How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.
Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)
May 2026 Patch Tuesday: Microsoft fixed 117 vulnerabilities, 16 of them Critical. None was known to be exploited on the day. Released Tue 12 May 2026.
- 117vulnerabilities fixed
- 16Critical
- 0exploited before the fix
- 0publicly disclosed
- 0now on CISA KEV
By type: 58 elevation of privilege, 29 remote code execution, 8 information disclosure, 8 denial of service, 7 spoofing, 5 security feature bypass, 2 tampering.
Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.
Patch these first
Nothing this month was known to be exploited or public when it was fixed, and none of it is on CISA’s list yet. Patch in your normal cycle, Critical first.
Critical (16)
Microsoft’s top rating: usually code execution with little or no user action.
| CVE | What | Impact | CVSS |
|---|---|---|---|
CVE-2026-42898 | Microsoft Dynamics 365 On-Premises Remote Code Execution | Remote Code Execution | 9.9 |
CVE-2026-41089 | Windows Netlogon Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-41096 | Windows DNS Client Remote Code Execution | Remote Code Execution | 9.8 |
CVE-2026-40402 | Windows Hyper-V Elevation of Privilege | Elevation of Privilege | 9.3 |
CVE-2026-41103 | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege | Elevation of Privilege | 9.1 |
CVE-2026-40365 | Microsoft SharePoint Server Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-40403 | Windows Graphics Component Remote Code Execution | Remote Code Execution | 8.8 |
CVE-2026-40358 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-40361 | Microsoft Outlook and Word Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-40363 | Microsoft Office Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-40364 | Microsoft Word Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-40366 | Microsoft Word Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-40367 | Microsoft Word Remote Code Execution | Remote Code Execution | 8.4 |
CVE-2026-35421 | Windows GDI Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-42831 | Microsoft Office Remote Code Execution | Remote Code Execution | 7.8 |
CVE-2026-32161 | Windows Native WiFi Miniport Driver Remote Code Execution | Remote Code Execution | 7.5 |
Added to CISA KEV in May 2026 (21)
Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.
| CVE | Vendor and product | What | Added | Federal deadline | Ransomware |
|---|---|---|---|---|---|
CVE-2026-0257 | Palo Alto Networks PAN-OS | Authentication Bypass | 29 May | 1 Jun 2026 | Known |
CVE-2026-45321 | TanStack TanStack | TanStack Unspecified | 27 May | 10 Jun 2026 | Known |
CVE-2026-48027 | Nx Nx Console | Nx Console Embedded Malicious Code | 27 May | 10 Jun 2026 | Known |
CVE-2026-8398 | Daemon Daemon Tools Lite | Daemon Tools Lite Embedded Malicious Code | 27 May | 30 May 2026 | |
CVE-2026-48172 | LiteSpeed cPanel Plugin | Privilege Escalation | 26 May | 29 May 2026 | |
CVE-2026-9082 | Drupal Core | SQL Injection | 22 May | 27 May 2026 | |
CVE-2025-34291 | Langflow Langflow | Langflow Origin Validation Error | 21 May | 4 Jun 2026 | |
CVE-2026-34926 | Trend Micro Apex One | (On-Premise) Directory Traversal | 21 May | 4 Jun 2026 | |
CVE-2008-4250 | Microsoft Windows | Buffer Overflow | 20 May | 3 Jun 2026 | |
CVE-2009-1537 | Microsoft DirectX | NULL Byte Overwrite | 20 May | 3 Jun 2026 | |
CVE-2009-3459 | Adobe Acrobat and Reader | Heap-Based Buffer Overflow | 20 May | 3 Jun 2026 | |
CVE-2010-0249 | Microsoft Internet Explorer | Use-After-Free | 20 May | 3 Jun 2026 | |
CVE-2010-0806 | Microsoft Internet Explorer | Use-After-Free | 20 May | 3 Jun 2026 | |
CVE-2026-41091 | Microsoft Defender | Link Following | 20 May | 3 Jun 2026 | |
CVE-2026-45498 | Microsoft Defender | Denial of Service | 20 May | 3 Jun 2026 | |
CVE-2026-42897 | Microsoft Microsoft | Microsoft Exchange Server Cross-Site Scripting | 15 May | 29 May 2026 | |
CVE-2026-20182 | Cisco Catalyst SD-WAN | Controller Authentication Bypass | 14 May | 17 May 2026 | |
