Patch Tuesday - May 2026
2026-05-13T07:23:47Z•d87e61065ad730362a0c56efbde7dc85585f5025291403e358e279e087f6bbc6
CVE-2020-1472CVE-2026-41089CVSS 9.8MicrosoftPatch TuesdayWindows Netlogonbrowser vulnerabilitiescriticaldomain controllerremote code executionstack-based buffer overflowvulnerability management
What happened
Rapid7’s May 2026 Patch Tuesday summarizes Microsoft’s release of 137 vulnerabilities (plus 133 browser fixes published separately) and highlights a critical Windows Netlogon remote code execution: CVE-2026-41089 — a stack-based buffer overflow with CVSSv3 9.8 that can yield SYSTEM on domain controllers with no privileges or user interaction required. Microsoft reports no known in-the-wild exploitation but rates exploitability as low; Rapid7 advises prioritizing remediation of domain controllers immediately and treating this as high-risk (analogous to CVE-2020-1472/Zerologon-era impact).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- d87e61065ad730362a0c56efbde7dc85585f5025291403e358e279e087f6bbc6
- Enrichment time
- 2026-05-13T07:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.