Patch Tuesday 2026
The latest Patch Tuesday 2026 coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-40418: Microsoft Office Click-to-Run Elevation of Privilege Flaw Patched in May 2026 Update
Microsoft's May 2026 Patch Tuesday, released on May 12, 2026, addressed CVE-2026-40418, an elevation-of-privilege vulnerability in Microsoft Office Click-to-Run. Rated Important, this security flaw...
Patch Now: May 2026 Fix for Windows TCP/IP DoS Bug CVE-2026-40413
Microsoft has released a critical security update addressing a denial-of-service vulnerability in the Windows TCP/IP stack, tracked as CVE-2026-40413, as part of its May 2026 Patch Tuesday rollout....
Patch Now: Critical CVE-2026-40403 Win32K RCE Hits All Windows
Microsoft’s May 2026 Patch Tuesday brought with it a critical disclosure that should jolt every Windows administrator into action: CVE-2026-40403, a remote code execution flaw in the Win32K...
Windows Hyper-V Bug Lets Guest VM Crash Host via TCP/IP DoS
Microsoft’s May 2026 Patch Tuesday landed with a particularly nasty surprise for Hyper-V administrators: a denial-of-service vulnerability in the Windows TCP/IP stack that can bleed from a guest...
Microsoft patched CVE-2026-40398 in May 2026, an Important privilege escalation vulnerability in Windows Remote Desktop Services that allows a low-privileged authenticated attacker to gain SYSTEM priv
Microsoft's May 2026 Patch Tuesday rollout addressed 78 security vulnerabilities, among them CVE-2026-40398—an elevation-of-privilege bug in Windows Remote Desktop Services (RDS) scored at CVSS 7.8...
CVE-2026-32209: Microsoft Patches Critical Windows Filtering Platform Bypass in May 2026 Patch Tuesday
Microsoft dropped its May 2026 Patch Tuesday on May 12, and among the slew of fixes sits CVE-2026-32209 — a nasty security feature bypass in the Windows Filtering Platform (WFP). Public reporting...
Microsoft May Patch Tuesday Fixes Critical CLFS Elevation of Privilege Bug
Microsoft’s May 12, 2026 Patch Tuesday includes a fix for CVE-2026-40397, an Important-severity elevation-of-privilege vulnerability in the Windows Common Log File System (CLFS) driver. Public...
Windows Kernel Driver Bug CVE-2026-40369 Allows SYSTEM Access in May Patch Tuesday
Microsoft's May 2026 Patch Tuesday, released on May 12, includes a fix for CVE-2026-40369, an Important-rated elevation of privilege vulnerability in the Windows kernel-mode driver with a CVSS score...
Microsoft Issues Urgent Patch for Critical SharePoint Server 2019 RCE Flaw
Microsoft has released security updates to address a critical remote code execution vulnerability in SharePoint Server 2019, tracked as CVE-2026-40365. The patch, delivered via the SharePoint Server...
CVE-2026-40361: Microsoft Word Remote Code Execution Vulnerability Demands Immediate Patching
Microsoft has disclosed CVE-2026-40361, a remote code execution vulnerability in Microsoft Word, through its Security Update Guide on May 12, 2026. The advisory carries an urgent tone, starkly...
Patch Now: Microsoft Flags Critical Office RCE CVE-2026-40358 as High Risk
Microsoft dropped a bombshell in its May 2026 Patch Tuesday release, disclosing a critical remote code execution vulnerability in Microsoft Office that carries an unusually high confidence label for...
Microsoft fixes CVE-2026-34339: Patch LDAP DoS flaw to prevent domain controller crashes
Microsoft dropped a critical patch for CVE-2026-34339 in its May 12, 2026 Patch Tuesday release, addressing a denial-of-service vulnerability in the Windows Lightweight Directory Access Protocol...