Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft security patch release for CVE-2026-41089

Security Patch Release
First reported
Last updated
Happening score
H score 27
2 unique sources, 2 articles

Summary

Hide ▲

Microsoft and other major software vendors shipped a heavy May 2026 patch cycle, with fixes spanning Windows, iOS, Firefox, Oracle products, and Chrome. Microsoft Patch Tuesday alone addressed at least 118 vulnerabilities, including CVE-2026-41089, CVE-2026-41096, and CVE-2026-41103. The round mattered because Microsoft said it was the first Patch Tuesday in nearly two years without an actively exploited zero-day, while the other vendors also accelerated their release cadence. Some updates require immediate installation, and Chrome updates still need a full browser restart.

Related Happenings

Microsoft security patch release for CVE-2026-41091 and CVE-2026-45498

Security Patch Release
First: 21.05.2026 10:49 Last: 21.05.2026 10:49 Sources 1

About this happening: Microsoft rolled out security updates for Defender and related malware protection components to address two zero-days: CVE-2026-41091 and CVE-2026-45498. The fixes cover affected...

Latest development: 21.05.2026 12:52

Microsoft released patches for Microsoft Defender Antimalware Platform version 4.18.26040.7 to address CVE-2026-41091, a link-following privilege-escalation flaw that can let an authorized attacker elevate privileges locally to System, and CVE-2026-45498, a denial-of-service flaw. Microsoft said both vulnerabilities were publicly disclosed and exploited in the wild as zero-days. CISA added both flaws to its Known Exploited Vulnerabilities (KEV) list and urged federal agencies to patch them by June 3.

Cisco security patch release for CVE-2026-20182

Security Patch Release
First: 14.05.2026 20:45 Last: 14.05.2026 20:45 Sources 1

About this happening: Cisco released **updates** for **CVE-2026-20182**, a **maximum-severity authentication bypass** in **Catalyst SD-WAN Controller/Manager**, after the flaw was **exploited in limite...

Microsoft May 2026 Patch Tuesday release

Security Patch Release
First: 13.05.2026 13:36 Last: 13.05.2026 13:36 Sources 1

About this happening: Microsoft's **May 13, 2026 Patch Tuesday** release fixed **138 vulnerabilities** across its product portfolio, including **Windows**, **Azure**, and **Edge**. None of the flaws we...

Windows 10 KB5087544 extended security update

Security Patch Release
First: 12.05.2026 21:58 Last: 12.05.2026 21:58 Sources 1

About this happening: **Microsoft** released **Windows 10 KB5087544** for **Windows 10 ESU/LTSC systems**, addressing **May 2026 Patch Tuesday vulnerabilities** and a **Remote Desktop warnings** issue....

Microsoft Windows 11 mandatory Patch Tuesday updates (KB5089549, KB5087420)

Security Patch Release
First: 12.05.2026 21:09 Last: 12.05.2026 21:09 Sources 1

About this happening: Microsoft released **mandatory Windows 11 cumulative updates** for **KB5089549** and **KB5087420**, delivering the **May 2026 Patch Tuesday** fixes for **120 vulnerabilities** acr...

Timeline

  1. 13.05.2026 00:46 1 articles · 14d ago

    Chrome security update rollout

    Mitigation Patch Update

    Google started rolling out Chrome browser updates that fixed 127 security flaws, a steep increase from the 30 vulnerabilities addressed the previous month.

    Show sources
  2. 13.05.2026 00:46 1 articles · 14d ago

    iOS 15 security update

    Mitigation Patch Update

    Apple shipped iOS 15 and addressed at least 52 vulnerabilities, with the fixes backported to iPhone 6s and iOS 15 devices.

    Show sources
  3. 13.05.2026 00:46 2 articles · 14d ago

    Microsoft Patch Tuesday fixes

    Initial Disclosure

    Microsoft released at least 118 security updates for Windows operating systems and other products on May 12, including critical flaws in Windows Netlogon, the Windows DNS client implementation, and an elevation-of-privilege issue that can bypass Entra ID; Microsoft also said this was the first Patch Tuesday in nearly two years without emergency zero-day flaws already being exploited.

    Show sources