilities, Office for 98, SharePoint Server for 30, Developer Tools for 26, Azure for 17, Exchange Server for seven, Other for six, and Defender for one.  The release also republishes two non-Microsoft CVEs: CVE-2026-6726 and CVE-2026-6727, both tagged as Windows TPM issues by MITRE. FAQs are available for both, while no workarounds or mitigations are listed.  Separate non-security releases include Windows 11 KB5121003 and KB5120240 cumulative updates and the Windows 10 KB5120249 extended security update. 
  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Cisco Talos
    Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to
     

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

14 de Julho de 2026, 17:27
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."

Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.

CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileges locally.

CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An unauthorized attacker could exploit it to perform spoofing over a network.

The 57 "critical" entries break down by vulnerability type as follows: 48 remote code execution (RCE), seven elevation of privilege (EoP), 1 spoofing and 1 security feature bypass vulnerability.

The 48 critical RCE vulnerabilities affect a range of Microsoft Windows services and applications, including Windows Media and Media Foundation, the Windows DHCP client and DHCP Server service, Microsoft Office, Word, Excel and PowerPoint, Windows GDI and GDI+, the DirectX Graphics Kernel, Microsoft SharePoint, Microsoft SQL Server, the Windows Reliable Multicast Transport Driver (RMCAST), Windows TCP/IP, the Windows Server Network driver, the Windows Print Spooler, the Windows Secure Socket Tunneling Protocol (SSTP), Windows Active Directory Domain Services, Microsoft Defender, Microsoft Copilot, Microsoft Message Queuing (MSMQ), the Remote Desktop Client, Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (on-premises), and the Minecraft Bedrock Dedicated Server.

Eleven of the critical RCE vulnerabilities are rated "more likely" to be exploited. CVE-2026-50370 and CVE-2026-50518 are heap-based buffer overflows in the Windows DHCP Server service, exploitable by an unauthorized attacker over an adjacent network and over a network, respectively. CVE-2026-54128 is a use-after-free in the Windows DHCP client that allows an unauthorized attacker to execute code locally. CVE-2026-50327 and CVE-2026-50655 are heap-based buffer overflows in Windows Media and Windows Media Foundation. CVE-2026-54992 is a heap-based buffer overflow in the Microsoft Message Queuing Queue Manager. CVE-2026-56188 is a race condition in the Windows Server Network driver, and CVE-2026-55010 is a heap-based buffer overflow in the Minecraft Bedrock Dedicated Server that an unauthorized attacker could exploit over a network. CVE-2026-50522 and CVE-2026-58644 are deserialization vulnerabilities in Microsoft SharePoint that allow an unauthorized attacker to execute code over a network. CVE-2026-55944 is a deserialization vulnerability in Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (on-premises) that allows an unauthorized attacker to execute code over a network.

The remaining critical RCE vulnerabilities are rated "less likely" or "unlikely" to be exploited, or were not assigned an exploitation-likelihood rating by Microsoft. Microsoft Office and its applications account for a large share: CVE-2026-50314, CVE-2026-50467, CVE-2026-55018, CVE-2026-55022, CVE-2026-55045, CVE-2026-55049, CVE-2026-55056, CVE-2026-55129 and CVE-2026-55140 are in Microsoft Office; CVE-2026-55033, CVE-2026-55127 and CVE-2026-55132 are in Microsoft Word; and CVE-2026-55043, CVE-2026-55120 and CVE-2026-55123 are in Microsoft PowerPoint. These are typically triggered by opening a specially crafted document.

The remaining critical RCE vulnerabilities affect Windows Media and Media Foundation (CVE-2026-56189, CVE-2026-57087, CVE-2026-57090, CVE-2026-57094 and CVE-2026-58542), the Windows DHCP Server service (CVE-2026-48564 and CVE-2026-56159), Windows GDI+ and GDI (CVE-2026-49796, CVE-2026-50380 and CVE-2026-54122), the DirectX Graphics Kernel (CVE-2026-50382), the Remote Desktop Client (CVE-2026-50474), Microsoft SQL Server (CVE-2026-54117 and CVE-2026-54118), the Windows Reliable Multicast Transport Driver (CVE-2026-54982 and CVE-2026-54995), Windows TCP/IP (CVE-2026-54999), the Windows Print Spooler (CVE-2026-58608), the Windows SSTP (CVE-2026-50694), Windows Active Directory Domain Services (CVE-2026-49164), Microsoft Defender (CVE-2026-55011 and CVE-2026-55012) and Microsoft Copilot (CVE-2026-48561).

The seven critical elevation of privilege vulnerabilities are CVE-2026-42982 and CVE-2026-50392 in Windows Secure Kernel Mode; CVE-2026-50444 in the Windows Server Update Service (WSUS); CVE-2026-50680 and CVE-2026-54127 in Windows Hyper-V; CVE-2026-54121 in Active Directory Certificate Services; and CVE-2026-57092 in Microsoft Windows VMSwitch.

The single critical spoofing vulnerability is CVE-2026-55008 in Microsoft Exchange Server, caused by a cross-site scripting condition. The single critical security feature bypass is CVE-2026-55040 in Microsoft SharePoint Server, caused by weak authentication. Both are rated "more likely" to be exploited.

Several of the critical entries above — including the Copilot, Azure Synapse, Azure OpenAI, Exchange Online and Entra items — affect Microsoft cloud services, for which Microsoft has not assigned an exploitation-likelihood rating.

