Thursday , September 17 2026

Microsoft Patch Tuesday May 2026 fixed 120 flaws, Including 29 Critical RCE

Microsoft’s May 2026 Patch Tuesday brings many updates for businesses. It fixes 120 security flaws in Windows, Office, Azure, developer tools, and Microsoft 365 apps. Among these, 29 critical flaws let attackers run code from far away.

Microsoft says there are no zero-days used in attacks or announced before this release, which is different from past cycles. However, the wide range of areas that could be attacked, like DNS, Netlogon, Office, and Wi-Fi drivers, means that those defending systems should not see this month as low risk.

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks
Vulnerability Type Count
Elevation of Privilege 61
Security Feature Bypass 6
Remote Code Execution (RCE) 31
Information Disclosure 14
Denial of Service (DoS) 8
Spoofing 13

Multiple Remote Code Execution Vulnerabilities

This month has no zero-day bugs being used, but the biggest flaws are with network and document-related RCE vulnerabilities that could lead to total control if not fixed.

High‑value targets include Microsoft Dynamics 365 on‑premises (CVE‑2026‑42898, CVE‑2026‑42833), multiple Microsoft Office and Word RCEs (for example CVE‑2026‑42831, CVE‑2026‑40363, CVE‑2026‑40358, several Word‑specific CVEs), Windows DNS Client (CVE‑2026‑41096), Netlogon (CVE‑2026‑41089), Windows Graphics/Win32k (CVE‑2026‑40403), Windows GDI (CVE‑2026‑35421), Windows Native Wi‑Fi Miniport (CVE‑2026‑32161), and Microsoft SharePoint Server (CVE‑2026‑40365 and related CVEs).

Many of these are in parts that often face untrusted content, network traffic, Office documents, or web-like processes. This makes them likely targets for phishing and other attacks.

Windows Core Networking, Kernel, and Virtualization Flaws

Many flaws affect Windows networking and kernel parts, increasing risks for systems connected to domains and the internet.

Windows DNS Client RCE (CVE‑2026‑41096) and Netlogon RCE (CVE‑2026‑41089) are important issues: attackers with low access or no access could run code in critical areas of Windows authentication and name resolution. This is similar to the effects of past bugs like SigRed and Zerologon.

Windows Hyper-V (CVE-2026-40402, rated Critical) gets a fix for privilege escalation. This is very important for shared and private cloud systems. A guest could escape to host and cause big problems.

Copilot, VS Code, and Azure Flaws

This Patch Tuesday shows how much AI and cloud-based development are part of business security risks.
Microsoft fixes problems with fake identities and security gaps in M365 Copilot for Desktop and Android, GitHub Copilot with Visual Studio, and Azure Machine Learning notebooks. These issues raise worries about tricking users, stealing data, or adding harmful content through trusted AI tools.

Organizations that have a lot of virtual work should plan times for Hyper-V updates. Those using Copilot, Teams, and Azure should not forget about fixes for AI and workflows, even if they are marked as Important.

Related News:

Check Also

VPN flaws

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both …