Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)

2026-05-12T20:52:19Z07dd15935bc1579530bfac81243e3e9625fafc4aa6b867147f176b4c592a3a7e
ai-driven discoverycve-2025-54518cve-2026-41103cve-2026-43284cve-2026-43500dirty fragexposure managementlinux kernellocal privilege escalationmicrosoft patch tuesdaynvd enrichmentproject glasswingpublic exploittenable hexa aivulnerability management

What happened

This Tenable feed aggregates multiple May 2026 posts: (1) Microsoft’s May 2026 Patch Tuesday fixed 118 CVEs (16 critical, 102 important), highlighted in the post title (CVE-2026-41103 called out) and noting an omitted AMD CPU OP Cache Corruption entry (CVE-2025-54518). (2) “Dirty Frag” is a chained Linux kernel local privilege escalation (CVE-2026-43284 + CVE-2026-43500) with public exploit/PoC released prior to patches, enabling local users to achieve root. (3) Analysis posts warn of an accelerating flood of vulnerabilities driven by AI-driven discovery (Project Glasswing / Mythos) and the NV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
07dd15935bc1579530bfac81243e3e9625fafc4aa6b867147f176b4c592a3a7e
Enrichment time
2026-05-12T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.