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"

·       CVE-2026-49170: Windows StateRepository API Server file Elevation of Privilege Vulnerability

·       CVE-2026-49795: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-49798: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-49805: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50297: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50325: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50329: Microsoft DWM Core Library Elevation of Privilege Vulnerability

·       CVE-2026-50332: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50343: Microsoft Install Service Elevation of Privilege Vulnerability

·       CVE-2026-50351: Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability

·       CVE-2026-50375: DirectX Graphics Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50387: Windows GDI Elevation of Privilege Vulnerability

·       CVE-2026-50390: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50423: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50433: Windows Media Elevation of Privilege Vulnerability

·       CVE-2026-50436: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50454: Windows User Interface Core Elevation of Privilege Vulnerability

·       CVE-2026-50475: Windows Kernel Information Disclosure Vulnerability

·       CVE-2026-50476: Windows Network Connections Service Elevation of Privilege Vulnerability

·       CVE-2026-50489: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50509: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

·       CVE-2026-50667: Windows Common Log File System Driver Elevation of Privilege Vulnerability

·       CVE-2026-50688: Windows Win32k Elevation of Privilege Vulnerability

·       CVE-2026-54114: Windows Win32k Elevation of Privilege Vulnerability

·       CVE-2026-54986: Windows Win32k Elevation of Privilege Vulnerability

·       CVE-2026-57091: Windows File History Service Elevation of Privilege Vulnerability

·       CVE-2026-58531: Windows SMB Elevation of Privilege Vulnerability

·       CVE-2026-58536: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

·       CVE-2026-58596: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

·       CVE-2026-58631: Windows Admin Center (WAC) Remote Code Execution Vulnerability

·       CVE-2026-58633: Desktop Window Manager Elevation of Privilege Vulnerability

·       CVE-2026-58638: Windows Boot Loader Security Feature Bypass Vulnerability

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are: 1:66733 - 1:66743, 1:66745 - 1:66785, 1:66791 - 1:66793, 1:66800 - 1:66807

The following Snort 3 rules are also available: 1:301555 - 1:301579, 1:301581 - 1:301583

  • ✇Security Affairs
  • Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one month Pierluigi Paganini
    Patch Tuesday: Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS. Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company’s history. The Zero Day Initiative counted 621 new Microsoft CVEs for the month, and the year-to-date total already exceeds every other full-year total in the last two decades. That’s before counting the roughly 480 additional
     

Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one month

14 de Julho de 2026, 18:33

Patch Tuesday: Microsoft fixes a record 621 CVEs, including 2 exploited zero-days and critical flaws affecting SharePoint, RDP, Hyper-V, and AD FS.

Microsoft’s July 2026 Patch Tuesday is, by a significant margin, the largest single-month security release in the company’s history. The Zero Day Initiative counted 621 new Microsoft CVEs for the month, and the year-to-date total already exceeds every other full-year total in the last two decades. That’s before counting the roughly 480 additional bugs in Chromium and Microsoft Edge that ZDI didn’t cover separately. Of the Microsoft-specific fixes, 63 are rated Critical, six Moderate, one Low, and the rest Important. The IT giant labeled two issues as “under active exploitation,” and one more is publicly known.

The product scope is equally remarkable. Patches this month cover Windows and Windows components, Office, Microsoft Edge, Azure, .NET, Visual Studio, GitHub Copilot, Defender, Exchange Server, Hyper-V, and, at the more unexpected end of the list, Ages of Empire II and Minecraft Server. Eight of the bugs came through ZDI’s own submission program.

“The CVE count year-to-date exceeds all other years’ totals. How to count this mess is anyone’s guess.” states the report published by ZDI.

Patch Tuesday

The following two bugs are being actively exploited:

  • CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services. It requires local access and low privileges to start, which sounds like a limited threat until you remember that AD FS is identity infrastructure, and attackers who are already inside a network use exactly this kind of bug to move sideways and upward. ZDI notes it can be paired with a remote code execution vulnerability, the combination frequently seen in ransomware incidents. Patch it fast.
  • CVE-2026-56164 is a SharePoint Server elevation of privilege vulnerability rated only CVSS 5.3, which is Moderate, and that score has probably caused some organizations to deprioritize it. That would be a mistake. A missing-authentication flaw allows unauthenticated remote attacks without user interaction. Active exploitation makes immediate patching essential, regardless of CVSS score.

The highest-severity bug this month is a critical Microsoft Windows VMSwitch Elevation of Privilege Vulnerability tracked as CVE-2026-57092, which received a CVSS score of 9.9. It is a use-after-free vulnerability that lets a low-privileged attacker escalate all the way to full host compromise across a virtual machine boundary, meaning an attacker inside a VM can reach the host running it. If your Hyper-V deployments use VMSwitch, which they almost certainly do, this is an immediate priority.

Below are other interesting issues addressed by Microsoft this month:

  • CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs, both scored CVSS 9.8, both reachable without authentication or user interaction, both stemming from the deserialization of untrusted data. CVE-2026-50522 was demonstrated live at Pwn2Own Berlin, meaning a working exploit was handed to Microsoft. Despite that, the advisory lists exploit maturity as unknown.
  • CVE-2026-56190 is an unauthenticated remote code execution bug in RDP Server, requiring no user interaction, rooted in use of an uninitialized resource. Specially crafted RDP traffic can interact with memory that was never properly set up, giving an attacker a path to corrupt memory and control code execution. RDP servers are a perennial favorite target. Audit which of yours face the internet and start there.
  • CVE-2026-55008 in Exchange Server is listed as a spoofing vulnerability, but ZDI recommends treating it as what it actually is: a stored cross-site scripting flaw in Outlook Web Access with a CVSS of 9.6. A crafted email opened in Outlook Web Access can execute JavaScript in the victim’s browser session without attachments or user interaction beyond viewing it. Patch urgently.
  • CVE-2026-50518 covers a heap-based buffer overflow in Windows DHCP Server, scored CVSS 9.8, unauthenticated and network-reachable. A second DHCP RCE is also in this release with some caveats, but this one has none. DHCP servers shouldn’t be internet-facing, but if yours somehow are, these jump to the very top of the list.

The full list of vulnerabilities addressed by Microsoft in July 2026 is available here

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Patch Tuesday)

Microsoft’s Largest Patch Tuesday Fixes 622 Vulnerabilities, Two Under Active Attack

Microsoft Patch Tuesday

Microsoft Patch Tuesday July 2026 delivered the company's largest security update to date, addressing 622 Microsoft CVEs, more than tripling the roughly 200 vulnerabilities patched in June. Among the fixes are two zero-day vulnerabilities—CVE-2026-56164 and CVE-2026-56155—that Microsoft confirmed are being actively exploited, making them the highest-priority updates in this month's release.  According to Microsoft's July 2026 Security Updates, the release includes patches across multiple product families. Windows accounts for the largest share with 416 vulnerabilities, followed by Office with 82, Microsoft Edge with 46, Developer Tools with 27, SharePoint Server with 17, Azure with 11, SQL Server with eight, Defender and Exchange Server with five each, and four additional updates categorized under Other. Microsoft also republished 428 non-Microsoft Chromium CVEs. 

Microsoft Patch Tuesday July 2026 Highlights Exploited Vulnerabilities 

The two most significant flaws in Microsoft Patch Tuesday July 2026 are CVE-2026-56164 and CVE-2026-56155, both elevation-of-privilege vulnerabilities affecting critical enterprise infrastructure.  CVE-2026-56164 impacts on-premises Microsoft SharePoint Server and allows an unauthenticated attacker to elevate privileges remotely over the network without requiring credentials or user interaction. Microsoft said the vulnerability was discovered by Mandiant incident responders and Google's FLARE team, suggesting it was identified during investigations into active attacks. However, the company has not disclosed how the flaw was exploited or who was responsible.  Microsoft also noted that enabling the Antimalware Scan Interface (AMSI) in Full Mode can help reduce the attack risk. The update arrives on the same day that SharePoint Server 2016 and SharePoint Server 2019 reach the end of extended support. Unlike Windows Server and SQL Server, these products do not have a paid Extended Security Updates (ESU) program. SharePoint has remained a frequent target since the ToolShell attack chain affected unpatched servers in 2025. 

The Second Vulnerability (CVE-2026-56155)

The second actively exploited vulnerability, CVE-2026-56155, affects Active Directory Federation Services (AD FS). Microsoft said the flaw enables an authenticated attacker to elevate privileges locally because of weak access controls. The company's Detection and Response Team (DART) reported the issue. While Microsoft has not disclosed the exact privileges attackers gained or how the vulnerability was used, AD FS plays a critical role by issuing authentication tokens across enterprise environments, increasing the potential impact of a successful attack.  Beyond these two zero-days, Microsoft identified CVE-2026-50661, a Windows BitLocker Security Feature Bypass vulnerability, as publicly known.  As of publication, neither CVE-2026-56164 nor CVE-2026-56155 has been added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog. However, Microsoft has already classified both as exploited through its own exploitability assessment. The company also assigned the SharePoint flaw a relatively low severity rating, highlighting that active exploitation should take precedence over severity scores when prioritizing remediation. 
  • ✇Malwarebytes
  • July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days
    Just one month ago, June 2026 Patch Tuesday broke Microsoft’s previous record with 206 CVEs and three zero‑days. July now triples that count, reinforcing that the era of “small” Patch Tuesdays may be over as AI‑driven vulnerability discovery ramps up. The update includes 59 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. Two are known to b
     

July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days

15 de Julho de 2026, 09:21

Just one month ago, June 2026 Patch Tuesday broke Microsoft’s previous record with 206 CVEs and three zero‑days. July now triples that count, reinforcing that the era of “small” Patch Tuesdays may be over as AI‑driven vulnerability discovery ramps up.

The update includes 59 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. Two are known to be actively exploited by attackers.

How to apply patches and check if you’re protected

These updates fix security problems and keep your Windows PC protected. Here’s how to make sure you’re up to date:

1. Open Settings

  • Click the Start button, then open Settings.

2. Go to Windows Update

  • Select Windows Update (usually at the bottom of the menu on the left).

3. Check for updates

  • Click Check for updates. Windows will search for the latest security updates.
  • If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately. If so, restart your computer to complete the update. Otherwise, continue to the next step.
    Windows Update History for July 2026

4. Download and install

  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.

5. Double-check you’re up to date

  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Windows is up to date

Technical details

Let’s look at the three zero-days.

First is a Windows BitLocker security feature bypass vulnerability, tracked as CVE-2026-50661. It is not known to be actively exploited. Microsoft describes it as:

“Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”

In other words, even if you’ve encrypted your machine with BitLocker, an attacker could exploit this vulnerability to access your data if they have physical access to your computer.

Next is the actively exploited CVE-2026-56155, an Active Directory Federation Services (ADFS) elevation of privilege (EoP) vulnerability. ADFS is a Microsoft software component that provides single sign-on (SSO) and federated access. It acts as a trust broker between an organization’s Active Directory and applications. An attacker who successfully exploited this vulnerability could gain administrator privileges. Reportedly, Microsoft discovered the vulnerability while investigating active attacks.

Last but not least is CVE-2026-56164, a Microsoft SharePoint Server elevation of privilege vulnerability. SharePoint Server is the on-premises version of Microsoft’s web-based collaboration and document management platform. A missing authentication check in Microsoft Office SharePoint could allow an attacker to elevate privileges over a network.

