Briefing

Microsoft, Apple, Google, Mozilla, Oracle Release Major Security Patches—118 CVEs Fixed on Patch Tuesday

security
by BrianKrebs · Anthropic CVE-2026-41089 CVE-2026-41096 CVE-2026-41103

Patch all Windows Server 2012+ to fix CVE‑2026‑41089, CVE‑2026‑41096, CVE‑2026‑41103; update Chrome to the latest build to resolve 127 CVEs; back up data before applying any vendor patches.

What to do now

Patch all Windows Server 2012+ to address CVE‑2026‑41089, CVE‑2026‑41096, CVE‑2026‑41103; update Chrome to the latest build; back up data before applying any vendor patches.

Summary

Microsoft’s Patch Tuesday released 118 security fixes, including 16 critical vulnerabilities, with no zero‑day or previously disclosed flaws—an anomaly for the first time in nearly two years. The critical CVEs include CVE‑2026‑41089, a stack‑based buffer overflow in Windows Netlogon that grants SYSTEM on domain controllers; CVE‑2026‑41096, a critical RCE in the Windows DNS client; and CVE‑2026‑41103, an elevation of privilege that lets attackers forge credentials to bypass Entra ID.

Apple shipped updates for 52 vulnerabilities, backporting fixes all the way to iPhone 6s and iOS 15. Mozilla’s Firefox 150 fixed 271 vulnerabilities discovered by Anthropic’s Project Glasswing and has moved to a weekly security cadence. Oracle addressed 450 flaws, 300 of which were remotely exploitable, and announced a monthly critical patch cycle. Google Chrome rolled out 127 CVEs, auto‑downloading updates that require a full browser restart.

Key changes

  • Microsoft Patch Tuesday fixed 118 vulnerabilities, 16 critical, with no zero‑day or previously disclosed flaws
  • CVE‑2026‑41089: stack‑based buffer overflow in Windows Netlogon grants SYSTEM on domain controllers, affecting Windows Server 2012+
  • CVE‑2026‑41096: critical RCE in Windows DNS client, exploitation less likely but still critical
  • CVE‑2026‑41103: elevation of privilege via forged credentials bypassing Entra ID, exploitation more likely
  • Apple shipped 52 vulnerabilities, backported to iPhone 6s and iOS 15
  • Mozilla Firefox 150 fixed 271 vulnerabilities discovered by Project Glasswing, now on weekly cadence
  • Oracle addressed 450 flaws, 300 remotely exploitable, and switched to monthly critical patch cycle
  • Google Chrome rolled out 127 CVEs, auto‑downloaded but requiring full browser restart

Affects

enterprise

Source angles · 2 perspectives

Krebs on Security
Independent angle

Patch Tuesday, May 2026 Edition

Open
The Hacker News
Independent angle

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting