Microsoft’s May Patch Tuesday fixes 120 security flaws across Windows and Office

news
Microsoft’s May Patch Tuesday fixes 120 security flaws across Windows and Office

Microsoft has released its May Patch Tuesday updates, fixing 120 security vulnerabilities across Windows, Office, and several cloud services.

None of the flaws are currently known to be exploited in the wild, but the update is still important. Microsoft rates 30 of the vulnerabilities as critical, while the rest are listed as high risk.

That is a larger than usual Patch Tuesday total. One possible reason is timing. The Pwn2Own hacking competition begins in Berlin on May 14, and Microsoft may have wanted to patch as much as possible before researchers publicly demonstrate new attacks.

The next Patch Tuesday is scheduled for June 9, 2026.

Here is the main breakdown:

Product areaFixed vulnerabilities
Windows66
Microsoft Office27
Microsoft Edge3 Edge specific fixes, plus Chromium fixes
Total Patch Tuesday fixes120
Critical vulnerabilities30

Windows received the largest number of fixes, with 66 vulnerabilities patched across Windows 10, Windows 11, and Windows Server. Windows 10 support officially ended in October 2025, but systems enrolled in Microsoft’s Extended Security Updates program still receive patches.

Five of the Windows flaws are critical remote code execution vulnerabilities.

One of the most serious is CVE 2026 41096 in the Windows DNS client. This is risky because the DNS client runs on almost every Windows machine. A malicious DNS response could potentially allow an attacker to run code on a target PC.

Another important flaw is CVE 2026 41089 in Windows Netlogon. Microsoft says an attacker could execute code on a domain controller without logging in by sending specially crafted network requests.

Office also received a heavy set of fixes. Microsoft patched 27 Office vulnerabilities, nearly twice as many as in April. Fifteen of those are remote code execution flaws, and eight are rated critical.

Word is a major concern this month. Four critical Word vulnerabilities can be triggered through the preview pane, meaning a user may not need to fully open a malicious document for the attack path to matter.

Microsoft also patched a critical data leak in Team Events Portal, tracked as CVE 2026 33823. Two Microsoft 365 Copilot data leak flaws, CVE 2026 26129 and CVE 2026 26164, are also rated critical.

Edge received its own updates too. Microsoft Edge version 148.0.3967.54 includes fixes based on Chromium 148.0.7778.97. That update addresses 127 Chromium vulnerabilities, which are separate from the 120 Patch Tuesday count. Microsoft also fixed three Edge specific vulnerabilities and two issues in Edge for Android.

For regular users, the advice is simple. Install the May updates as soon as possible, especially if you use Microsoft Office or manage Windows PCs in a business environment.

The Word preview pane issues are especially important because they reduce the amount of user interaction needed for an attack. The DNS and Netlogon flaws also matter because they affect core Windows networking components.

Even though Microsoft says none of these vulnerabilities are being actively exploited yet, that can change quickly after patches are released and attackers begin studying them. Keeping Windows, Office, and Edge updated is the safest move.

Discover: News

Discussion (0)

Be the first to comment.