Both actively exploited vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog, which sets patch deadlines for Federal Civilian Executive Branch (FCEB) agencies. CISA has also urged organizations using SharePoint Server to implement hardening measures after the latest exploitations.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days

Microsoft’s July 2026 Patch Tuesday fixes 622 CVEs, including exploited AD FS and SharePoint flaws, plus the disclosed BitLocker bypass requiring urgent action.
  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Chetan Raghuprasad
    Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”. Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client
     

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

9 de Junho de 2026, 18:21
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”. 

Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack. 

Talos highlights 4 critical vulnerabilities as Microsoft has determined that their exploitation is “more likely:” 

CVE-2026-42985 is a critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Remote Desktop Client which allows an unauthorized attacker to execute code over a network. 

CVE-2026-47291 is a critical Remote Code Execution Vulnerability due to Integer overflow or wraparound in Windows HTTP Protocol Stack (http.sys). An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http.sys) to process packets. 

CVE-2026-44803 and CVE-2026-44812 are critical Remote Code Execution Vulnerability in the Windows Graphics component. This vulnerability is due to Integer overflow or wraparound in Windows Win32K – GRFX subsystem (graphics component). An unauthorized attacker, exploiting this vulnerability can execute malicious code locally. 

Talos highlights 23 critical vulnerabilities as Microsoft has determined that their exploitation is “less likely:” 

CVE-2026-42992CVE-2026-44799CVE-2026-44801CVE-2026-47289 and CVE-2026-48563 are critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Windows Remote Desktop Client allows an unauthorized attacker to execute code over a network. Successful exploitation of this vulnerability necessitates that an attacker takes additional steps to prepare the target environment before exploitation. In the case of a Remote Desktop connection, an attacker who controls a Remote Desktop Server could initiate a remote code execution (RCE) on the machine when a victim connects to the attacking server using the vulnerable Remote Desktop Client. 

CVE-2026-45607CVE-2026-45641 and CVE-2026-47652 are critical Remote Code Execution vulnerabilities in Windows Hyper-V that arise from Out-of-bounds reads, which enable an unauthorized attacker to execute code locally. This vulnerability necessitates that an authenticated attacker on a guest virtual machine (VM) sends specially crafted file operation requests to hardware resources within the VM which could result in remote code execution on the host server. 

CVE-2026-45657 is a critical use after free vulnerability in Windows Kernel which allows an unauthorized attacker to execute malicious code over a network. An attacker could exploit this vulnerability by sending specially crafted network traffic to a vulnerable Windows system. With the successful exploitation attempt, the malicious network packets could trigger a flaw in how the Windows kernel processes certain TCP/IP data, potentially allowing the attacker to run code with system-level privileges without needing to sign in or interact with a user. 

CVE-2026-48574 is a critical Remote Code Execution vulnerability in Windows Media due to Heap-based buffer overflow which allows an unauthorized attacker to execute the malicious code locally.  

CVE-2026-42987 is a critical Remote Code Execution vulnerability in Windows Deployment Services (WDS). This vulnerability is due to the use after free flaw in Windows Deployment Services and an unauthorized attacker, exploiting this vulnerability, can execute malicious code over a network.  

CVE-2026-44815 is a critical Remote Code Execution vulnerability due to the Stack-based buffer overflow in Windows DHCP Client which allows an unauthorized attacker to execute code over a network. An authenticated user could exploit this vulnerability by sending specially crafted network traffic to a server configured for use as a Dynamic Host Configuration Protocol (DHCP) Server. 

CVE-2026-45456CVE-2026-45458, and CVE-2026-47635 are critical Remote Code Execution vulnerabilities in Microsoft Outlook and Word, caused by the access of resources using an incompatible type ('type confusion') in Microsoft Office. The exploitation of these vulnerabilities allows an unauthorized attacker to execute malicious code locally. Microsoft states that the attack vector is the preview pane of Outlook (classic), and this vulnerability can be exploited when rendering emails in Outlook (classic), as the email rendering in Outlook (classic) utilizes Microsoft Word functionality, where this vulnerability exists. 

CVE-2026-45461CVE-2026-45463CVE-2026-45472 and CVE-2026-45474 are critical Use after free flaw in Microsoft office when exploited, allows an unauthorized attacker to execute malicious code locally. 

CVE-2026-45476 is a critical Elevation of Privilege vulnerability in Microsoft Azure Network Adapter. The vulnerability is due to use after free flaw in Linux MANA Driver. An attacker who already has control of the host environment could trigger the flaw in the guest driver that mishandles memory. This could allow the attacker to read sensitive information from the guest and potentially use that access to gain higher privileges within the guest system. 

CVE-2026-44810 is a critical Improper authentication flaw in Windows Cryptographic Services, when exploited, allows an unauthorized attacker to elevate privileges locally. Microsoft states that, to exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. Additionally, an attacker could convince a local user to open a malicious file. The attacker would have to convince the user to click a link, typically by way of an enticement in an email or instant message and then convince them to open the specially crafted file. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. 

CVE-2026-47644 is a critical information disclosure vulnerability due to the Improper neutralization of special elements in output used by a downstream component('injection') in Copilot Chat (Microsoft Edge). Exploiting this vulnerability allows an unauthorized attacker to disclose information over a network. 

CVE-2026-26142 is a remote code execution vulnerability due to deserialization of untrusted data in Nuance Powerscribe. Exploiting this vulnerability could allow an attacker to execute code over a network. 

Talos also highlights 6 critical vulnerabilities as Microsoft has determined that these are unlikely exploited.  

CVE-2026-32193 is a critical Remote Code Execution Vulnerability in Azure Kubernetes Service (AKS) due to Improper limitation of a pathname to a restricted directory (path traversal). An exploitation of this vulnerability allows an authorized attacker to execute the malicious code locally.  Microsoft states that this vulnerability can be exploited by an attacker who can run an untrusted container configured with host Network could send specially crafted requests to a host level service that was not intended for unauthenticated access. This action could allow the attacker to break out of the container and gain control of the AKS worker node. 

