CVE-2024-41975, CVE-2025-15467, CVE-2025-2595, CVE-2025-41659, CVE-2025-41691, CVE-2025-4676, CVE-2026-0481, CVE-2026-20794, CVE-2026-26289, CVE-2026-33109, CVE-2026-33570, CVE-2026-33844, CVE-2026-35421, CVE-2026-35504, CVE-2026-35555, CVE-2026-40361, CVE-2026-40364, CVE-2026-40365, CVE-2026-41089, CVE-2026-41096, CVE-2026-41103, CVE-2026-42823, CVE-2026-42826, CVE-2026-42898, CVE-2026-45185
IP Addresses:
127.0.0.1
Get tomorrow's brief in your inbox
May 13, 2026
Today: Microsoft ships 137 patches with no zero-days for the first time in two years, but three critical flaws demand immediate attention: CVE-2026-41089 in Windows Netlogon allows unauthenticated remote code execution on domain controllers, CVE-2026-41096 in the Windows DNS Client enables RCE without authentication, and CVE-2026-42898 in Dynamics 365 exposes CRM systems to code injection. Meanwhile, a critical use-after-free vulnerability in Exim mail servers (CVE-2026-45185) threatens code execution on GnuTLS builds, and supply chain attacks hit both npm and RubyGems package repositories with hundreds of malicious packages targeting developers.
Microsoft Windows Netlogon RCE (CVE-2026-41089)
A stack-based buffer overflow in Windows Netlogon (CVSS 9.8) allows unauthenticated remote attackers to execute code on domain controllers without user interaction. An attacker can send a specially crafted network request to a Windows server acting as a domain controller, causing the Netlogon service to improperly handle the request and execute malicious code without requiring any prior access or credentials. A compromised domain controller means a compromised domain.
Microsoft Windows DNS Client RCE (CVE-2026-41096)
A heap-based buffer overflow in the Windows DNS Client (CVSS 9.8) enables unauthenticated remote code execution without user interaction. An attacker controlling a DNS server or positioned to intercept DNS responses could send a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory, potentially enabling RCE. The Windows DNS Client runs on virtually all Windows workstations and servers, creating enormous attack surface. Practical exploitation requires the attacker to be in a position to influence DNS responses through DNS spoofing, a rogue DNS server, or a machine-in-the-middle position on the network.
Exim Mail Server Use-After-Free (CVE-2026-45185)
A critical use-after-free vulnerability in Exim mail servers (all versions 4.97 through 4.99.2) enables memory corruption and potential code execution when a TLS connection is handled by GnuTLS. The vulnerability is triggered during BDAT message body handling when a client sends a TLS close_notify alert before the body transfer is complete, followed by a final byte in cleartext on the same TCP connection. This sequence causes Exim to write into a memory buffer that has already been freed during TLS session teardown, leading to heap corruption. The vulnerability only affects builds using USE_GNUTLS=yes; OpenSSL builds are not impacted. Federico Kirschbaum from XBOW discovered the flaw and describes it as "one of the highest-caliber bugs" discovered in Exim to date.
exim -bV | grep GnuTLS and prioritize those systems. OpenSSL builds are not affected but should still be updated to the latest version.Microsoft Entra ID Credential Bypass (CVE-2026-41103)
A critical elevation of privilege vulnerability allows an unauthorized attacker to impersonate an existing user by presenting forged credentials, bypassing Entra ID (formerly Azure AD) authentication. Microsoft assesses exploitation as more likely. The vulnerability affects the Microsoft SSO Plugin for Jira and Confluence, making it particularly dangerous given ongoing supply chain attacks targeting development and CI/CD tools.
Foxconn Confirms Ransomware Attack, Nitrogen Gang Claims Data Theft
Foxconn confirmed a ransomware attack that disrupted North American factory operations earlier this month after workers leaked internal messages on social media. The Nitrogen ransomware group claimed the attack Tuesday, alleging theft of 8TB of data including confidential projects and chip drawings for Apple, Google, and NVIDIA orders. The company operates major manufacturing facilities for Apple iPhone and iPad production, plus contract manufacturing for numerous tech companies.
