top of page

Security Bulletin

Public·5 members

George SuttonGeorge Sutton
George Sutton

Patch Tuesday Special: May 2026

May 13th, 2026


Overview:

Microsoft’s May 12, 2026 Patch Tuesday addresses 137 CVE's, with no actively exploited or publicly disclosed zero-days. This month includes 30 Critical vulnerabilities, including multiple vulnerabilities presenting a high risk of remote code execution (RCE), local code execution (LCE), escalation of privilege (EoP), and VM escape. Several vulnerabilities require low or no user interaction required.


Vulnerability Category Breakdown:

• Elevation of Privilege (EoP): ~61 vulnerabilities (~48–51%)

• Remote Code Execution (RCE): ~31 vulnerabilities (~25–26%)

• Information Disclosure: ~14 vulnerabilities (~12%)

• Spoofing: ~13 vulnerabilities (~11%)

• Denial of Service (DoS): ~8 vulnerabilities

• Security Feature Bypass: ~6 vulnerabilities 


Top 5:

1) CVE-2026-41089: Windows Netlogon Remote Code Execution

  • Why it matters: This is a Critical CVSS 9.8 RCE affecting Windows Netlogon. Rapid7 notes that no privileges or user interaction are required, and successful exploitation could execute code as SYSTEM on a domain controller.

  • Affected systems: Windows Server systems acting as domain controllers, with patches available for Windows Server 2012 and later.

  • Pivotalogic Priority Rating: 💥SHUT IT DOWN - Patch ASAP, especially all domain controllers.


2) CVE-2026-41096: Windows DNS Client Remote Code Execution

  • Why it matters: This is a Critical CVSS 9.8 RCE in the Windows DNS Client. A specially crafted DNS response from an attacker-controlled DNS server could corrupt memory and potentially allow remote code execution.

  • Affected systems: Windows clients and servers using the Windows DNS Client.

  • Pivotalogic Priority Rating: 💥SHUT IT DOWN - Patch ASAP, prioritizing endpoints and servers that rely on external or untrusted DNS paths.


3) CVE-2026-41103: Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege

  • Why it matters: This Critical CVSS 9.1 flaw affects the Microsoft SSO Plugin for Jira and Confluence. Tenable reports Microsoft assessed exploitation as “Exploitation More Likely,” and successful exploitation could allow an attacker to sign in using a forged identity without Microsoft Entra ID authentication.

  • Affected systems: Self-hosted Jira and Confluence environments using the Microsoft Entra ID / SSO plugin.

  • Pivotalogic Priority Rating: 💥SHUT IT DOWN - Patch ASAP,  where the plugin is deployed.


4) CVE-2026-40361, CVE-2026-40364, CVE-2026-40366 & CVE-2026-40367: Microsoft Word Remote Code Execution

  • Why it matters: These are Critical Microsoft Word RCEs. Tenable notes that Microsoft’s Preview Pane is an attack vector, meaning malicious documents could pose risk even before a user fully opens them.

  • Affected systems: Microsoft Word / Office installations on user endpoints, shared workstations, terminal servers, and systems that process external documents.

  • Pivotalogic Priority Rating: 💥SHUT IT DOWN - Patch ASAP, Patch applicable systems immediately, especially users who frequently receive external attachments


5) CVE-2026-40365: Microsoft SharePoint Server Remote Code Execution

  • Why it matters: This Critical SharePoint RCE allows an authenticated attacker with at least Site Owner permissions to inject and remotely execute code on a SharePoint Server. Even though authentication is required, SharePoint is high-value infrastructure and often contains sensitive business data.

  • Affected systems: Microsoft SharePoint Server environments.

  • Pivotalogic Priority Rating: 💥SHUT IT DOWN - Patch ASAP, especially internet-accessible or high-value SharePoint deployments.


Pivotalogic Priority Rating Scale: 

💥SHUT IT DOWN (not literally) = Critical

🚨Yikes! = High

⚠️Welp. = Medium

💡Eh = Low

Full Microsoft Release Notes HERE

33 Views
bottom of page