CVE-2026-45648 is a critical Remote Code Execution Vulnerability in Windows Active Directory Domain services due to a Stack-based buffer overflow flaw in Active Directory Domain services. An authorized attacker who exploits this vulnerability could execute the malicious code over a network.  

CVE-2026-47288 is a critical Remote Code Execution Vulnerability in Windows Kerberos Key Distribution Center (KDC) due to the Integer overflow or wraparound in Windows Kerberos, when exploited, allows an authorized attacker to execute malicious code over an adjacent network. 

CVE-2026-47654 is a critical Remote Code Execution Vulnerability in Remote Desktop Client due to the Heap-based buffer overflow flaw which when exploited allows an unauthorized attacker to execute malicious code over a network. 

CVE-2026-33828 is a critical Elevation of Privilege Vulnerability in Windows Device Health Attestation (DHA). This vulnerability is due to the trust boundary violation in Windows Attestation which when exploited, allows an authorized attacker to elevate privileges locally. 

CVE-2026-45460 is a critical Information disclosure vulnerability in Microsoft Office due to a buffer over-read flaw which when exploited allows an unauthorized attacker to disclose information locally. 

Talos also shares few other critical vulnerabilities where Microsoft had mentioned that their exploitation status is unknown or not applicable.  

CVE-2026-48567 is a critical elevation of privilege vulnerability in Azure HorizonDB. This vulnerability arises from an authentication bypass through spoofing in Azure HorizonDB. An unauthorized attacker exploiting this vulnerability can elevate their privileges over a network. 

CVE-2026-48579 is a critical information disclosure vulnerability in Microsoft Exchange Online caused by improper authorization. An unauthorized attacker exploiting this vulnerability could disclose information over a network. 

CVE-2026-45497 and CVE-2026-42824 is a remote code execution vulnerability in Microsoft M365 copilot due to improper neutralization of special elements used in a command (‘command injection’). An unauthorized attacker exploiting this vulnerability could execute code over a network.  

CVE-2026-47655 is a critical information disclosure vulnerability in Microsoft Graph that allows an authorized attacker to expose sensitive information to an unauthorized actor over a network. 

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"   

  • CVE-2026-42905: Windows DWM Core Library Elevation of Privilege Vulnerability 
  • CVE-2026-42980: NT OS Kernel Elevation of Privilege Vulnerability 
  • CVE-2026-42986: Microsoft Graphics Component Elevation of Privilege Vulnerability 
  • CVE-2026-42989: Winlogon Elevation of Privilege Vulnerability 
  • CVE-2026-45481: Microsoft SharePoint Server Spoofing Vulnerability 
  • CVE-2026-45586: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability 
  • CVE-2026-45658 and CVE-2026-50507: Windows BitLocker Security Feature Bypass Vulnerability 
  • CVE-2026-47634: Microsoft SharePoint Server Spoofing Vulnerability 
  • CVE-2026-49160: Windows HTTP Protocol Stack (http.sys) Denial of Service Vulnerability  

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.    

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.    

Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are: 66572-66577, 66581,66589,66590,66594,66595, 66601-66604 

The following Snort 3 rules are also available: 301523-301525, 301527-301529, 301531, 301532. 

  • ✇Firewall Daily – The Cyber Express
  • Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday Ashish Khaitan
    Microsoft's June 2026 Patch Tuesday, released on June 10, 2026, addressed 200 security vulnerabilities across Windows, Office, Azure, and related products—the largest single Patch Tuesday release in the programme's history, surpassing the previous record of 167 CVEs. The update includes fixes for three publicly disclosed zero-day vulnerabilities and 33 critical-severity flaws. The June 2026 release patches vulnerabilities across all major Microsoft product families: Windows 11 and Windows
     

Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday

June 2026 Patch Tuesday

Microsoft's June 2026 Patch Tuesday, released on June 10, 2026, addressed 200 security vulnerabilities across Windows, Office, Azure, and related products—the largest single Patch Tuesday release in the programme's history, surpassing the previous record of 167 CVEs. The update includes fixes for three publicly disclosed zero-day vulnerabilities and 33 critical-severity flaws. The June 2026 release patches vulnerabilities across all major Microsoft product families: Windows 11 and Windows Server, Microsoft Office, Exchange Server, .NET Framework, Azure services, Hyper-V, Remote Desktop Services, and HTTP.sys. Of the 200 CVEs addressed, 33 are rated Critical, 166 are rated Important, and one is rated Moderate. Twenty-eight of the critical flaws are remote code execution vulnerabilities, four are elevation of privilege issues, and one is an information disclosure flaw.

