# Microsoft's Massive May Patch Day: 138 Vulnerabilities and Critical Flaws in DNS, Netlogon, and Azure Services


Microsoft released security patches for 138 vulnerabilities across its product ecosystem in its May 2026 Patch Tuesday update. While the company reported no signs of active exploitation at the time of disclosure, the breadth of the update—including 30 Critical-severity flaws and numerous 9.x-scored vulnerabilities across core Windows services and cloud platforms—underscores the expanding attack surface enterprises face as they manage hybrid infrastructure.


## The Threat


The May update addresses a diverse vulnerability landscape spanning traditional Windows security services, Azure cloud infrastructure, and third-party integrations. Two of the most immediately concerning flaws affect Windows DNS and Netlogon services—foundational components relied upon by virtually every enterprise domain environment.


CVE-2026-41096 (CVSS 9.8) is a heap-based buffer overflow in Windows DNS that allows unauthenticated remote code execution. An attacker crafting a malicious DNS response and directing it to a vulnerable system can corrupt memory and execute arbitrary code without authentication. In typical network configurations where DNS requests traverse trust boundaries, this creates a direct attack vector from an external attacker to internal systems. CVE-2026-41089 (CVSS 9.8) parallels this risk in Windows Netlogon, where a stack-based buffer overflow allows unauthenticated RCE against domain controllers. Since Netlogon is the authentication backbone of Active Directory forests, a compromise of this service could grant attackers lateral movement across an entire enterprise.


Beyond Windows core services, the update reflects mounting pressure on Microsoft's cloud platforms. Azure services including Logic Apps, Entra ID (formerly Azure AD), Cassandra Managed Instance, and Cloud Shell collectively received multiple high-severity flaws related to improper access control, information disclosure, and authentication bypass. Azure DevOps was patched for a 10.0 CVSS information disclosure vulnerability. Organizations running hybrid or cloud-native architectures now face the challenge of coordinating patches across systems spanning on-premises Active Directory, cloud-hosted databases, and SaaS application integrations.


Notably, the update also includes a fix for CVE-2025-54518 (CVSS 7.3), an AMD CPU vulnerability related to improper cache isolation on Zen 2-based processors that could enable privilege escalation. This cross-vendor issue highlights how modern attack chains increasingly transcend individual software vendors, requiring coordination across multiple supply layers.


## Severity and Impact


| CVE ID | CVSS Score | Vulnerability Type | Attack Vector | Attack Complexity | Requires Authentication | Impact |

|--------|----------|-------------------|----------------|-------------------|------------------------|--------|

| CVE-2026-41096 | 9.8 | Heap Buffer Overflow | Network | Low | No | Remote Code Execution |

| CVE-2026-42826 | 10.0 | Information Disclosure | Network | Low | No | Sensitive Data Exposure (Azure DevOps) |

| CVE-2026-33109 | 9.9 | Improper Access Control | Network | Low | Yes | Remote Code Execution (Azure Cassandra) |

| CVE-2026-42898 | 9.9 | Code Injection | Network | Low | Yes | Remote Code Execution (Dynamics 365) |

| CVE-2026-42823 | 9.9 | Improper Access Control | Network | Low | Yes | Privilege Escalation (Azure Logic Apps) |

| CVE-2026-41089 | 9.8 | Stack Buffer Overflow | Network | Low | No | Remote Code Execution (Windows Netlogon) |

| CVE-2026-33823 | 9.6 | Improper Authorization | Network | Low | Yes | Information Disclosure (Teams) |

| CVE-2026-35428 | 9.6 | Command Injection | Network | Low | No | Spoofing (Azure Cloud Shell) |

| CVE-2026-40379 | 9.3 | Information Disclosure | Network | Low | No | Spoofing (Azure Entra ID) |

| CVE-2026-40402 | 9.3 | Use-After-Free | Network | Low | No | Privilege Escalation (Hyper-V) |

| CVE-2026-41103 | 9.1 | Authentication Bypass | Network | Low | No | Unauthorized Access (SSO Plugin) |

| CVE-2025-54518 | 7.3 | Microarchitectural Flaw | Local | Low | No | Privilege Escalation (AMD Zen 2) |


Breakdown of 138 Total Vulnerabilities:

  • 30 Critical | 104 Important | 3 Moderate | 1 Low
  • 61 Privilege Escalation | 32 Remote Code Execution | 15 Information Disclosure | 14 Spoofing | 8 Denial of Service | 6 Security Feature Bypass | 2 Tampering

  • ## Affected Products


    Windows Operating System and Services

  • Windows DNS Client
  • Windows Netlogon
  • Windows Hyper-V
  • Windows Server (all supported versions)

