Tuesday , August 4 2026

Microsoft Patch Tuesday May 2026 fixed 120 flaws, Including 29 Critical RCE

Microsoft’s May 2026 Patch Tuesday brings many updates for businesses. It fixes 120 security flaws in Windows, Office, Azure, developer tools, and Microsoft 365 apps. Among these, 29 critical flaws let attackers run code from far away.

Microsoft says there are no zero-days used in attacks or announced before this release, which is different from past cycles. However, the wide range of areas that could be attacked, like DNS, Netlogon, Office, and Wi-Fi drivers, means that those defending systems should not see this month as low risk.

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves
Vulnerability Type Count
Elevation of Privilege 61
Security Feature Bypass 6
Remote Code Execution (RCE) 31
Information Disclosure 14
Denial of Service (DoS) 8
Spoofing 13

Multiple Remote Code Execution Vulnerabilities

This month has no zero-day bugs being used, but the biggest flaws are with network and document-related RCE vulnerabilities that could lead to total control if not fixed.

High‑value targets include Microsoft Dynamics 365 on‑premises (CVE‑2026‑42898, CVE‑2026‑42833), multiple Microsoft Office and Word RCEs (for example CVE‑2026‑42831, CVE‑2026‑40363, CVE‑2026‑40358, several Word‑specific CVEs), Windows DNS Client (CVE‑2026‑41096), Netlogon (CVE‑2026‑41089), Windows Graphics/Win32k (CVE‑2026‑40403), Windows GDI (CVE‑2026‑35421), Windows Native Wi‑Fi Miniport (CVE‑2026‑32161), and Microsoft SharePoint Server (CVE‑2026‑40365 and related CVEs).

Many of these are in parts that often face untrusted content, network traffic, Office documents, or web-like processes. This makes them likely targets for phishing and other attacks.

Windows Core Networking, Kernel, and Virtualization Flaws

Many flaws affect Windows networking and kernel parts, increasing risks for systems connected to domains and the internet.

Windows DNS Client RCE (CVE‑2026‑41096) and Netlogon RCE (CVE‑2026‑41089) are important issues: attackers with low access or no access could run code in critical areas of Windows authentication and name resolution. This is similar to the effects of past bugs like SigRed and Zerologon.

Windows Hyper-V (CVE-2026-40402, rated Critical) gets a fix for privilege escalation. This is very important for shared and private cloud systems. A guest could escape to host and cause big problems.

Copilot, VS Code, and Azure Flaws

This Patch Tuesday shows how much AI and cloud-based development are part of business security risks.
Microsoft fixes problems with fake identities and security gaps in M365 Copilot for Desktop and Android, GitHub Copilot with Visual Studio, and Azure Machine Learning notebooks. These issues raise worries about tricking users, stealing data, or adding harmful content through trusted AI tools.

Organizations that have a lot of virtual work should plan times for Hyper-V updates. Those using Copilot, Teams, and Azure should not forget about fixes for AI and workflows, even if they are marked as Important.

Related News:

Check Also

BlueField

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This …