June 2026 Patch Tuesday: Three Zero-Day Vulnerabilities

This month's release includes patches for three publicly disclosed zero-days. None are currently known to be under active exploitation, but security researchers note that patch reversal is underway. CVE-2026-50507 – Windows BitLocker Bypass (publicly disclosed): This vulnerability, nicknamed "YellowKey" by the researcher who discovered it, allows a local attacker with physical access to a device to bypass BitLocker's full-disk encryption and access data on an encrypted drive. The flaw requires local access and an elevated privilege context, reducing immediate remote risk—but it is significant for organisations that rely on BitLocker to protect data on lost or stolen hardware. The severity rating is Important. CVE-2026-49160 – HTTP/2 Denial of Service (publicly disclosed): Dubbed "HTTP/2 Bomb," this vulnerability was publicly disclosed by researchers at offensive security firm Calif before the patch was available. An unauthenticated remote attacker can exhaust server memory by sending crafted HTTP/2 frames, causing denial of service on Windows IIS and other HTTP.sys-dependent services. CVE-2026-45586 – Windows CTFMON Privilege Escalation (publicly disclosed): This elevation-of-privilege flaw in the Windows Collaborative Translation Framework Monitor (ctfmon.exe) grants a logged-in attacker SYSTEM-level privileges. While exploitation requires local access, it is a valuable component in multi-stage attack chains following initial compromise. Headline Critical Vulnerability: CVE-2026-45657
Beyond the three zero-days, security professionals should prioritise CVE-2026-45657, a Windows Kernel use-after-free vulnerability with a CVSS score of 9.8. The flaw stems from improper handling of TCP/IP operations within the Windows Kernel and allows a remote, unauthenticated attacker to execute arbitrary code at the SYSTEM level with no user interaction. Microsoft has classified it as "wormable" under certain network configurations. "CVE-2026-45657 is the kind of vulnerability that keeps defenders up at night," said a Zero Day Initiative researcher. The CVSS 9.8 score, combined with wormable potential, means we could see mass exploitation the moment a reliable exploit is developed.
The record-breaking scale of this month's release creates prioritisation challenges for already-stretched security teams. Microsoft and independent researchers recommend prioritising patches for BitLocker-protected devices, HTTP.sys and IIS infrastructure, Remote Desktop Services, Hyper-V hosts, and Windows Kernel components.

Mitigation Steps

  • Deploy June 2026 cumulative updates (KB5094126 for Windows 11, KB5094127 for Windows 10) without delay.
  • Prioritise CVE-2026-45657 patching on all internet-accessible Windows systems.
  • Apply the IIS/HTTP.sys patch for CVE-2026-49160 on all public-facing web servers.
  • Audit BitLocker-protected device inventory and apply CVE-2026-50507 patches before deploying new field hardware.
  • Review CTFMON and SYSTEM privilege escalation detections in endpoint security tooling.
  • Use the Microsoft Security Update Guide (msrc.microsoft.com) to filter by CVSS >= 9.0 for prioritisation.
  • Validate patch deployment through automated compliance reporting within 72 hours.
  • ✇Malwarebytes
  • Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days
    This month’s Patch Tuesday fixes 206 security flaws in Microsoft software, making it the biggest Patch Tuesday release ever. The update includes 32 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. None are known to have been actively exploited by attackers. The huge number of fixed vulnerabilities makes this the largest Patch Tuesday sin
     

Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days

10 de Junho de 2026, 09:43

This month’s Patch Tuesday fixes 206 security flaws in Microsoft software, making it the biggest Patch Tuesday release ever.

The update includes 32 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. None are known to have been actively exploited by attackers.

The huge number of fixed vulnerabilities makes this the largest Patch Tuesday since Microsoft launched the program in October 2003. The company introduced the monthly update schedule after the Blaster worm caused disruption in the early days of Windows.

How to apply patches and check if you’re protected

These updates fix security problems and keep your Windows PC protected. Here’s how to make sure you’re up to date:

1. Open Settings

  • Click the Start button (the Windows logo at the bottom left of your screen).
  • Click on Settings (it looks like a little gear).

2. Go to Windows Update

  • In the Settings window, select Windows Update (usually at the bottom of the menu on the left).

3. Check for updates

  • Click the button that says Check for updates.
  • Windows will search for the latest Patch Tuesday updates.
  • If you have selected to get the latest updates as soon as they’re available, you may see this under More options.
    In which case you may see a Restart required message. Restart your system and the update will complete.
    restart required
  • If not, continue with the steps below.

4. Download and install

  • If updates are found, they’ll start downloading automatically. Once complete, you’ll see a button that says Install or Restart now.
  • Click Install if needed and follow any prompts. Your computer will usually need a restart to finish the update. If it does, click Restart now.

5. Double-check you’re up to date

  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set!
Windows up to date

Technical details

One publicly disclosed vulnerability is important to mention. This flaw in Windows BitLocker is tracked as CVE-2026-50507 (CVSS score: 6.8 out of 10) and its description states:

“a protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”

BitLocker is a built-in Windows security feature that encrypts your entire hard drive, securing your data from unauthorized access if your device is lost or stolen. However, this vulnerability could allow an attacker with physical access to bypass BitLocker Device Encryption and gain access to encrypted data.

Another is CVE-2026-49160 (CVSS score: 7.5 out of 10) in HTTP.sys. This vulnerability can be exploited to launch a remote denial-of-service attack against major web servers using a technique called HTTP/2 Bomb.

The third to discuss is CVE-2026-45586 (CVSS score: 7.8 out of 10) in the Windows Collaborative Translation Framework (CTFMON). An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. These elevation of privilege (EoP) vulnerabilities are especially valuable to attackers because they can be combined with other flaws to gain full control of a compromised system.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days

Microsoft’s June 2026 patch Tuesday resolves 206 vulnerabilities, including 3 critical zero-days and severe 9.8 CVSS kernel, network and HTTP.sys flaws.
  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Jaeson Schultz
    By Jaeson Schultz Microsoft has released its monthly security update for May 2026, which includes 137 vulnerabilities affecting a range of products, including 31 that Microsoft marked as “critical”. In this month's release, Microsoft has not observed any of the included vulnerabilities being actively exploited in the wild. Out of 31 "critical" entries, 16 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Microsoft Office, Microsoft Word, Win
     

Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities

12 de Maio de 2026, 16:57
Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities

By Jaeson Schultz 

Microsoft has released its monthly security update for May 2026, which includes 137 vulnerabilities affecting a range of products, including 31 that Microsoft marked as “critical”. 