CVE-2026-42208 | BerriAI LiteLLM | SQL Injection | 8 May | 11 May 2026 | |
CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | Improper Input Validation | 7 May | 10 May 2026 | |
CVE-2026-0300 | Palo Alto Networks PAN-OS | Out-of-bounds Write | 6 May | 9 May 2026 | |
CVE-2026-31431 | Linux Kernel | Incorrect Resource Transfer Between Spheres | 1 May | 15 May 2026 |
All 117 fixes
Show the full list, with a filter
| CVE | Product | What | Severity | CVSS |
|---|---|---|---|---|
CVE-2026-42898 | Microsoft Dynamics 365 (on-premises) | Microsoft Dynamics 365 On-Premises Remote Code Execution | Critical | 9.9 |
CVE-2026-41089 | Windows Netlogon | Windows Netlogon Remote Code Execution | Critical | 9.8 |
CVE-2026-41096 | Microsoft Windows DNS | Windows DNS Client Remote Code Execution | Critical | 9.8 |
CVE-2026-40402 | Windows Hyper-V | Windows Hyper-V Elevation of Privilege | Critical | 9.3 |
CVE-2026-41103 | Microsoft SSO Plugin for Jira & Confluence | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege | Critical | 9.1 |
CVE-2026-40365 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Critical | 8.8 |
CVE-2026-40403 | Windows Win32K – GRFX | Windows Graphics Component Remote Code Execution | Critical | 8.8 |
CVE-2026-40358 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-40361 | Microsoft Office | Microsoft Outlook and Word Remote Code Execution | Critical | 8.4 |
CVE-2026-40363 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 8.4 |
CVE-2026-40364 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 8.4 |
CVE-2026-40366 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 8.4 |
CVE-2026-40367 | Microsoft Office Word | Microsoft Word Remote Code Execution | Critical | 8.4 |
CVE-2026-35421 | Windows GDI | Windows GDI Remote Code Execution | Critical | 7.8 |
CVE-2026-42831 | Microsoft Office | Microsoft Office Remote Code Execution | Critical | 7.8 |
CVE-2026-32161 | Windows Native WiFi Miniport Driver | Windows Native WiFi Miniport Driver Remote Code Execution | Critical | 7.5 |
CVE-2026-42823 | Azure Logic Apps | Azure Logic Apps Elevation of Privilege | Important | 9.9 |
CVE-2026-33117 | Azure SDK | Azure SDK for Java Security Feature Bypass | Important | 9.1 |
CVE-2026-42833 | Microsoft Dynamics 365 (on-premises) | Microsoft Dynamics 365 On-Premises Remote Code Execution | Important | 9.1 |
CVE-2026-33110 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-33112 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-34329 | Windows Message Queuing | Microsoft Message Queuing (MSMQ) Remote Code Execution | Important | 8.8 |
CVE-2026-35436 | Microsoft Office Click-To-Run | Microsoft Office Click-To-Run Elevation of Privilege | Important | 8.8 |
CVE-2026-35439 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-40357 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.8 |
CVE-2026-40370 | SQL Server | SQL Server Remote Code Execution | Important | 8.8 |
CVE-2026-40420 | Microsoft Office Click-To-Run | Microsoft Office Click-To-Run Elevation of Privilege | Important | 8.8 |
CVE-2026-41086 | Windows Admin Center | Windows Admin Center in Azure Portal Elevation of Privilege | Important | 8.8 |
CVE-2026-41094 | Microsoft Data Formulator | Microsoft Data Formulator Remote Code Execution | Important | 8.8 |
CVE-2026-41613 | Visual Studio Code | Visual Studio Code Elevation of Privilege | Important | 8.8 |
CVE-2026-35438 | Windows Admin Center | Windows Admin Center Elevation of Privilege | Important | 8.3 |
CVE-2026-33833 | Azure Machine Learning | Azure Machine Learning Notebook Spoofing | Important | 8.2 |
CVE-2026-40415 | Windows TCP/IP | Windows TCP/IP Remote Code Execution | Important | 8.1 |
CVE-2026-34332 | Windows Kernel-Mode Drivers | Windows Kernel-Mode Driver Remote Code Execution | Important | 8.0 |
CVE-2026-40368 | Microsoft Office SharePoint | Microsoft SharePoint Server Remote Code Execution | Important | 8.0 |
CVE-2026-32204 | Azure Monitor Agent | Azure Monitor Agent Elevation of Privilege | Important | 7.8 |
