Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103)
2026-05-12T20:52:19Z•07dd15935bc1579530bfac81243e3e9625fafc4aa6b867147f176b4c592a3a7e
ai-driven discoverycve-2025-54518cve-2026-41103cve-2026-43284cve-2026-43500dirty fragexposure managementlinux kernellocal privilege escalationmicrosoft patch tuesdaynvd enrichmentproject glasswingpublic exploittenable hexa aivulnerability management
What happened
This Tenable feed aggregates multiple May 2026 posts: (1) Microsoft’s May 2026 Patch Tuesday fixed 118 CVEs (16 critical, 102 important), highlighted in the post title (CVE-2026-41103 called out) and noting an omitted AMD CPU OP Cache Corruption entry (CVE-2025-54518). (2) “Dirty Frag” is a chained Linux kernel local privilege escalation (CVE-2026-43284 + CVE-2026-43500) with public exploit/PoC released prior to patches, enabling local users to achieve root. (3) Analysis posts warn of an accelerating flood of vulnerabilities driven by AI-driven discovery (Project Glasswing / Mythos) and the NV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- 07dd15935bc1579530bfac81243e3e9625fafc4aa6b867147f176b4c592a3a7e
- Enrichment time
- 2026-05-12T20:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.