In this month's release, Microsoft has not observed any of the included vulnerabilities being actively exploited in the wild. Out of 31 "critical" entries, 16 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Microsoft Office, Microsoft Word, Windows Native WiFi Miniport Driver, Azure, Office for Android, Microsoft Dynamics 365, Windows GDI, Microsoft SharePoint, Windows Graphics Component, Windows Netlogon, and Windows DNS Client. 

CVE-2026-32161 is a critical use after free vulnerability. Concurrent execution using a shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network. 

CVE-2026-33109 is a critical access control vulnerability in Azure Managed Instance for Apache Cassandra. Improper access control allows an authorized attacker to execute code over a network.

CVE-2026-33844 is a critical input validation vulnerability in Azure Managed Instance for Apache Cassandra. Improper input validation allows an authorized attacker to execute code over a network.

CVE-2026-35421 is a critical heap-based buffer overflow vulnerability in Windows GDI that allows an unauthorized attacker to execute code locally. For this vulnerability to be exploited, a user would need to open or otherwise process a specially crafted Enhanced Metafile (EMF) file using Microsoft Paint. This action is necessary to trigger the affected graphics functionality in the Windows component. 

CVE-2026-40358 is a critical use after free vulnerability in Microsoft Office which allows an unauthorized attacker to execute code locally. 

CVE-2026-40361 is a critical use after free vulnerability in Microsoft Word that allows an unauthorized attacker to execute code locally. 

CVE-2026-40363 is a critical heap-based buffer overflow in Microsoft Office which allows an unauthorized attacker to execute code locally. 

CVE-2026-40364 is a critical heap-based buffer overflow vulnerability. Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 

CVE-2026-40365 is a critical vulnerability affecting Microsoft SharePoint. Insufficient granularity of access control allows an authorized attacker to execute code over a network. In a network-based attack, an authenticated attacker, as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server. 

CVE-2026-40366 is a critical use after free vulnerability in Microsoft Word which allows an unauthorized attacker to execute code locally. 

CVE-2026-40367 is a critical vulnerability affecting Microsoft Word. An untrusted pointer dereference may allow an unauthorized attacker to execute code locally. 

CVE-2026-40403 is a critical heap-based buffer overflow vulnerability in Windows Win32K – GRFX that allows an authorized attacker to execute code locally. This vulnerability could lead to a contained execution environment escape. In the case of a Remote Desktop connection, an attacker with control of a Remote Desktop Server could trigger a remote code execution (RCE) on the machine when a victim connects to the attacking server with a vulnerable Remote Desktop Client. 

CVE-2026-41089 is a critical stack-based buffer overflow in Windows Netlogon that allows an unauthorized attacker to execute code over a network. An attacker could send a specially crafted network request to a Windows server that is acting as a domain controller. If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access. 

CVE-2026-41096 is a critical heap-based overflow vulnerability in Windows DNS Client. An attacker could exploit this vulnerability by sending a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory. In certain configurations, this could allow the attacker to run code remotely on the affected system without authentication. 

CVE-2026-42831 is a critical heap-based buffer overflow vulnerability in Office for Android that allows an unauthorized attacker to execute code locally. An attacker must send a user a malicious Office file and convince them to open it. 

CVE-2026-42898 is a critical code injection vulnerability in Microsoft Dynamics 365 (on-premises). Improper control of generation of code ('code injection') allows an authorized attacker to execute code over a network. An attacker with the required permissions could modify the saved state of a process session in Dynamics CRM and trigger the system to process that data, which could result in the server unintentionally executing malicious code.

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"   

  • CVE-2026-33835: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 
  • CVE-2026-33837: Windows TCP/IP Local Elevation of Privilege Vulnerability 
  • CVE-2026-33840: Win32k Elevation of Privilege Vulnerability 
  • CVE-2026-33841: Windows Kernel Elevation of Privilege Vulnerability 
  • CVE-2026-35416: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 
  • CVE-2026-35417: Windows Win32k Elevation of Privilege Vulnerability 
  • CVE-2026-40369: Windows Kernel Elevation of Privilege Vulnerability 
  • CVE-2026-40397: Windows Common Log File System Driver Elevation of Privilege Vulnerability 
  • CVE-2026-40398: Windows Remote Desktop Services Elevation of Privilege Vulnerability 

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.    

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.    

Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are: 1:66438-1:66445, 1:66451-1:66460, and 1:66470-1:66476.  

The following Snort 3 rules are also available: 1:301494-1:301497, 1:301500-1:301506, 1:66472-1:66473, and 1:66476. 

Microsoft May 2026 Patch Tuesday Fixes 120 Vulnerabilities, No Zero-Day Exploits Reported

May 2026 Patch Tuesday

Microsoft has rolled out its May 2026 Patch Tuesday security updates, delivering fixes for approximately 120 vulnerabilities across Windows, Microsoft Office, networking services, and enterprise platforms. Unlike several recent monthly releases, this update contains no publicly disclosed or actively exploited zero-day vulnerabilities, making it a relatively less chaotic cycle for IT and security teams.  Even without emergency-level exploits, the Microsoft May 2026 Patch Tuesday release remains significant due to the large number of critical flaws addressed. The company confirmed that the update resolves 17 critical vulnerabilities, including 14 remote code execution (RCE) flaws, two elevation-of-privilege issues, and one information disclosure vulnerability. 

Microsoft May 2026 Patch Tuesday: Vulnerabilities That Demand Attention 

One of the most important areas covered in the May 2026 Patch Tuesday update involves multiple vulnerabilities affecting Microsoft Office applications, particularly Word and Excel.  According to Microsoft, attackers could exploit these flaws by tricking users into opening malicious files. Several of the vulnerabilities can also be triggered through the preview pane, allowing remote code execution without fully opening the attachment.  Because Office documents remain a common attack vector in phishing campaigns, security professionals are strongly recommending that organizations prioritize deployment of these updates, especially in environments where employees regularly receive external attachments. 

