Skip to main content
QUIETLYTIC
Advisory

Microsoft Patch Tuesday May 2026: 1129 Vulnerabilities Fixed

Microsoft's May 12, 2026 Patch Tuesday fixed 1129 vulnerabilities (57 critical, 240 important) — 1 of them is confirmed under active exploitation, per CISA…

Microsoft Patch Tuesday May 2026: 1129 Vulnerabilities Fixed — Advisory research covering CVE-2026-23652, CVE-2026-39821, CVE-2026-40412, CVE-2026-41104, CVE-2026-42822, CVE-2026-42826, CVE-2026-42901, CVE-2026-46595, CVE-2026-47280, CVE-2026-33109, CVE-2026-40411, CVE-2026-42898, CVE-2026-7374, CVE-2025-71305, CVE-2026-31705, CVE-2026-31718, CVE-2026-33278, CVE-2026-41089, CVE-2026-41096, CVE-2026-45899, CVE-2026-33823, CVE-2026-35428, CVE-2026-41615, CVE-2026-40379, CVE-2026-40402, CVE-2026-41090, CVE-2026-33843, CVE-2026-41103, CVE-2026-8450, CVE-2026-33844, CVE-2026-32207, CVE-2026-35430, CVE-2026-40365, CVE-2026-40403, CVE-2026-35435, CVE-2026-40358, CVE-2026-40361, CVE-2026-40363, CVE-2026-40364, CVE-2026-40366, CVE-2026-40367, CVE-2026-34327, CVE-2026-41105, CVE-2026-42897, CVE-2026-42945, CVE-2026-45584, CVE-2026-35421, CVE-2026-42831, CVE-2026-26147, CVE-2026-33821, CVE-2026-23663, CVE-2026-26129, CVE-2026-26164, CVE-2026-32161, CVE-2026-33111, CVE-2026-42827, CVE-2026-6722, CVE-2026-42823, CVE-2026-33117, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42496, CVE-2026-42508, CVE-2026-42833, CVE-2026-23918, CVE-2026-31706, CVE-2026-31709, CVE-2026-31717, CVE-2026-33110, CVE-2026-33112, CVE-2026-34329, CVE-2026-35436, CVE-2026-35439, CVE-2026-40357, CVE-2026-40370, CVE-2026-40420, CVE-2026-41086, CVE-2026-41094, CVE-2026-41109, CVE-2026-41613, CVE-2026-43249, CVE-2026-45495, CVE-2026-45659, CVE-2026-6473, CVE-2026-6475, CVE-2026-6477, CVE-2026-6637, CVE-2026-43493, CVE-2026-4892, CVE-2026-31712, CVE-2026-35438, CVE-2026-33833, CVE-2026-42013, CVE-2026-5260, CVE-2026-31708, CVE-2026-31771, CVE-2026-40415, CVE-2026-43618, CVE-2026-47783, CVE-2026-47784, CVE-2026-6665, CVE-2026-8711, CVE-2026-9256, CVE-2026-34332, CVE-2026-40368, CVE-2026-47294, CVE-2026-31694, CVE-2026-31700, CVE-2026-31702, CVE-2026-31721, CVE-2026-31722, CVE-2026-31723, CVE-2026-31724, CVE-2026-31725, CVE-2026-32204, CVE-2026-33834, CVE-2026-33835, CVE-2026-33837, CVE-2026-33838, CVE-2026-33840, CVE-2026-33841, CVE-2026-34330, CVE-2026-34333, CVE-2026-34334, CVE-2026-34336, CVE-2026-34337, CVE-2026-34338, CVE-2026-34343, CVE-2026-34344, CVE-2026-34351, CVE-2026-35415, CVE-2026-35417, CVE-2026-35418, CVE-2026-35420, CVE-2026-40034, CVE-2026-40359, CVE-2026-40360, CVE-2026-40362, CVE-2026-40369, CVE-2026-40377, CVE-2026-40381, CVE-2026-40382, CVE-2026-40397, CVE-2026-40398, CVE-2026-40399, CVE-2026-40407, CVE-2026-40408
Severity
Critical
Confidence
High
Status
Active

Full CVE Roster

All 150 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search — 4 flagged as actively exploited (KEV).