Instructure Pays Ransom to Restore Canvas Platform
EdTech company Instructure paid hackers who took down its Canvas student management platform, restoring service over the weekend after nearly 9,000 universities, schools, and school districts lost access during end-of-year exams. The company emailed schools about the payment before restoration. Payment amount is unknown, but the company's name was removed from the attackers' leak site. The House Homeland Security Committee has summoned Instructure leadership to a meeting, and there is a concerted effort to track the group via blockchain payments.
Supply Chain Attack on npm TanStack Packages
A cache-poisoning attack compromised TanStack framework packages on npm, spreading to over 400 npm libraries within hours. The attack originated from the TanStack framework's packages and targeted developers, not npm staff. The incident happened simultaneously with a separate attack on RubyGems but involved different tactics and targets.
RubyGems Disables Sign-Ups After Staff-Targeted Attack
The RubyGems package repository disabled new user sign-ups after a malicious attack Monday targeted its engineers and staff. Hundreds of malicious packages were published Monday and again Tuesday, containing code aimed at RubyGems developers through cross-site scripting attacks designed to steal data from their systems. The attack is unrelated to the simultaneous npm TanStack supply chain attack. Details remain unclear on what the attackers tried to steal from RubyGems staff. RubyGems also reported a DDoS attack, though this may be terminology confusion referring to the flood of malicious packages rather than an actual distributed denial-of-service attack.
bundle audit for known vulnerabilities. Check developer workstations for XSS payloads or data exfiltration. Monitor RubyGems security team updates at rubygems.org/pages/security.Best Western International Data Breach
Best Western International is notifying guests of a security breach affecting its reservation systems. A hacker had access to reservation systems for over six months between October 2025 and April 2026. The company operates several hotel brands including Best Western, Sure Hotels, and WorldHotels.
UK Water Utility Fined for 2-Year Breach Detection Failure
The UK Information Commissioner's Office fined South Staffordshire Water nearly £1 million for failing to detect hackers in its network for almost two years. The extended dwell time allowed attackers prolonged access to water utility systems and customer data.
Microsoft Office Word Preview Pane RCE Vulnerabilities
Two Microsoft Office Word vulnerabilities (CVE-2026-40361 and CVE-2026-40364, both CVSS 8.4) allow remote code execution through the preview pane without user interaction. CVE-2026-40361 is a memory-related vulnerability enabling remote code execution locally. CVE-2026-40364 is a type-confusion bug stemming from incorrect memory handling. An attacker can trigger both flaws by simply sending a maliciously crafted document; Outlook's reading pane can execute the code without the user ever opening the file.
Microsoft Dynamics 365 Code Injection (CVE-2026-42898)
A critical code injection vulnerability (CVSS 9.9) in Microsoft Dynamics 365 On-Premises allows any authenticated remote attacker to execute arbitrary code over a network with no user interaction required. An attacker could modify the saved state of a process session in Dynamics CRM and trigger the system to process that data, causing the server to execute malicious code. While Microsoft categorizes the flaw as unlikely to be exploited, the lack of privilege requirements and zero user interaction makes it extremely dangerous. Compromise of Dynamics 365 infrastructure can expose customer records, operational workflows, financial information, and integrated business systems. Since CRM environments often connect with identity services, databases, and enterprise applications, successful exploitation could lead to broader organizational compromise.
Windows GDI RCE via Malicious EMF Files (CVE-2026-35421)
A heap-based buffer overflow in Windows GDI (CVSS 8.8) allows unauthorized attackers to execute code locally by exploiting a vulnerability triggered when a user opens or processes a specially crafted Enhanced Metafile (EMF) file using Microsoft Paint. The vulnerability requires user action (opening the file) but could be chained with social engineering or delivered via email attachments.
Microsoft SharePoint RCE (CVE-2026-40365)
A critical vulnerability in Microsoft SharePoint Server allows an authenticated attacker (at least Site Owner role) to write and execute arbitrary code remotely on the SharePoint Server. The insufficient granularity of access control enables privileged users to inject and execute code in network-based attacks.
