Microsoft May Patch Tuesday: 139 Updates, No Zero-Days

Critical RCE vulnerabilities in core Windows services require immediate attention to secure enterprise AI infrastructure
30-Second TL;DR
What Changed
139 security updates released for Windows, Office, .NET, and SQL Server.
Why It Matters
The presence of multiple RCE vulnerabilities in core infrastructure components like Netlogon and DNS Client poses a significant risk to enterprise environments. Organizations should prioritize patching internet-facing services and domain controllers to prevent potential exploitation.
What To Do Next
Review your infrastructure's exposure to the Word Preview Pane attack vector and prioritize patching domain controllers and internet-facing endpoints immediately.
Key Points
- •139 security updates released for Windows, Office, .NET, and SQL Server.
- •Critical RCE vulnerabilities identified in Netlogon, DNS Client, and SSO plugins.
- •Word Preview Pane vulnerabilities (CVE-2026-40361/40364) flagged as 'Exploitation More Likely'.
Deep Insight
Background and context from public sources — not the original article. 24 sources cited.
Enhanced Key Takeaways
- •Microsoft's May 2026 Patch Tuesday addressed 118 to 139 Common Vulnerabilities and Exposures (CVEs), with various sources reporting slightly different counts, including 16 to 31 critical vulnerabilities and 102 important ones.
- •This Patch Tuesday marks the first time since June 2024 that no zero-day vulnerabilities were actively exploited in the wild or publicly disclosed prior to the release, breaking a 22-month streak.
- •The critical Word Preview Pane vulnerabilities (CVE-2026-40361/40364) are 'Use After Free' and 'Type Confusion' flaws, respectively, and can be triggered by merely viewing a malicious document in Outlook's Reading Pane or Windows File Explorer's Preview Pane, without requiring the user to open the document or enable macros.
- •The Windows Netlogon Remote Code Execution (RCE) vulnerability (CVE-2026-41089) is a stack-based buffer overflow that allows an unauthenticated attacker to execute code on a domain controller by sending a specially crafted network request.
- •Elevation of Privilege (EoP) vulnerabilities constituted the largest category of patches this month, accounting for 48.3% of the addressed flaws, followed by Remote Code Execution (RCE) vulnerabilities at 24.6%.
Technical Deep Dive
- Word Preview Pane Vulnerabilities (CVE-2026-40361/40364): These are classified as a 'Use After Free' (CWE-416) and 'Type Confusion' vulnerability, respectively, within Microsoft Office Word. The exploit vector is local, but the attack can be triggered remotely by rendering a malicious document in Outlook's Reading Pane or Windows File Explorer's Preview Pane. This bypasses the need for user interaction like opening the document or enabling macros, allowing remote code execution with the privileges of the current user.
- Windows Netlogon Remote Code Execution Vulnerability (CVE-2026-41089): This critical vulnerability is a stack-based buffer overflow in the Windows Netlogon service. An unauthenticated attacker can exploit it by sending a specially crafted network request to a Windows server configured as a domain controller, leading to arbitrary code execution with SYSTEM privileges. This is similar in impact to previous Netlogon vulnerabilities like 'Zerologon' (CVE-2020-1472), which involved cryptographic flaws in the Netlogon Remote Protocol (MS-NRPC) allowing identity spoofing and password resets.
- Windows DNS Client Remote Code Execution Vulnerability (CVE-2026-41096): This is a heap-based buffer overflow flaw in the Windows DNS Client. Exploitation occurs when an attacker sends a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory. In certain configurations, this can lead to remote code execution on the affected system without authentication. Past critical DNS vulnerabilities, such as 'SIGRed' (CVE-2020-1350), also involved buffer overflows in the Windows DNS Server and were deemed 'wormable'.
- Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability (CVE-2026-41103): This critical vulnerability stems from an incorrect implementation of an authentication algorithm (CWE-303). An unauthenticated remote attacker can exploit this flaw during the login process by sending a specially crafted response message, allowing them to elevate privileges and gain unauthorized access to Jira or Confluence as a valid user, bypassing Microsoft Entra ID authentication.
Future ImplicationsAI analysis grounded in cited sources
Timeline
- 2003-10Microsoft formalized 'Patch Tuesday' to standardize security update releases on the second Tuesday of each month.
- 2020-07Microsoft patched the critical Windows DNS Server RCE vulnerability (CVE-2020-1350), also known as SIGRed.
- 2020-08Microsoft addressed the critical Netlogon RCE vulnerability (CVE-2020-1472), dubbed 'Zerologon'.
- 2021-02Netlogon Domain Controller Enforcement Mode was enabled by default with the February security update, related to CVE-2020-1472.
- 2025-08Microsoft issued urgent security updates for critical Office RCE vulnerabilities (CVE-2025-53731, CVE-2025-53740) exploitable via the Preview Pane.
- 2026-05Microsoft released 139 security updates, including critical RCEs in Netlogon, DNS Client, SSO plugins, and Word Preview Pane, with no zero-days reported for the first time since June 2024.
Sources (24)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events →
AI-curated news aggregator. All content rights belong to original publishers.
Original source: Computerworld ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
The weekly digest
One email a week. Unsubscribe anytime.