Claude is having a major outage. Status board · Discuss Claude

Patch Tuesday: May 2026

Each month's Microsoft security updates: what to patch first, the Critical fixes, and what CISA says attackers are exploiting.

How to use it Start with "Patch these first" for the fixes attackers are already using. Then filter the list by product or keyword, or tick "Critical only" to narrow it down.

Next Patch Tuesday: Tue 13 Oct 2026 (in 3 days)

May 2026 Patch Tuesday: Microsoft fixed 117 vulnerabilities, 16 of them Critical. None was known to be exploited on the day. Released Tue 12 May 2026.

  • 117vulnerabilities fixed
  • 16Critical
  • 0exploited before the fix
  • 0publicly disclosed
  • 0now on CISA KEV

By type: 58 elevation of privilege, 29 remote code execution, 8 information disclosure, 8 denial of service, 7 spoofing, 5 security feature bypass, 2 tampering.

Update problems? Ask in Patch Tuesday & Updates. From October 2026 a “what broke for you?” thread opens there at 1 pm Eastern every Patch Tuesday.

Patch these first

Nothing this month was known to be exploited or public when it was fixed, and none of it is on CISA’s list yet. Patch in your normal cycle, Critical first.

Critical (16)

Microsoft’s top rating: usually code execution with little or no user action.

CVEWhatImpactCVSS
CVE-2026-42898Microsoft Dynamics 365 On-Premises Remote Code ExecutionRemote Code Execution9.9
CVE-2026-41089Windows Netlogon Remote Code ExecutionRemote Code Execution9.8
CVE-2026-41096Windows DNS Client Remote Code ExecutionRemote Code Execution9.8
CVE-2026-40402Windows Hyper-V Elevation of PrivilegeElevation of Privilege9.3
CVE-2026-41103Microsoft SSO Plugin for Jira & Confluence Elevation of PrivilegeElevation of Privilege9.1
CVE-2026-40365Microsoft SharePoint Server Remote Code ExecutionRemote Code Execution8.8
CVE-2026-40403Windows Graphics Component Remote Code ExecutionRemote Code Execution8.8
CVE-2026-40358Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-40361Microsoft Outlook and Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-40363Microsoft Office Remote Code ExecutionRemote Code Execution8.4
CVE-2026-40364Microsoft Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-40366Microsoft Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-40367Microsoft Word Remote Code ExecutionRemote Code Execution8.4
CVE-2026-35421Windows GDI Remote Code ExecutionRemote Code Execution7.8
CVE-2026-42831Microsoft Office Remote Code ExecutionRemote Code Execution7.8
CVE-2026-32161Windows Native WiFi Miniport Driver Remote Code ExecutionRemote Code Execution7.5

Added to CISA KEV in May 2026 (21)

Every vendor, not only Microsoft. CISA adds a vulnerability when it has evidence attackers are using it. US federal agencies must fix it by the deadline shown; for everyone else, it is the best free “patch this now” list there is.

