Patch Tuesday - May 2026

2026-05-13T07:23:47Zd87e61065ad730362a0c56efbde7dc85585f5025291403e358e279e087f6bbc6
CVE-2020-1472CVE-2026-41089CVSS 9.8MicrosoftPatch TuesdayWindows Netlogonbrowser vulnerabilitiescriticaldomain controllerremote code executionstack-based buffer overflowvulnerability management

What happened

Rapid7’s May 2026 Patch Tuesday summarizes Microsoft’s release of 137 vulnerabilities (plus 133 browser fixes published separately) and highlights a critical Windows Netlogon remote code execution: CVE-2026-41089 — a stack-based buffer overflow with CVSSv3 9.8 that can yield SYSTEM on domain controllers with no privileges or user interaction required. Microsoft reports no known in-the-wild exploitation but rates exploitability as low; Rapid7 advises prioritizing remediation of domain controllers immediately and treating this as high-risk (analogous to CVE-2020-1472/Zerologon-era impact).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
d87e61065ad730362a0c56efbde7dc85585f5025291403e358e279e087f6bbc6
Enrichment time
2026-05-13T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.