Azure Critical Vulnerabilities Remediated by Microsoft
Three critical vulnerabilities affecting Azure services (CVE-2026-33109, CVE-2026-33844, CVE-2026-42823, and CVE-2026-42826) with CVSS scores up to 10.0 have been proactively remediated by Microsoft within cloud infrastructure without requiring customer action. CVE-2026-42826 (CVSS 10.0) is a critical information disclosure vulnerability in Azure DevOps allowing unauthenticated remote attackers to disclose sensitive information. CVE-2026-33109 (CVSS 9.9) and CVE-2026-33844 (CVSS 9.0) are RCE vulnerabilities in Azure Managed Instance for Apache Cassandra. CVE-2026-42823 (CVSS 9.9) is an elevation of privilege vulnerability in Azure Logic Apps.
Windows 11 May 2026 Updates
Microsoft released Windows 11 KB5089549 and KB5087420 cumulative updates for versions 25H2/24H2 and 23H2, containing May 2026 Patch Tuesday security patches for 120 vulnerabilities. Updates are mandatory and can be installed via Windows Update or downloaded from Microsoft Update Catalog. After installation, Windows 11 25H2/24H2 will be build 26200.8457/26100.8457, and 23H2 will be 22631.7079. New features include Xbox mode on desktop, expanded File Explorer archive format support (uu, cpio, xar, NuGet packages), improved haptic feedback for compatible input devices, and enhanced batch file security controls for administrators.
Windows 10 Extended Security Update (KB5087544)
Microsoft released Windows 10 KB5087544 extended security update fixing May 2026 Patch Tuesday vulnerabilities and resolving an issue with Remote Desktop security warnings. Available for Windows 10 Enterprise LTSC and ESU program enrollees. After installation, Windows 10 updates to build 19045.7291 and Windows 10 Enterprise LTSC 2021 to 19044.7291. The update fixes Remote Desktop Connection security warning dialog rendering incorrectly in multi-monitor configurations with different display scaling settings and enables dynamic Secure Boot status reporting in Windows Security App.
AI-Driven Vulnerability Discovery Accelerating Patch Volumes
Microsoft's May 2026 Patch Tuesday is the first in nearly two years with no actively exploited zero-days or previously disclosed flaws. However, the company disclosed 137 CVEs (13 critical), marking the third month this year with over 100 CVEs. Through May, Microsoft has patched over 500 CVEs, on pace to surpass the annual record of 1,245 bugs disclosed in 2020. Microsoft's VP of Engineering Tom Gallagher stated that large releases will soon be the norm, with AI helping researchers uncover more vulnerabilities than before. "Advanced AI models are part of the discovery picture and help to accelerate it. They enable us to reason about code paths and configurations at a speed and consistency that would not be possible through manual review alone." Multiple tech giants including Apple, Mozilla, Oracle, and Google participated in Anthropic's "Project Glasswing," an AI capability that has proven effective at unearthing security vulnerabilities in code. Apple fixed 52 vulnerabilities in iOS 15 (up from an average of 20), Mozilla resolved 271 vulnerabilities in Firefox 150, Oracle addressed 450 flaws including 300+ remotely exploitable unauthenticated flaws, and Google fixed 127 Chrome vulnerabilities (up from 30 the previous month). Oracle switched to monthly updates for critical security issues in response to Glasswing findings.
CISA Releases SBOM Guidance for AI Systems
CISA and G7 international partners (Germany, Canada, France, Italy, Japan, United Kingdom, and European Union) released joint guidance, "Software Bill of Materials for AI - Minimum Elements," to help public and private sector stakeholders improve transparency in AI systems and supply chains. The guidance builds on CISA's previous SBOM work and provides recommendations on minimum elements for AI system SBOMs. Because AI systems are software systems, these recommendations supplement general SBOM minimum elements. The supplemental elements reflect G7 expert consensus and will expand over time to keep pace with AI technology advancement.
