Patch Tuesday 2026
The latest Patch Tuesday 2026 coverage — news, analysis, and updates from the WindowsNews.AI desk.
Apply May 2026 Patch for Windows Telephony EoP Flaw CVE-2026-34338
On May 12, 2026, Microsoft published details on CVE-2026-34338, a new elevation-of-privilege (EoP) vulnerability affecting the Windows Telephony Service. The disclosure arrived as part of the...
CVE-2026-34337 Windows Cloud Files Driver Bug Grants SYSTEM — Patch Now
Microsoft has listed a new elevation-of-privilege vulnerability under CVE-2026-34337 in its Security Update Guide, affecting the Windows Cloud Files Mini Filter Driver. The flaw, rated Important by...
CVE-2026-33838: Windows MSMQ Bug Gives SYSTEM Access via Malformed Message
Microsoft disclosed a critical elevation-of-privilege vulnerability in its legacy Message Queuing service as part of the May 2026 Patch Tuesday releases. Tracked as CVE-2026-33838, the flaw allows a...
CVE-2026-33835: Microsoft Patches Windows Cloud Files Elevation of Privilege Flaw in May 2026 Patch Tuesday
Microsoft fixed an elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver as part of its May 2026 Patch Tuesday updates. The flaw, tracked as CVE-2026-33835, was disclosed...
CVE-2026-33112: Critical SharePoint RCE Hits On-Prem Servers May 12
Microsoft dropped a bombshell on administrators this Patch Tuesday with the publication of CVE-2026-33112, a confirmed remote code execution vulnerability in Microsoft SharePoint Server. The...
Microsoft Patches .NET Core Tampering Vulnerability CVE-2026-32175 in May Patch Tuesday
Microsoft rolled out a fix for a security flaw in .NET Core on May 12, 2026, as part of the company’s monthly Patch Tuesday cycle. Tracked as CVE-2026-32175, the vulnerability is a confirmed...
CVE-2026-42831 Office RCE: Microsoft Flags High Exploit Risk, Patch Now
Microsoft’s Security Update Guide now carries a new entry that demands immediate attention from enterprises and individuals alike: CVE-2026-42831, a remote code execution vulnerability in Microsoft...
Microsoft Patches Rich Text Edit Control Privilege Escalation (CVE-2026-32170) in May 2026 Patch Tuesday
Microsoft's May 12, 2026 Patch Tuesday release addresses CVE-2026-32170, an elevation-of-privilege vulnerability in the Windows Rich Text Edit Control. The flaw, disclosed in the Microsoft Security...
Microsoft Patches Critical VS Code Security Bypass (CVE-2026-41610) in May 2026 Patch Tuesday
Microsoft released its May 2026 Patch Tuesday updates on May 12, and among the 75 vulnerabilities addressed, one stands out for developers: CVE-2026-41610, a security feature bypass in Visual Studio...
Windows 11 May 2026 update adds Xbox Mode, AI taskbar agents, and 73 security fixes
Microsoft rolled out its May 2026 Patch Tuesday updates on schedule, delivering KB5089549 for Windows 11 versions 25H2 and 24H2 and KB5089548 for version 26H1. The cumulative updates bump 25H2 to...
CVE-2026-40415: Patch Critical Windows TCP/IP RCE Flaw Now
Microsoft disclosed a critical remote code execution vulnerability in the Windows TCP/IP stack on May 12, 2026, assigned CVE-2026-40415. The flaw, detailed in the monthly Security Update Guide, sits...
Windows WAN ARP Driver Use-After-Free Flaw Grants SYSTEM Access
Microsoft disclosed CVE-2026-40408 on May 12, 2026, as part of its monthly Patch Tuesday security updates. This Important-rated elevation-of-privilege vulnerability resides in the Windows WAN ARP...