CVE-2026-33834 | Windows Event Logging Service | Windows Event Logging Service Elevation of Privilege | Important | 7.8 |
CVE-2026-33835 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-33837 | Windows TCP/IP | Windows TCP/IP Local Elevation of Privilege | Important | 7.8 |
CVE-2026-33838 | Windows Message Queuing | Windows Message Queuing (MSMQ) Elevation of Privilege | Important | 7.8 |
CVE-2026-33840 | Windows Win32K – ICOMP | Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-33841 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-34330 | Windows Win32K – GRFX | Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-34333 | Windows Win32K – GRFX | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-34334 | Windows TCP/IP | Windows TCP/IP Elevation of Privilege | Important | 7.8 |
CVE-2026-34336 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-34337 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-34338 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.8 |
CVE-2026-34343 | Windows Application Identity (AppID) Subsystem | Windows Application Identity (AppID) Subsystem Elevation of Privilege | Important | 7.8 |
CVE-2026-34344 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-34351 | Windows TCP/IP | Windows TCP/IP Elevation of Privilege | Important | 7.8 |
CVE-2026-35415 | Windows Storage Spaces Controller | Windows Storage Spaces Controller Elevation of Privilege | Important | 7.8 |
CVE-2026-35417 | Windows Win32K – ICOMP | Windows Win32k Elevation of Privilege | Important | 7.8 |
CVE-2026-35418 | Windows Cloud Files Mini Filter Driver | Windows Cloud Files Mini Filter Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-35420 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-40359 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-40360 | Microsoft Office Excel | Microsoft Excel Information Disclosure | Important | 7.8 |
CVE-2026-40362 | Microsoft Office Excel | Microsoft Excel Remote Code Execution | Important | 7.8 |
CVE-2026-40369 | Windows Kernel | Windows Kernel Elevation of Privilege | Important | 7.8 |
CVE-2026-40377 | Windows Cryptographic Services | Microsoft Cryptographic Services Elevation of Privilege | Important | 7.8 |
CVE-2026-40381 | Azure Connected Machine Agent | Azure Connected Machine Agent Elevation of Privilege | Important | 7.8 |
CVE-2026-40382 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.8 |
CVE-2026-40397 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-40398 | Windows Remote Desktop | Windows Remote Desktop Services Elevation of Privilege | Important | 7.8 |
CVE-2026-40399 | Windows TCP/IP | Windows TCP/IP Elevation of Privilege | Important | 7.8 |
CVE-2026-40407 | Windows Common Log File System Driver | Windows Common Log File System Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-40408 | Windows Kernel-Mode Drivers | Windows WAN ARP Driver Elevation of Privilege | Important | 7.8 |
CVE-2026-40417 | Dynamics Business Central | Microsoft Dynamics 365 Business Central Elevation of Privilege | Important | 7.8 |
CVE-2026-40418 | Microsoft Office Click-To-Run | Microsoft Office Click-To-Run Elevation of Privilege | Important | 7.8 |
CVE-2026-40419 | Microsoft Office | Microsoft Office Click-To-Run Elevation of Privilege | Important | 7.8 |
CVE-2026-41088 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.8 |
CVE-2026-41095 | Data Deduplication | Data Deduplication Elevation of Privilege | Important | 7.8 |
CVE-2026-41611 | Visual Studio Code | Visual Studio Code Remote Code Execution | Important | 7.8 |
CVE-2026-42896 | Windows DWM Core Library | Windows DWM Core Library Elevation of Privilege | Important | 7.8 |
CVE-2026-42832 | Microsoft Office | Microsoft Office Spoofing | Important | 7.7 |
CVE-2026-35424 | Windows Internet Key Exchange (IKE) Protocol | Internet Key Exchange (IKE) Protocol Denial of Service | Important | 7.5 |
CVE-2026-40405 | Windows TCP/IP | Windows TCP/IP Denial of Service | Important | 7.5 |
CVE-2026-40406 | Windows TCP/IP | Windows TCP/IP Information Disclosure | Important | 7.5 |
CVE-2026-42899 | ASP.NET Core | ASP.NET Core Denial of Service | Important | 7.5 |
CVE-2026-40413 | Windows TCP/IP | Windows TCP/IP Denial of Service | Important | 7.4 |
CVE-2026-40414 | Windows TCP/IP | Windows TCP/IP Denial of Service | Important | 7.4 |
CVE-2026-42893 | M365 Copilot | Microsoft Outlook for iOS Tampering | Important | 7.4 |
CVE-2026-32177 | .NET | .NET Elevation of Privilege | Important | 7.3 |
CVE-2026-35433 | .NET | .NET Elevation of Privilege | Important | 7.3 |
CVE-2026-40401 | Windows TCP/IP | Windows TCP/IP Denial of Service | Important | 7.1 |
CVE-2026-41101 | Microsoft Office Word | Microsoft Word for Android Spoofing | Important | 7.1 |
CVE-2026-41102 | Microsoft Office PowerPoint | Microsoft PowerPoint for Android Spoofing | Important | 7.1 |
CVE-2026-33839 | Windows Win32K – GRFX | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-34331 | Windows Win32K – GRFX | Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-34340 | Windows Projected File System | Windows Projected File System Elevation of Privilege | Important | 7.0 |
CVE-2026-34341 | Windows Link-Layer Discovery Protocol (LLDP) | Windows Link-Layer Discovery Protocol (LLDP) Elevation of Privilege | Important | 7.0 |
CVE-2026-34342 | Windows Print Spooler Components | Windows Print Spooler Elevation of Privilege | Important | 7.0 |
CVE-2026-34345 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-34347 | Windows Win32K – GRFX | Windows Win32k Elevation of Privilege | Important | 7.0 |
CVE-2026-35416 | Windows Ancillary Function Driver for WinSock | Windows Ancillary Function Driver for WinSock Elevation of Privilege | Important | 7.0 |
CVE-2026-40410 | Windows SMB Client | Windows SMB Client Elevation of Privilege | Important | 7.0 |
CVE-2026-42825 | Windows Telephony Service | Windows Telephony Service Elevation of Privilege | Important | 7.0 |
CVE-2026-21530 | Windows Rich Text Edit | Windows Rich Text Edit Elevation of Privilege | Important | 6.7 |
CVE-2026-32170 | Windows Rich Text Edit Control | Windows Rich Text Edit Elevation of Privilege | Important | 6.7 |
CVE-2026-41097 | Windows Secure Boot | Secure Boot Security Feature Bypass | Important | 6.7 |
CVE-2026-34350 | Windows Storport Miniport Driver | Windows Storport Miniport Driver Denial of Service | Important | 6.5 |
CVE-2026-35422 | Windows TCP/IP | Windows TCP/IP Driver Security Feature Bypass | Important | 6.5 |
CVE-2026-40374 | Power Automate | Microsoft Power Automate Desktop Information Disclosure | Important | 6.5 |
CVE-2026-42830 | Azure Monitor Agent | Azure Monitor Agent Metrics Extension Elevation of Privilege | Important | 6.5 |
CVE-2026-41610 | Visual Studio Code | Visual Studio Code Security Feature Bypass | Important | 6.3 |
CVE-2026-40380 | Windows Volume Manager Extension Driver | Windows Volume Manager Extension Driver Remote Code Execution | Important | 6.2 |
CVE-2026-41614 | M365 Copilot for Desktop | M365 Copilot for Desktop Spoofing | Important | 6.2 |
CVE-2026-32185 | Microsoft Teams | Microsoft Teams Spoofing | Important | 5.5 |
CVE-2026-34339 | Windows LDAP – Lightweight Directory Access Protocol | Windows Lightweight Directory Access Protocol (LDAP) Denial of Service | Important | 5.5 |
CVE-2026-35419 | Windows DWM Core Library | Windows DWM Core Library Information Disclosure | Important | 5.5 |
CVE-2026-35440 | Microsoft Office Word | Microsoft Word Information Disclosure | Important | 5.5 |
CVE-2026-41612 | Visual Studio Code | Visual Studio Code Information Disclosure | Important | 5.5 |
CVE-2026-35423 | Telnet Client | Windows 11 Telnet Client Information Disclosure | Important | 5.4 |
CVE-2026-32209 | Windows Filtering Platform (WFP) | Windows Filtering Platform (WFP) Security Feature Bypass | Important | 4.4 |
CVE-2026-41100 | M365 Copilot | Microsoft 365 Copilot for Android Spoofing | Important | 4.4 |
CVE-2026-32175 | .NET | .NET Core Tampering | Important | 4.3 |
CVE-2026-40421 | Microsoft Office Word | Microsoft Word Information Disclosure | Important | 4.3 |
Published later in the month (44)
Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.
| Date | CVE | What | Severity | Action |
|---|---|---|---|---|
| 21 May | CVE-2026-23652 | Microsoft Power Pages Remote Code Execution | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure | Critical | Fixed by Microsoft |
| 18 May | CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege | Critical | Update |
| 7 May | CVE-2026-42826 | Azure DevOps Information Disclosure | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-47280 | Azure Resource Manager Elevation of Privilege | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-33109 | Azure Managed Instance for Apache Cassandra Remote Code Execution | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-40411 | Azure Virtual Network Gateway Remote Code Execution | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-33823 | Microsoft Team Events Portal Information Disclosure | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-35428 | Azure Cloud Shell Spoofing | Critical | Fixed by Microsoft |
| 14 May | CVE-2026-41615 | Microsoft Authenticator Information Disclosure | Critical | Update |
| 7 May | CVE-2026-40379 | Azure Entra ID Spoofing | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-41090 | Microsoft Copilot Tampering | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-33843 | Microsoft Azure Active Directory B2C Elevation of Privilege | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-33844 | Azure Managed Instance for Apache Cassandra Remote Code Execution | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-32207 | Azure Machine Learning Notebook Spoofing | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-35430 | Azure Privileged Identity Management (PIM) Elevation of Privilege | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-35435 | Azure AI Foundry Elevation of Privilege | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-34327 | Microsoft Partner Center Spoofing | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-41105 | Azure Monitor Action Group Notification System Elevation of Privilege | Critical | Fixed by Microsoft |
| 14 May | CVE-2026-42897 | Microsoft Exchange Server Spoofing | Critical | Update |
| 19 May | CVE-2026-45584 | Microsoft Defender Remote Code Execution | Critical | Update |
| 21 May | CVE-2026-26147 | Azure Stack HCI Information Disclosure | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-33821 | Microsoft Dynamics 365 Customer Insights Elevation of Privilege | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-23663 | Microsoft Global Secure Access (GSA) Information Disclosure | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-26129 | M365 Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-26164 | M365 Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 7 May | CVE-2026-33111 | Copilot Chat (Microsoft Edge) Information Disclosure | Critical | Fixed by Microsoft |
| 21 May | CVE-2026-42827 | M365 Copilot Information Disclosure | Critical | Fixed by Microsoft |
| 15 May | CVE-2026-45495 | Microsoft Edge (Chromium-based) Remote Code Execution | Important | Update |
| 21 May | CVE-2026-45659 | Microsoft SharePoint Remote Code Execution | Important | Update |
| 29 May | CVE-2026-47294 | Microsoft SharePoint Server Remote Code Execution | Important | Update |
| 19 May | CVE-2026-41091 | Microsoft Defender Elevation of Privilege | Important | Update |
| 19 May | CVE-2026-42834 | Windows Admin Center in Azure Portal Elevation of Privilege | Important | Update |
| 19 May | CVE-2026-45585 | Windows BitLocker Security Feature Bypass | Important | Update |
| 11 May | CVE-2026-41107 | Microsoft Edge (Chromium-based) Information Disclosure | Moderate | Update |
| 11 May | CVE-2026-42891 | Microsoft Edge (Chromium-based) for Android Spoofing | Moderate | Update |
| 11 May | CVE-2026-42838 | Microsoft Edge (Chromium-based) Elevation of Privilege | Moderate | Update |
| 15 May | CVE-2026-45492 | Microsoft Edge (Chromium-based) Security Feature Bypass | Moderate | Update |
| 15 May | CVE-2026-45494 | Microsoft Edge (Chromium-based) Spoofing | Moderate | Update |
| 11 May | CVE-2026-35429 | Microsoft Edge (Chromium-based) for Android Spoofing | Moderate | Update |
| 11 May | CVE-2026-40416 | Microsoft Edge (Chromium-based) for Android Spoofing | Low | Update |
| 19 May | CVE-2026-45498 | Microsoft Defender Denial of Service | Low | Update |
From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 2 weeks ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.