CVE ID Title CVSS Severity KEV
CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability 10.0 critical
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna 10.0 critical
CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability 10.0 critical
CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability 10.0 critical
CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-42826 Azure DevOps Information Disclosure Vulnerability 10.0 critical
CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-46595 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh 10.0 critical
CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability 10.0 critical
CVE-2026-33109 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability 9.9 critical
CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability 9.9 critical
CVE-2026-42898 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 9.9 critical
CVE-2026-7374 Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability 9.9 critical
CVE-2025-71305 drm/display/dp_mst: Add protection against 0 vcpi 9.8 critical
CVE-2026-31705 ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment 9.8 critical
CVE-2026-31718 ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger 9.8 critical
CVE-2026-33278 Possible arbitrary code execution during DNSSEC validation 9.8 critical
CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability 9.8 critical Yes
CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability 9.8 critical
CVE-2026-45899 ext4: drop extent cache when splitting extent fails 9.8 critical
CVE-2026-33823 Microsoft Team Events Portal Information Disclosure Vulnerability 9.6 critical
CVE-2026-35428 Azure Cloud Shell Spoofing Vulnerability 9.6 critical
CVE-2026-41615 Microsoft Authenticator Information Disclosure Vulnerability 9.6 critical
CVE-2026-40379 Azure Entra ID Spoofing Vulnerability 9.3 critical
CVE-2026-40402 Windows Hyper-V Elevation of Privilege Vulnerability 9.3 critical
CVE-2026-41090 Microsoft Copilot Tampering Vulnerability 9.3 critical
CVE-2026-33843 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability 9.1 critical
CVE-2026-41103 Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability 9.1 critical
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() 9.1 critical
CVE-2026-33844 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability 9.0 critical
CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability 8.8 critical
CVE-2026-35430 Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability 8.8 critical
CVE-2026-40365 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 critical
CVE-2026-40403 Windows Graphics Component Remote Code Execution Vulnerability 8.8 critical
CVE-2026-35435 Azure AI Foundry Elevation of Privilege Vulnerability 8.6 critical
CVE-2026-40358 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-40361 Microsoft Outlook and Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-40363 Microsoft Office Remote Code Execution Vulnerability 8.4 critical
CVE-2026-40364 Microsoft Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-40366 Microsoft Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability 8.4 critical
CVE-2026-34327 Microsoft Partner Center Spoofing Vulnerability 8.2 critical
CVE-2026-41105 Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability 8.1 critical
CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability 8.1 critical Yes
CVE-2026-42945 NGINX ngx_http_rewrite_module vulnerability 8.1 critical Yes
CVE-2026-45584 Microsoft Defender Remote Code Execution Vulnerability 8.1 critical
CVE-2026-35421 Windows GDI Remote Code Execution Vulnerability 7.8 critical
CVE-2026-42831 Microsoft Office Remote Code Execution Vulnerability 7.8 critical
CVE-2026-26147 Azure Stack HCI Information Disclosure Vulnerability 7.7 critical
CVE-2026-33821 Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability 7.7 critical
CVE-2026-23663 Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability 7.5 critical
CVE-2026-26129 M365 Copilot Information Disclosure Vulnerability 7.5 critical
CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability 7.5 critical
CVE-2026-32161 Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability 7.5 critical
CVE-2026-33111 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability 7.5 critical
CVE-2026-42827 M365 Copilot Information Disclosure Vulnerability 6.5 critical
CVE-2026-6722 Use-After-Free in SOAP using Apache map — critical
CVE-2026-42823 Azure Logic Apps Elevation of Privilege Vulnerability 9.9 high
CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability 9.1 high
CVE-2026-39830 Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh 9.1 high
CVE-2026-39831 Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh 9.1 high
CVE-2026-39832 Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent 9.1 high
CVE-2026-39833 Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent 9.1 high
CVE-2026-39834 Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh 9.1 high
CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory 9.1 high
CVE-2026-42508 Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts 9.1 high
CVE-2026-42833 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 9.1 high
CVE-2026-23918 Apache HTTP Server: http2: double free and possible RCE on early reset 8.8 high
CVE-2026-31706 ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl() 8.8 high
CVE-2026-31709 smb: client: validate the whole DACL before rewriting it in cifsacl 8.8 high
CVE-2026-31717 ksmbd: validate owner of durable handle on reconnect 8.8 high
CVE-2026-33110 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-33112 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-34329 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 8.8 high