Intel and AMD Chipmaker Vulnerabilities
Intel and AMD released over two dozen advisories addressing 70 vulnerabilities across their product portfolios. Intel published 13 advisories describing 24 security defects (1 critical, 8 high-severity). The critical bug CVE-2026-20794 (CVSS 9.3) is a buffer overflow in Data Center Graphics Driver for VMware ESXi enabling privilege escalation and potentially code execution. Intel also addressed high-severity vulnerabilities in Vision software, Endpoint Management Assistant (EMA), UEFI firmware, and QuickAssist Technology (QAT) drivers. AMD published 15 advisories covering 45 vulnerabilities (1 critical, 24 high-severity). The critical bug CVE-2026-0481 (CVSS 9.2) affects AMD Device Metrics Exporter (ROCm ecosystem), which exposes port 50061 on all network interfaces by default, allowing unauthenticated users to access the GPU-Agent gRPC server and perform unauthorized GPU configuration changes.
ABB Industrial Control System Vulnerabilities
CISA published multiple advisories for ABB product vulnerabilities. ABB AC500 V3 PLC firmware versions below 3.9.0 are affected by three vulnerabilities enabling forced browsing to bypass user management (CVE-2025-2595), certificate and key read/write access via CODESYS protocol (CVE-2025-41659), and denial-of-service via null pointer dereference (CVE-2025-41691). ABB AC500 V3 PM5xxx firmware 3.9.0 and 3.9.0_HF1 are affected by a critical stack buffer overflow (CVE-2025-15467, CVSS 9.8) in CMS message parsing that can cause crash, DoS, or potentially RCE. ABB Automation Builder Gateway for Windows versions below 2.9.0 are affected by CVE-2024-41975, which exposes the gateway on all network adapters by default on port 1217, enabling unauthenticated attackers to scan for PLCs. ABB WebPro SNMP Card PowerValue versions 1.1.8.k and earlier are affected by three vulnerabilities including authentication bypass via single-character validation (CVE-2025-4676).
Siemens, Schneider Electric, and ICS Vendors Publish Patch Tuesday Advisories
Siemens published 18 new security advisories, several describing critical vulnerabilities. Critical issues include device takeover in Sentron 7KT PAC1261 Data Manager, XSS in Simatic S7 PLC web server, command execution as root in Ruggedcom Rox, arbitrary file access in ROS#, over 300 third-party component flaws in Simatic CN4100, and missing authentication in Opcenter RDnL. Siemens informed customers that Ruggedcom APE1808 is affected by the recently disclosed Palo Alto Networks PAN-OS vulnerability exploited in the wild. Schneider Electric published four advisories addressing high-severity vulnerabilities in EcoStruxure Panel Server (sensitive information exposure), EasyLogic T150 and Saitel DP RTU (unauthorized file access), and EasyLogic, PowerLogic, Easergy, and EcoStruxure products (session hijacking). CISA also released advisories for Subnet Solutions PowerSYSTEM Center vulnerabilities (CVE-2026-35555, CVE-2026-26289, CVE-2026-33570, CVE-2026-35504) enabling information disclosure and CRLF injection.
May 2026 Patch Tuesday marks a significant milestone as the first Microsoft release in nearly two years without actively exploited zero-days, but the volume of vulnerabilities continues to escalate driven by AI-assisted discovery. With 137 flaws patched this month and over 500 year-to-date, Microsoft is on track to surpass its 2020 record of 1,245 annual CVEs. The trend extends beyond Microsoft: AI-driven vulnerability discovery through initiatives like Anthropic's Project Glasswing is forcing every major vendor to increase patch velocity. Apple, Mozilla, Oracle, and Google have all shipped dramatically larger security updates in recent months, with Oracle switching to monthly critical security releases. Simultaneously, supply chain attacks on software development ecosystems continue to intensify. The simultaneous npm TanStack cache-poisoning attack and RubyGems staff-targeted campaign demonstrate attackers' focus on developer toolchains as force multipliers. Defenders face a dual challenge: accelerating patch deployment cycles to keep pace with AI-discovered vulnerabilities while hardening development pipelines against supply chain compromise. The three critical Windows vulnerabilities (Netlogon, DNS Client, Entra ID bypass) plus the Exim mail server flaw demand immediate attention, as each provides threat actors with high-value attack paths requiring minimal prerequisites.