CVEVendor and productWhatAddedFederal deadlineRansomware
CVE-2026-0257Palo Alto Networks PAN-OSAuthentication Bypass29 May1 Jun 2026Known
CVE-2026-45321TanStack TanStackTanStack Unspecified27 May10 Jun 2026Known
CVE-2026-48027Nx Nx ConsoleNx Console Embedded Malicious Code27 May10 Jun 2026Known
CVE-2026-8398Daemon Daemon Tools LiteDaemon Tools Lite Embedded Malicious Code27 May30 May 2026
CVE-2026-48172LiteSpeed cPanel PluginPrivilege Escalation26 May29 May 2026
CVE-2026-9082Drupal CoreSQL Injection22 May27 May 2026
CVE-2025-34291Langflow LangflowLangflow Origin Validation Error21 May4 Jun 2026
CVE-2026-34926Trend Micro Apex One(On-Premise) Directory Traversal21 May4 Jun 2026
CVE-2008-4250Microsoft WindowsBuffer Overflow20 May3 Jun 2026
CVE-2009-1537Microsoft DirectXNULL Byte Overwrite20 May3 Jun 2026
CVE-2009-3459Adobe Acrobat and ReaderHeap-Based Buffer Overflow20 May3 Jun 2026
CVE-2010-0249Microsoft Internet ExplorerUse-After-Free20 May3 Jun 2026
CVE-2010-0806Microsoft Internet ExplorerUse-After-Free20 May3 Jun 2026
CVE-2026-41091Microsoft DefenderLink Following20 May3 Jun 2026
CVE-2026-45498Microsoft DefenderDenial of Service20 May3 Jun 2026
CVE-2026-42897Microsoft MicrosoftMicrosoft Exchange Server Cross-Site Scripting15 May29 May 2026
CVE-2026-20182Cisco Catalyst SD-WANController Authentication Bypass14 May17 May 2026
CVE-2026-42208BerriAI LiteLLMSQL Injection8 May11 May 2026
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM)Improper Input Validation7 May10 May 2026
CVE-2026-0300Palo Alto Networks PAN-OSOut-of-bounds Write6 May9 May 2026
CVE-2026-31431Linux KernelIncorrect Resource Transfer Between Spheres1 May15 May 2026

