Microsoft faces Exchange attacks, Defender flaws, and a new BitLocker bypass after May Patch Tuesday

news
Microsoft faces Exchange attacks, Defender flaws, and a new BitLocker bypass after May Patch Tuesday

Microsoft’s May security cycle has become more serious than it first appeared. Patch Tuesday did not include a major zero day fix, but several issues have emerged since then, including active attacks on Exchange Server, three Defender vulnerabilities, a BitLocker bypass proof of concept, and security problems involving Edge and Microsoft Authenticator.

The most urgent issue is a critical Exchange Server spoofing vulnerability tracked as CVE 2026 42897. It affects Exchange Server 2016, 2019, and Subscription Edition, and attackers are already exploiting it in the wild. Microsoft has not released a full patch yet, which means organizations have to rely on mitigation steps for now. The Exchange Emergency Mitigation service can help reduce risk if it is enabled, and Microsoft has also shared guidance for admins who need to shrink the attack surface.

Some fixes are already available, but Exchange still needs close attention

The BitLocker issue is also important, especially for laptops and other devices that may be physically accessible. A researcher known as Nightmare Eclipse has published a proof of concept exploit called YellowKey. It can bypass BitLocker protection on a PC if the attacker has physical access and the device uses TPM only mode without a PIN. Microsoft has listed the vulnerability as CVE 2026 45585 and rated it high risk. Updates are available for Windows 11 and Windows Server 2025.

Product or featureIssueCurrent status
Exchange ServerCritical spoofing flaw being exploitedNo full patch yet, mitigations available
BitLockerYellowKey bypass with physical accessWindows 11 and Server 2025 updates released
Microsoft DefenderThree flaws affecting malware protectionFixed in newer engine versions
Microsoft EdgePasswords handled too openly in memoryChanged in version 148.0.3967.70
Microsoft AuthenticatorSensitive information disclosureFixed versions released

Microsoft Defender also needed urgent fixes. Three vulnerabilities affect Microsoft’s Malware Protection Engine up to version 1.1.26030.3008. One flaw, CVE 2026 41091, has public exploit code and can give attackers system privileges. Another flaw, CVE 2026 45498, can be used for denial of service and is already being exploited. A third issue, CVE 2026 45584, is a remote code execution flaw, although it is not currently known to be exploited. Microsoft says all three are fixed in engine version 1.1.26040.8 and later.

For home users, the Defender fix should arrive through automatic daily security intelligence updates. Still, it is worth checking manually. Open Windows Settings, go to Privacy and security, then Windows Security, then Virus and threat protection, and check the About section under settings. The engine version should be 1.1.26040.8 or newer.

Microsoft has also adjusted how Edge handles saved passwords. Earlier reports showed that Edge loaded saved passwords into memory in plaintext so they could be used quickly. Since Edge version 148.0.3967.70, released on May 15, Microsoft has made the browser handle passwords more carefully. Edge for Android reached the same version on May 21.

Microsoft Authenticator also had a critical vulnerability, CVE 2026 41615, affecting its Android and iOS apps. The flaw could allow attackers to access sensitive information using the permissions of the signed in user. Microsoft has released fixed versions of the apps.

The next scheduled Patch Tuesday is June 9, 2026, but organizations should not wait until then for the problems that already have fixes or mitigations. Exchange admins should review Microsoft’s mitigation guidance immediately, Windows users should confirm Defender has updated, and BitLocker users relying on TPM only protection should consider adding a PIN where possible.

Discover: News

Discussion (0)

Be the first to comment.