  • Microsoft 365 and Cloud Services

  • Azure DevOps
  • Azure Managed Instance for Apache Cassandra
  • Azure Logic Apps
  • Azure Entra ID
  • Azure Cloud Shell
  • Microsoft Teams
  • Microsoft Dynamics 365 (on-premises)
  • Microsoft Edge (via Chromium patches from Google)

  • Third-Party Integrations

  • Microsoft SSO Plugin for Jira and Confluence

  • Additional Updates

  • Chromium-based vulnerabilities (127 flaws addressed in Edge)
  • AMD CPU firmware (CVE-2025-54518)

  • ## Mitigations


    Immediate Actions (48-72 hours)


    Organizations should prioritize patching in this order:

    1. Windows DNS and Netlogon: These affect domain controller stability and AD authentication. Deploy to domain controllers first, followed by member servers and workstations.

    2. Azure cloud services: If using Azure DevOps, Logic Apps, Cassandra, or Entra ID, apply patches immediately. Many Azure services auto-patch, but verify deployment status in your subscription.

    3. Hyper-V hosts: If running virtualized infrastructure, patch hosts to prevent guest-to-host privilege escalation.


    Interim Network Controls


  • Segment DNS traffic: Restrict DNS requests to known, trusted resolvers. Monitor for unexpected DNS traffic patterns.
  • Restrict Netlogon access: Limit Netlogon traffic (ports 445, 135) to authorized domain controllers and forest trust relationships.
  • Multi-factor authentication: Strengthen authentication for Azure and Microsoft 365 services, especially those affected by CVE-2026-41103 (SSO bypass).
  • Monitor privilege escalation attempts: Increase logging on systems patching CVE-2026-42823 and CVE-2026-40402 to detect exploitation attempts.

  • Longer-Term Hardening


  • Test patches in a staging environment before broad deployment to avoid production disruption.
  • Implement application whitelisting on critical systems to limit damage from RCE exploits.
  • Review cloud RBAC policies (especially Azure) to ensure least-privilege access.
  • For organizations running hybrid infrastructure, coordinate patch schedules across on-premises and cloud components.

  • ## References


  • [Microsoft Security Update Guide — May 2026](https://portal.msrc.microsoft.com/)
  • [CVE-2026-41096 — Windows DNS Heap Buffer Overflow](https://nvd.nist.gov/)
  • [CVE-2026-41089 — Windows Netlogon Stack Buffer Overflow](https://nvd.nist.gov/)
  • [Azure Security Updates — May 2026](https://docs.microsoft.com/en-us/azure/security/)
  • [AMD Security Bulletin — CVE-2025-54518](https://www.amd.com/en/corporate/security)

  • ---


    ## HackWire Analysis


    May's Patch Tuesday reflects a troubling trend: Microsoft's attack surface is expanding faster than its ability to reduce it. The presence of 9.8-9.9 CVSS flaws in foundational services like DNS and Netlogon suggests that core security assumptions—that Windows services are relatively hardened due to their prevalence as attack targets—are eroding. An unauthenticated attacker can now push malformed DNS packets across a network boundary to trigger RCE on any Windows system. This isn't a bug in a niche feature; this is a flaw in infrastructure that enterprises depend on hourly.


    The concentration of high-severity flaws in Azure services (DevOps, Entra ID, Logic Apps, Cloud Shell) also signals a broader challenge: as organizations migrate to hybrid and cloud-first architectures, patching becomes a coordination nightmare. A flaw in Azure Entra ID can silently expose your on-premises Active Directory integration. A bug in Cloud Shell could grant shell access to attackers. Yet these patches often don't get the same urgency as Windows updates, leaving hybrid deployments vulnerable.


    What's particularly striking is the absence of zero-day exploitation. Microsoft's statement that none of these flaws were publicly known or under active attack at disclosure is somewhat reassuring—but also suspicious. High-CVSS flaws in DNS and Netlogon are exactly the kinds of vulnerabilities sophisticated attackers would weaponize. The lack of prior disclosure might simply mean the exploits haven't been detected yet, or that attacks are being conducted selectively against high-value targets. Organizations should assume these flaws are being actively exploited within weeks of patch release.


    The cross-vendor nature of this update (AMD, Google Chromium, Microsoft) also hints at a broader ecosystem problem: no single company's security is sufficient. Defenders need visibility across all three layers—firmware, OS, and applications—to reduce risk effectively. This month's Patch Tuesday reinforces an uncomfortable truth: comprehensive security patching is now a multi-vendor, multi-layer, multi-team operational challenge, not a single Tuesday ritual.


    — *HackWire Editorial*


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)