Critical RCE and EoP vulnerabilities in Microsoft products addressed in May Patch Tuesday
Updated:
· First: 13.05.2026 11:15
· 📰 1 src / 1 articles
Microsoft released 120 CVEs in the May 2026 Patch Tuesday update, including 17 critical flaws, primarily remote code execution (RCE) and elevation of privilege (EoP) issues. A new multi-model agentic AI system discovered 16 of these CVEs. Key critical vulnerabilities include CVE-2026-41089 (Windows Netlogon stack-based buffer overflow, CVSS 9.8), CVE-2026-41096 (Windows DNS client RCE, CVSS 9.8), and CVE-2026-42898 (Microsoft Dynamics 365 On-Premises RCE). These flaws allow attackers to gain system privileges, compromise endpoints, and execute malicious code with minimal prerequisites.