CVE-2026-35436 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability 8.8 high
CVE-2026-35439 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-40357 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-40370 SQL Server Remote Code Execution Vulnerability 8.8 high
CVE-2026-40420 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability 8.8 high
CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability 8.8 high
CVE-2026-41094 Microsoft Data Formulator Remote Code Execution Vulnerability 8.8 high
CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability 8.8 high
CVE-2026-41613 Visual Studio Code Elevation of Privilege Vulnerability 8.8 high
CVE-2026-43249 9p/xen: protect xen_9pfs_front_free against concurrent calls 8.8 high
CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 8.8 high
CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability 8.8 high Yes
CVE-2026-6473 PostgreSQL server undersizes allocations, via integer wraparound 8.8 high
CVE-2026-6475 PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice 8.8 high
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory 8.8 high
CVE-2026-6637 PostgreSQL refint allows stack buffer overflow and SQL injection 8.8 high
CVE-2026-43493 crypto: pcrypt - Fix handling of MAY_BACKLOG requests 8.4 high
CVE-2026-4892 CVE-2026-4892 8.4 high
CVE-2026-31712 ksmbd: require minimum ACE size in smb_check_perm_dacl() 8.3 high
CVE-2026-35438 Windows Admin Center Elevation of Privilege Vulnerability 8.3 high
CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability 8.2 high
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name 8.2 high
CVE-2026-5260 Gnutls: gnutls: information disclosure via heap overread in rsa key exchange 8.2 high
CVE-2026-31708 smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path 8.1 high
CVE-2026-31771 Bluetooth: hci_event: move wake reason storage into validated event handlers 8.1 high
CVE-2026-40415 Windows TCP/IP Remote Code Execution Vulnerability 8.1 high
CVE-2026-43618 Rsync < 3.4.3 Integer Overflow Information Disclosure 8.1 high
CVE-2026-47783 In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass. 8.1 high
CVE-2026-47784 In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass. 8.1 high
CVE-2026-6665 PgBouncer buffer overflow in SCRAM 8.1 high
CVE-2026-8711 NGINX JavaScript vulnerability 8.1 high
CVE-2026-9256 NGINX ngx_http_rewrite_module vulnerability 8.1 high
CVE-2026-34332 Windows Kernel-Mode Driver Remote Code Execution Vulnerability 8.0 high
CVE-2026-40368 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.0 high
CVE-2026-47294 Microsoft SharePoint Server Remote Code Execution Vulnerability 8.0 high
CVE-2026-31694 fuse: reject oversized dirents in page cache 7.8 high
CVE-2026-31700 net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() 7.8 high
CVE-2026-31702 f2fs: fix use-after-free of sbi in f2fs_compress_write_end_io() 7.8 high
CVE-2026-31721 usb: gadget: f_hid: move list and spinlock inits from bind to alloc 7.8 high
CVE-2026-31722 usb: gadget: f_rndis: Fix net_device lifecycle with device_move 7.8 high
CVE-2026-31723 usb: gadget: f_subset: Fix net_device lifecycle with device_move 7.8 high
CVE-2026-31724 usb: gadget: f_eem: Fix net_device lifecycle with device_move 7.8 high
CVE-2026-31725 usb: gadget: f_ecm: Fix net_device lifecycle with device_move 7.8 high
CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33834 Windows Event Logging Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33837 Windows TCP/IP Local Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33838 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33840 Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2026-33841 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34330 Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34333 Windows Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34334 Windows TCP/IP Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34336 Windows DWM Core Library Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34337 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34338 Windows Telephony Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34343 Windows Application Identity (AppID) Subsystem Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34344 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 7.8 high
CVE-2026-34351 Windows TCP/IP Elevation of Privilege Vulnerability 7.8 high
CVE-2026-35415 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 7.8 high
CVE-2026-35417 Windows Win32k Elevation of Privilege Vulnerability 7.8 high
CVE-2026-35418 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-35420 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40034 gitoxide - Command Injection via Partial .gitmodules Override in gix-submodule 7.8 high
CVE-2026-40359 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-40360 Microsoft Excel Information Disclosure Vulnerability 7.8 high
CVE-2026-40362 Microsoft Excel Remote Code Execution Vulnerability 7.8 high
CVE-2026-40369 Windows Kernel Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40377 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40381 Azure Connected Machine Agent Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40382 Windows Telephony Service Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40397 Windows Common Log File System Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40398 Windows Remote Desktop Services Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40399 Windows TCP/IP Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40407 Windows Common Log File System Driver Elevation of Privilege Vulnerability 7.8 high
CVE-2026-40408 Windows WAN ARP Driver Elevation of Privilege Vulnerability 7.8 high

