Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityidentity-authentication-vulnerabilityinternet-facing-service-vulnerability

Microsoft Fixes 137 Flaws Led by Netlogon, DNS Client, and Dynamics 365 RCEs

Updated 1mo agoFirst seen May 12, 202646 sources

Microsoft released fixes for 137 vulnerabilities across Windows, Azure, Microsoft 365, developer tools, and AI-related products, with no zero-days reported as exploited in the wild. The most urgent issues included a wormable pre-auth remote code execution flaw in Windows Netlogon (CVE-2026-41089), an unauthenticated RCE in the Windows DNS Client (CVE-2026-41096) that can be triggered through crafted DNS responses, and a remote code execution bug in Microsoft Dynamics 365 on-premises (CVE-2026-42898). Microsoft also patched an authenticated SharePoint Server RCE (CVE-2026-40365), multiple Microsoft Word Preview Pane RCEs, and a critical authentication bypass in the Microsoft SSO Plugin for Jira & Confluence (CVE-2026-41103).

The release was notable for its severity, with reports citing 16 to 30 critical vulnerabilities depending on classification, and 14 flaws scoring 9.0 or higher, including an Azure DevOps information disclosure issue rated CVSS 10.0 that Microsoft said had already been fully mitigated. Elevation-of-privilege bugs made up the largest share of fixes, spanning the Windows kernel, Win32k, TCP/IP, SMB Client, Print Spooler, and other core components; two locally exploitable issues, including Windows Print Spooler (CVE-2026-34342) and Windows Message Queueing (CVE-2026-33838), were publicly disclosed alongside patches. Microsoft said its AI-driven bug-finding system MDASH identified 16 of the vulnerabilities, and it separately warned enterprises to complete Secure Boot certificate updates before June 26, 2026, while noting a BitLocker Recovery issue on some Windows Server 2025 systems with an unrecommended Group Policy setting.

Share:
Microsoft Fixes 137 Flaws Led by Netlogon, DNS Client, and Dynamics 365 RCEs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
May 13, 20261mo ago

Microsoft says MDASH found 16 May Patch Tuesday vulnerabilities

Microsoft disclosed that its AI-based MDASH bug-hunting system identified 16 of the vulnerabilities included in the May 2026 Patch Tuesday release.

Microsoft warns enterprises to update Secure Boot certificates by June 26

In conjunction with the May 2026 Patch Tuesday guidance, Microsoft reminded organizations of a deadline to apply Secure Boot certificate updates by June 26, 2026, and also noted a BitLocker Recovery issue affecting some Windows Server 2025 systems with an unrecommended Group Policy setting.

Microsoft highlights critical wormable and unauthenticated RCE risks

Coverage of the May 2026 release identified the most urgent patched issues as a wormable Windows Netlogon RCE affecting domain controllers, an unauthenticated Windows DNS Client RCE, and a Dynamics 365 on-premises RCE.

May 12, 20261mo ago

Public disclosure issued for Windows Print Spooler LPE

ZDI publicly disclosed CVE-2026-34342 on the same day Microsoft released a patch, describing a race condition in splwow64.exe that could let a low-privileged attacker escalate privileges.

Public disclosure issued for Windows Message Queueing LPE

ZDI publicly disclosed CVE-2026-33838 on the same day Microsoft released a fix, describing a double-free flaw in the mqac.sys driver that could lead to kernel-level code execution from low privileges.

Microsoft fully mitigates Azure DevOps information disclosure flaw

As part of the May 2026 release, Microsoft said it had already fully mitigated a CVSS 10.0 Azure DevOps information disclosure vulnerability before or at disclosure time.

Microsoft releases May 2026 Patch Tuesday updates

Microsoft issued its May 2026 Patch Tuesday security updates, fixing 137 vulnerabilities across Windows, Office, Azure, developer tools, AI products, and server components. Microsoft said no zero-days were publicly disclosed before release or known to be exploited in the wild.

May 11, 20261mo ago

Microsoft publishes Edge vulnerability advisories ahead of Patch Tuesday

Microsoft posted Security Update Guide entries for several Edge and Edge for Android issues, including CVE-2026-41107, CVE-2026-42891, CVE-2026-42838, and CVE-2026-35429.

May 7, 20262mo ago

Microsoft publishes advisory for Dynamics 365 Customer Insights flaw

Microsoft's Security Update Guide published CVE-2026-33821, an elevation of privilege vulnerability in Microsoft Dynamics 365 Customer Insights, ahead of the broader May Patch Tuesday release.

Jan 12, 20265mo ago

ZDI reports Windows Print Spooler LPE to Microsoft

Researcher Marcin Wiazowski reported CVE-2026-34342, a Windows Print Spooler local privilege escalation vulnerability, to Microsoft through ZDI.

Jan 8, 20266mo ago

ZDI reports Windows Message Queueing LPE to Microsoft

Zero Day Initiative reported CVE-2026-33838, a local privilege escalation flaw in Microsoft Windows Message Queueing, to Microsoft for coordinated disclosure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

44 LINKEDOpen in app
Affected products
10 linked
FortigateNetAzure DevopsAsp.Net CoreWindows Server 2025Visual Studio CodeAzure Machine LearningFortiosBitlockerForticlient Ems
Organizations
9 linked
Microsoft CorporationLinkedinXGoogleThe RegisterAtlassianAnthropicAction1Fortinet
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Fixes 137 Flaws Led by Netlogon, DNS Client, and Dynamics 365 RCEs | Mallory