All 117 fixes

Show the full list, with a filter
CVEProductWhatSeverityCVSS
CVE-2026-42898Microsoft Dynamics 365 (on-premises)Microsoft Dynamics 365 On-Premises Remote Code ExecutionCritical9.9
CVE-2026-41089Windows NetlogonWindows Netlogon Remote Code ExecutionCritical9.8
CVE-2026-41096Microsoft Windows DNSWindows DNS Client Remote Code ExecutionCritical9.8
CVE-2026-40402Windows Hyper-VWindows Hyper-V Elevation of PrivilegeCritical9.3
CVE-2026-41103Microsoft SSO Plugin for Jira & ConfluenceMicrosoft SSO Plugin for Jira & Confluence Elevation of PrivilegeCritical9.1
CVE-2026-40365Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionCritical8.8
CVE-2026-40403Windows Win32K – GRFXWindows Graphics Component Remote Code ExecutionCritical8.8
CVE-2026-40358Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-40361Microsoft OfficeMicrosoft Outlook and Word Remote Code ExecutionCritical8.4
CVE-2026-40363Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical8.4
CVE-2026-40364Microsoft Office WordMicrosoft Word Remote Code ExecutionCritical8.4
CVE-2026-40366Microsoft Office WordMicrosoft Word Remote Code ExecutionCritical8.4
CVE-2026-40367Microsoft Office WordMicrosoft Word Remote Code ExecutionCritical8.4
CVE-2026-35421Windows GDIWindows GDI Remote Code ExecutionCritical7.8
CVE-2026-42831Microsoft OfficeMicrosoft Office Remote Code ExecutionCritical7.8
CVE-2026-32161Windows Native WiFi Miniport DriverWindows Native WiFi Miniport Driver Remote Code ExecutionCritical7.5
CVE-2026-42823Azure Logic AppsAzure Logic Apps Elevation of PrivilegeImportant9.9
CVE-2026-33117Azure SDKAzure SDK for Java Security Feature BypassImportant9.1
CVE-2026-42833Microsoft Dynamics 365 (on-premises)Microsoft Dynamics 365 On-Premises Remote Code ExecutionImportant9.1
CVE-2026-33110Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.8
CVE-2026-33112Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.8
CVE-2026-34329Windows Message QueuingMicrosoft Message Queuing (MSMQ) Remote Code ExecutionImportant8.8
CVE-2026-35436Microsoft Office Click-To-RunMicrosoft Office Click-To-Run Elevation of PrivilegeImportant8.8
CVE-2026-35439Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.8
CVE-2026-40357Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.8
CVE-2026-40370SQL ServerSQL Server Remote Code ExecutionImportant8.8
CVE-2026-40420Microsoft Office Click-To-RunMicrosoft Office Click-To-Run Elevation of PrivilegeImportant8.8
CVE-2026-41086Windows Admin CenterWindows Admin Center in Azure Portal Elevation of PrivilegeImportant8.8
CVE-2026-41094Microsoft Data FormulatorMicrosoft Data Formulator Remote Code ExecutionImportant8.8
CVE-2026-41613Visual Studio CodeVisual Studio Code Elevation of PrivilegeImportant8.8
CVE-2026-35438Windows Admin CenterWindows Admin Center Elevation of PrivilegeImportant8.3
CVE-2026-33833Azure Machine LearningAzure Machine Learning Notebook SpoofingImportant8.2
CVE-2026-40415Windows TCP/IPWindows TCP/IP Remote Code ExecutionImportant8.1
CVE-2026-34332Windows Kernel-Mode DriversWindows Kernel-Mode Driver Remote Code ExecutionImportant8.0
CVE-2026-40368Microsoft Office SharePointMicrosoft SharePoint Server Remote Code ExecutionImportant8.0
CVE-2026-32204Azure Monitor AgentAzure Monitor Agent Elevation of PrivilegeImportant7.8
CVE-2026-33834Windows Event Logging ServiceWindows Event Logging Service Elevation of PrivilegeImportant7.8
CVE-2026-33835Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2026-33837Windows TCP/IPWindows TCP/IP Local Elevation of PrivilegeImportant7.8
CVE-2026-33838Windows Message QueuingWindows Message Queuing (MSMQ) Elevation of PrivilegeImportant7.8
CVE-2026-33840Windows Win32K – ICOMPWin32k Elevation of PrivilegeImportant7.8
CVE-2026-33841Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-34330Windows Win32K – GRFXWin32k Elevation of PrivilegeImportant7.8
CVE-2026-34333Windows Win32K – GRFXWindows Win32k Elevation of PrivilegeImportant7.8
CVE-2026-34334Windows TCP/IPWindows TCP/IP Elevation of PrivilegeImportant7.8
CVE-2026-34336Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-34337Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2026-34338Windows Telephony ServiceWindows Telephony Service Elevation of PrivilegeImportant7.8
CVE-2026-34343Windows Application Identity (AppID) SubsystemWindows Application Identity (AppID) Subsystem Elevation of PrivilegeImportant7.8
CVE-2026-34344Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-34351Windows TCP/IPWindows TCP/IP Elevation of PrivilegeImportant7.8
CVE-2026-35415Windows Storage Spaces ControllerWindows Storage Spaces Controller Elevation of PrivilegeImportant7.8
CVE-2026-35417Windows Win32K – ICOMPWindows Win32k Elevation of PrivilegeImportant7.8
CVE-2026-35418Windows Cloud Files Mini Filter DriverWindows Cloud Files Mini Filter Driver Elevation of PrivilegeImportant7.8
CVE-2026-35420Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-40359Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-40360Microsoft Office ExcelMicrosoft Excel Information DisclosureImportant7.8
CVE-2026-40362Microsoft Office ExcelMicrosoft Excel Remote Code ExecutionImportant7.8
CVE-2026-40369Windows KernelWindows Kernel Elevation of PrivilegeImportant7.8
CVE-2026-40377Windows Cryptographic ServicesMicrosoft Cryptographic Services Elevation of PrivilegeImportant7.8
CVE-2026-40381Azure Connected Machine AgentAzure Connected Machine Agent Elevation of PrivilegeImportant7.8
CVE-2026-40382Windows Telephony ServiceWindows Telephony Service Elevation of PrivilegeImportant7.8
CVE-2026-40397Windows Common Log File System DriverWindows Common Log File System Driver Elevation of PrivilegeImportant7.8
CVE-2026-40398Windows Remote DesktopWindows Remote Desktop Services Elevation of PrivilegeImportant7.8
CVE-2026-40399Windows TCP/IPWindows TCP/IP Elevation of PrivilegeImportant7.8
CVE-2026-40407Windows Common Log File System DriverWindows Common Log File System Driver Elevation of PrivilegeImportant7.8
CVE-2026-40408Windows Kernel-Mode DriversWindows WAN ARP Driver Elevation of PrivilegeImportant7.8
CVE-2026-40417Dynamics Business CentralMicrosoft Dynamics 365 Business Central Elevation of PrivilegeImportant7.8
CVE-2026-40418Microsoft Office Click-To-RunMicrosoft Office Click-To-Run Elevation of PrivilegeImportant7.8
CVE-2026-40419Microsoft OfficeMicrosoft Office Click-To-Run Elevation of PrivilegeImportant7.8
CVE-2026-41088Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.8
CVE-2026-41095Data DeduplicationData Deduplication Elevation of PrivilegeImportant7.8
CVE-2026-41611Visual Studio CodeVisual Studio Code Remote Code ExecutionImportant7.8
CVE-2026-42896Windows DWM Core LibraryWindows DWM Core Library Elevation of PrivilegeImportant7.8
CVE-2026-42832Microsoft OfficeMicrosoft Office SpoofingImportant7.7
CVE-2026-35424Windows Internet Key Exchange (IKE) ProtocolInternet Key Exchange (IKE) Protocol Denial of ServiceImportant7.5
CVE-2026-40405Windows TCP/IPWindows TCP/IP Denial of ServiceImportant7.5
CVE-2026-40406Windows TCP/IPWindows TCP/IP Information DisclosureImportant7.5
CVE-2026-42899ASP.NET CoreASP.NET Core Denial of ServiceImportant7.5
CVE-2026-40413Windows TCP/IPWindows TCP/IP Denial of ServiceImportant7.4
CVE-2026-40414Windows TCP/IPWindows TCP/IP Denial of ServiceImportant7.4
CVE-2026-42893M365 CopilotMicrosoft Outlook for iOS TamperingImportant7.4
CVE-2026-32177.NET.NET Elevation of PrivilegeImportant7.3
CVE-2026-35433.NET.NET Elevation of PrivilegeImportant7.3
CVE-2026-40401Windows TCP/IPWindows TCP/IP Denial of ServiceImportant7.1
CVE-2026-41101Microsoft Office WordMicrosoft Word for Android SpoofingImportant7.1
CVE-2026-41102Microsoft Office PowerPointMicrosoft PowerPoint for Android SpoofingImportant7.1
CVE-2026-33839Windows Win32K – GRFXWin32k Elevation of PrivilegeImportant7.0
CVE-2026-34331Windows Win32K – GRFXWin32k Elevation of PrivilegeImportant7.0
CVE-2026-34340Windows Projected File SystemWindows Projected File System Elevation of PrivilegeImportant7.0
CVE-2026-34341Windows Link-Layer Discovery Protocol (LLDP)Windows Link-Layer Discovery Protocol (LLDP) Elevation of PrivilegeImportant7.0
CVE-2026-34342Windows Print Spooler ComponentsWindows Print Spooler Elevation of PrivilegeImportant7.0
CVE-2026-34345Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-34347Windows Win32K – GRFXWindows Win32k Elevation of PrivilegeImportant7.0
CVE-2026-35416Windows Ancillary Function Driver for WinSockWindows Ancillary Function Driver for WinSock Elevation of PrivilegeImportant7.0
CVE-2026-40410Windows SMB ClientWindows SMB Client Elevation of PrivilegeImportant7.0
CVE-2026-42825Windows Telephony ServiceWindows Telephony Service Elevation of PrivilegeImportant7.0
CVE-2026-21530Windows Rich Text EditWindows Rich Text Edit Elevation of PrivilegeImportant6.7
CVE-2026-32170Windows Rich Text Edit ControlWindows Rich Text Edit Elevation of PrivilegeImportant6.7
CVE-2026-41097Windows Secure BootSecure Boot Security Feature BypassImportant6.7
CVE-2026-34350Windows Storport Miniport DriverWindows Storport Miniport Driver Denial of ServiceImportant6.5
CVE-2026-35422Windows TCP/IPWindows TCP/IP Driver Security Feature BypassImportant6.5
CVE-2026-40374Power AutomateMicrosoft Power Automate Desktop Information DisclosureImportant6.5
CVE-2026-42830Azure Monitor AgentAzure Monitor Agent Metrics Extension Elevation of PrivilegeImportant6.5
CVE-2026-41610Visual Studio CodeVisual Studio Code Security Feature BypassImportant6.3
CVE-2026-40380Windows Volume Manager Extension DriverWindows Volume Manager Extension Driver Remote Code ExecutionImportant6.2
CVE-2026-41614M365 Copilot for DesktopM365 Copilot for Desktop SpoofingImportant6.2
CVE-2026-32185Microsoft TeamsMicrosoft Teams SpoofingImportant5.5
CVE-2026-34339Windows LDAP – Lightweight Directory Access ProtocolWindows Lightweight Directory Access Protocol (LDAP) Denial of ServiceImportant5.5
CVE-2026-35419Windows DWM Core LibraryWindows DWM Core Library Information DisclosureImportant5.5
CVE-2026-35440Microsoft Office WordMicrosoft Word Information DisclosureImportant5.5
CVE-2026-41612Visual Studio CodeVisual Studio Code Information DisclosureImportant5.5
CVE-2026-35423Telnet ClientWindows 11 Telnet Client Information DisclosureImportant5.4
CVE-2026-32209Windows Filtering Platform (WFP)Windows Filtering Platform (WFP) Security Feature BypassImportant4.4
CVE-2026-41100M365 CopilotMicrosoft 365 Copilot for Android SpoofingImportant4.4
CVE-2026-32175.NET.NET Core TamperingImportant4.3
CVE-2026-40421Microsoft Office WordMicrosoft Word Information DisclosureImportant4.3

Published later in the month (44)

Microsoft Edge updates, out-of-band fixes and cloud services. “Fixed by Microsoft” means a cloud service Microsoft has already patched: there is nothing to install.

DateCVEWhatSeverityAction
21 MayCVE-2026-23652Microsoft Power Pages Remote Code ExecutionCriticalFixed by Microsoft
21 MayCVE-2026-40412Azure Orbital Spatio Remote Code ExecutionCriticalFixed by Microsoft
21 MayCVE-2026-41104Microsoft Planetary Computer Pro Information DisclosureCriticalFixed by Microsoft
18 MayCVE-2026-42822Azure Local Disconnected Operations (ALDO) Elevation of PrivilegeCriticalUpdate
7 MayCVE-2026-42826Azure DevOps Information DisclosureCriticalFixed by Microsoft
21 MayCVE-2026-42901Microsoft Entra ID Elevation of PrivilegeCriticalFixed by Microsoft
21 MayCVE-2026-47280Azure Resource Manager Elevation of PrivilegeCriticalFixed by Microsoft
7 MayCVE-2026-33109Azure Managed Instance for Apache Cassandra Remote Code ExecutionCriticalFixed by Microsoft
21 MayCVE-2026-40411Azure Virtual Network Gateway Remote Code ExecutionCriticalFixed by Microsoft
7 MayCVE-2026-33823Microsoft Team Events Portal Information DisclosureCriticalFixed by Microsoft
7 MayCVE-2026-35428Azure Cloud Shell SpoofingCriticalFixed by Microsoft
14 MayCVE-2026-41615Microsoft Authenticator Information DisclosureCriticalUpdate
7 MayCVE-2026-40379Azure Entra ID SpoofingCriticalFixed by Microsoft
21 MayCVE-2026-41090Microsoft Copilot TamperingCriticalFixed by Microsoft
21 MayCVE-2026-33843Microsoft Azure Active Directory B2C Elevation of PrivilegeCriticalFixed by Microsoft
7 MayCVE-2026-33844Azure Managed Instance for Apache Cassandra Remote Code ExecutionCriticalFixed by Microsoft
7 MayCVE-2026-32207Azure Machine Learning Notebook SpoofingCriticalFixed by Microsoft
21 MayCVE-2026-35430Azure Privileged Identity Management (PIM) Elevation of PrivilegeCriticalFixed by Microsoft
7 MayCVE-2026-35435Azure AI Foundry Elevation of PrivilegeCriticalFixed by Microsoft
7 MayCVE-2026-34327Microsoft Partner Center SpoofingCriticalFixed by Microsoft
7 MayCVE-2026-41105Azure Monitor Action Group Notification System Elevation of PrivilegeCriticalFixed by Microsoft
14 MayCVE-2026-42897Microsoft Exchange Server SpoofingCriticalUpdate
19 MayCVE-2026-45584Microsoft Defender Remote Code ExecutionCriticalUpdate
21 MayCVE-2026-26147Azure Stack HCI Information DisclosureCriticalFixed by Microsoft
7 MayCVE-2026-33821Microsoft Dynamics 365 Customer Insights Elevation of PrivilegeCriticalFixed by Microsoft
21 MayCVE-2026-23663Microsoft Global Secure Access (GSA) Information DisclosureCriticalFixed by Microsoft
7 MayCVE-2026-26129M365 Copilot Information DisclosureCriticalFixed by Microsoft
7 MayCVE-2026-26164M365 Copilot Information DisclosureCriticalFixed by Microsoft
7 MayCVE-2026-33111Copilot Chat (Microsoft Edge) Information DisclosureCriticalFixed by Microsoft
21 MayCVE-2026-42827M365 Copilot Information DisclosureCriticalFixed by Microsoft
15 MayCVE-2026-45495Microsoft Edge (Chromium-based) Remote Code ExecutionImportantUpdate
21 MayCVE-2026-45659Microsoft SharePoint Remote Code ExecutionImportantUpdate
29 MayCVE-2026-47294Microsoft SharePoint Server Remote Code ExecutionImportantUpdate
19 MayCVE-2026-41091Microsoft Defender Elevation of PrivilegeImportantUpdate
19 MayCVE-2026-42834Windows Admin Center in Azure Portal Elevation of PrivilegeImportantUpdate
19 MayCVE-2026-45585Windows BitLocker Security Feature BypassImportantUpdate
11 MayCVE-2026-41107Microsoft Edge (Chromium-based) Information DisclosureModerateUpdate
11 MayCVE-2026-42891Microsoft Edge (Chromium-based) for Android SpoofingModerateUpdate
11 MayCVE-2026-42838Microsoft Edge (Chromium-based) Elevation of PrivilegeModerateUpdate
15 MayCVE-2026-45492Microsoft Edge (Chromium-based) Security Feature BypassModerateUpdate
15 MayCVE-2026-45494Microsoft Edge (Chromium-based) SpoofingModerateUpdate
11 MayCVE-2026-35429Microsoft Edge (Chromium-based) for Android SpoofingModerateUpdate
11 MayCVE-2026-40416Microsoft Edge (Chromium-based) for Android SpoofingLowUpdate
19 MayCVE-2026-45498Microsoft Defender Denial of ServiceLowUpdate

From Microsoft’s Security Update Guide and CISA’s Known Exploited Vulnerabilities catalog, checked 2 weeks ago. Only vulnerabilities Microsoft itself issued are counted; Chromium fixes that Edge inherits are left out. For known problems with the updates themselves, see Windows release health.

← All tools