Microsoft’s May 12, 2026 Patch Tuesday release covers 1129 CVEs: 57 rated critical, 240 rated important, and 415 rated moderate. Of these, 1 of them is confirmed under active exploitation.

Severity Breakdown

Severity Count
Critical 57
Important 240
Moderate 415
Actively exploited (CISA KEV) 1

Highest-Severity Vulnerabilities

Top 20 of 1129 total, by CVSS/severity:

CVE Title CVSS
CVE-2026-23652 Microsoft Power Pages Remote Code Execution Vulnerability 10.0
CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna 10.0
CVE-2026-40412 Azure Orbital Spatio Remote Code Execution Vulnerability 10.0
CVE-2026-41104 Microsoft Planetary Computer Pro Information Disclosure Vulnerability 10.0
CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability 10.0
CVE-2026-42826 Azure DevOps Information Disclosure Vulnerability 10.0
CVE-2026-42901 Microsoft Entra ID Elevation of Privilege Vulnerability 10.0
CVE-2026-46595 Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh 10.0
CVE-2026-47280 Azure Resource Manager Elevation of Privilege Vulnerability 10.0
CVE-2026-33109 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability 9.9
CVE-2026-40411 Azure Virtual Network Gateway Remote Code Execution Vulnerability 9.9
CVE-2026-42898 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 9.9
CVE-2026-7374 Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability 9.9
CVE-2026-42823 Azure Logic Apps Elevation of Privilege Vulnerability 9.9
CVE-2025-71305 drm/display/dp_mst: Add protection against 0 vcpi 9.8
CVE-2026-31705 ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment 9.8
CVE-2026-31718 ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger 9.8
CVE-2026-33278 Possible arbitrary code execution during DNSSEC validation 9.8
CVE-2026-41089 Windows Netlogon Remote Code Execution Vulnerability 9.8
CVE-2026-41096 Windows DNS Client Remote Code Execution Vulnerability 9.8

CVSS scores are sourced directly from Microsoft’s CVRF data as of May 12, 2026; exploitation status is cross-checked against CISA’s KEV catalog. Later re-scoring by NVD can shift a CVE’s score after this report was generated.

Why This Matters

With 1 vulnerability already under active exploitation, prioritizing this month’s patches isn’t optional for exposed systems — attackers are demonstrably already using at least one of these flaws. Organizations should prioritize the critical- and important-rated CVEs above, especially any with public proof-of-concept exploits.

Frequently Asked Questions

How many vulnerabilities did Microsoft patch in May 2026? 1129 CVEs, per Microsoft’s May 12, 2026 Patch Tuesday release.

Were any May 2026 Patch Tuesday vulnerabilities actively exploited? Yes — 1 of them is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog as of May 12, 2026.


Data sourced from Microsoft Security Response Center (MSRC) CVRF v3.0 and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated May 12, 2026. See more vulnerability research.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 Microsoft Security Response Center (MSRC)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools