Articles from May 2026
Browse all Windows news articles published in May 2026
Windows Kernel Bug Allows Attackers to Vault Out of Sandboxes — Patch Now, Microsoft Says
Microsoft’s May 2026 Patch Tuesday release fixes a kernel flaw that can pry open the containment barriers meant to keep untrusted code caged. CVE-2026-33841, a heap-based buffer overflow in the...
KB5089549: Microsoft’s Stealthy May Patch Preps Your PC for a Looming Secure Boot Deadline
Microsoft shipped the May 2026 security update for Windows 11 on schedule, but buried inside the routine cumulative patch is a quiet, deadline-driven campaign to keep millions of PCs from losing...
Low-Complexity Win32k Bug Gives Attackers SYSTEM; Microsoft Patches Windows 11 and Server 2025
On May 12, 2026, Microsoft shipped a security update that closes CVE-2026-33840, a local privilege escalation vulnerability in the Windows Win32k subsystem. An attacker with a low-privilege foothold...
Norm Ai Launches Compliance Agent for Microsoft 365 Copilot, Bringing Automated Audit Trails and Policy Guardrails to Enterprise AI
Norm Ai released a purpose-built compliance agent for Microsoft 365 Copilot on May 12, 2026. The new agent embeds automated policy review, real-time verification, disclosure support, and fully...
CVE-2026-33839 Win32k Race Flaw Grants SYSTEM Access—Patch Now
Microsoft has addressed a high-severity elevation-of-privilege vulnerability in the Windows graphics system, urging all users to apply the May 2026 security patches immediately. Tracked as...
Patch now: CVE-2026-33834 Windows Event Logging EoP bug gives attackers SYSTEM access
Microsoft’s May 2026 Patch Tuesday rollout included a critical fix for CVE-2026-33834, an elevation-of-privilege (EoP) vulnerability in the Windows Event Logging Service. Disclosed on May 12, 2026,...
Azure SDK for Java flaw CVE-2026-33117 bypasses auth, MSRC urges immediate patching
Microsoft has officially assigned CVE-2026-33117 to a critical security feature bypass vulnerability in the Azure SDK for Java. Published through the Microsoft Security Response Center (MSRC), the...
CVE-2026-21530: Critical Windows Rich Text Edit Privilege Escalation Flaw Fixed in May 2026 Patches
Microsoft has patched a serious elevation-of-privilege vulnerability in the Windows Rich Text Edit component as part of its May 2026 security updates. CVE-2026-21530 could allow attackers to gain...
CVE-2026-32177: Critical .NET Elevation of Privilege Flaw Demands Immediate Patching
Microsoft has disclosed a new elevation-of-privilege vulnerability in its .NET framework and Visual Studio, tracked as CVE-2026-32177, as part of the April 2026 Patch Tuesday release. The flaw,...
Patch Windows Azure Monitor Agent Now to Block SYSTEM Privilege Attacks
Microsoft's May 2026 Patch Tuesday brought a new elevation-of-privilege vulnerability, CVE-2026-32204, targeting the Azure Monitor Agent on Windows systems. The early signal from the software giant...
Microsoft pauses Exchange security patches in May 2026; admins should audit now.
Microsoft will not release security updates for Exchange Server this month, the company confirmed on May 12, 2026—the date that would typically mark Patch Tuesday for the collaboration platform....
CVE-2026-8108: Fuji Tellus Kernel Driver Flaw Lets Local Users Hijack Windows OT Systems
A critical local privilege escalation bug in Fuji Electric Tellus 5.0.2 can hand any authenticated user full SYSTEM rights on industrial Windows machines. The vulnerability, tracked as CVE-2026-8108,...