Windows GDI Flaw Allows Exploitation Through Microsoft Paint 

Among the noteworthy issues patched during Microsoft’s May 2026 Patch Tuesday rollout is CVE-2026-35421, a Windows GDI remote code execution vulnerability.  The flaw can be exploited through a malicious Enhanced Metafile (EMF) image opened in Microsoft Paint. Successful exploitation could allow attackers to execute arbitrary code on the victim’s machine.  Although the attack requires user interaction, researchers warned that image-based attacks are often effective because users may not recognize specially crafted files as dangerous. 

SharePoint and DNS Vulnerabilities Raise Enterprise Security Concerns 

Another major vulnerability addressed in the May 2026 Patch Tuesday release is CVE-2026-40365, a remote code execution flaw affecting Microsoft SharePoint Server.  Microsoft stated that an authenticated attacker could use the vulnerability to launch a network-based attack capable of remotely executing code on vulnerable SharePoint systems. Since SharePoint environments often store sensitive internal data and business documents, the flaw is expected to receive close attention from enterprise administrators.  The company also patched CVE-2026-41096, a serious Windows DNS Client remote code execution vulnerability. The flaw involves improper handling of specially crafted DNS responses sent by attacker-controlled DNS servers.  The issue stems from a heap-based buffer overflow condition in Windows NetLogon functionality. A successful attack could corrupt system memory and allow remote code execution without requiring authentication. 

Dynamics 365 Vulnerability Carries Near-Maximum Severity Score 

Another critical issue fixed during the Microsoft May 2026 Patch Tuesday cycle is CVE-2026-42898, a remote code execution vulnerability affecting on-premises versions of Microsoft Dynamics 365.  The flaw received a CVSS severity score of 9.9 and requires no user interaction for exploitation. Researchers warned that attacks targeting Dynamics 365 environments could have widespread consequences because the platform frequently connects with multiple enterprise systems and sensitive databases.  Previous attacks involving Dynamics infrastructure have exposed privileged business information, making this vulnerability especially concerning for large organizations.

Windows 11 Cumulative Updates Introduce New Features 

As part of the May 2026 Patch Tuesday rollout, Microsoft released Windows 11 cumulative updates KB5089549 and KB5087420 for versions 25H2, 24H2, and 23H2.  The updates are mandatory because they contain the latest security fixes and stability improvements.  After installation: 
  • Windows 11 25H2 updates to build 26200.8457  
  • Windows 11 24H2 updates to build 26100.8457  
  • Windows 11 23H2 updates to build 22631.7079  
Microsoft confirmed that versions 25H2 and 24H2 share the same underlying update structure, meaning users receive identical fixes and improvements across both versions. 

Xbox-Inspired Desktop Experience Added to Windows 11 

One of the more noticeable additions included in the Microsoft May 2026 Patch Tuesday update is a new Xbox-style desktop experience for PCs.  The feature is designed to provide a console-like interface on Windows devices. Alongside the visual changes, Microsoft also introduced reliability improvements for the taskbar and enhancements to Windows Hello authentication.  The update improves both Windows Hello Face recognition reliability and the persistence of fingerprint authentication across system upgrades. 

File Explorer Receives Major Improvements 

File Explorer received several updates in the latest May 2026 Patch Tuesday release.  Microsoft expanded archive support to include formats such as: 
  • uu  
  • cpio  
  • xar  
  • NuGet Packages (nupkg)  
The company also improved how File Explorer preserves View and Sort preferences in folders like Downloads and Documents when applications directly launch those locations.  Additionally, Microsoft fixed a white flash issue that sometimes appeared in dark mode while opening “This PC” or resizing the Details pane.  Explorer.exe reliability was also enhanced to reduce crashes and improve overall responsiveness. 

Input, Voice Typing, and Haptic Feedback Enhancements 

The Microsoft May 2026 Patch Tuesday updates introduced several improvements to input and accessibility features.  Compatible devices can now provide haptic feedback during actions such as snapping windows or aligning PowerPoint objects. Current supported hardware includes: 
  • Surface Slim Pen 2  
  • ASUS Pen 3.0  
  • MSI Pen 2  
Microsoft added that support for additional peripherals, including select mouse devices, could arrive in future hardware updates.  Voice typing on the touch keyboard also received a redesign. The updated interface removes the previous full-screen overlay and displays animations directly on the dictation key to reduce distractions. In addition, Microsoft introduced the Arabic 101 Legacy keyboard layout for users who prefer the earlier Arabic keyboard configuration.

Storage, Printing, and Performance Updates Included 

Several broader system improvements were bundled into the May 2026 Patch Tuesday release.  Microsoft increased the FAT32 formatting limit through the command line from 32GB to 2TB. The update also improves storage settings performance when viewing large disk volumes. Additional changes include: 
  • Reduced memory usage in Delivery Optimization  
  • Improved audio driver compatibility with midisrv.exe  
  • Better taskbar system tray reliability  
  • Enhanced startup application performance  
  • Improved monitor color profile persistence  
  • Simplified kiosk mode app configuration  
The update also introduces a new icon identifying printers that support Windows Protected Print Mode. 

Microsoft Introduces More Secure Batch File Processing 

Microsoft added a new security-focused feature aimed at administrators and enterprise policy managers.  The May 2026 Patch Tuesday update introduces a secure processing mode for batch files and Command Prompt scripts. When enabled, the feature prevents batch files from being modified during execution.  Administrators can activate the setting using the following registry path:  Registry Key: HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor  Value Name: LockBatchFilesWhenInUse  The feature can also be enabled through Application Control for Business policies. 
❌
❌